CCT - Crypto Currency Tracker logo CCT - Crypto Currency Tracker logo
Crypto Daily 2023-08-07 06:00:00

Curve Finance Opens $1.85m Bounty To Identify Threat Actor

Decentralized finance (DeFi) protocol Curve is offering a $1.85 million reward to anyone who can identify the exploiter responsible for draining over $61 million from its pools on July 30. This announcement was made after the deadline for the voluntary return of funds expired. The exploiter used vulnerable versions of the Vyper programming language to launch reentrancy attacks on targeted stable pools, leading to significant losses. Following the attack, Curve and other affected protocols offered a 10% bug bounty to the exploiter, totaling more than $6 million. In response, the hacker returned stolen assets to two projects, Alchemix and JPEGd, but did not refund other affected pools. What is a reentrancy attack?A reentrancy attack, the method used by the exploiter in this case, is a common security vulnerability in smart contracts, especially those running on blockchain platforms like Ethereum. In a nutshell, a reentrancy attack allows an attacker to repeatedly call a functiorn in a smart contract while a previous call to that same function has not yet finished executing. The Vyper programming language, which was used to build the targeted stable pools in this case, is a contract-oriented language similar to Solidity, another popular language for writing smart contracts on Ethereum. While Vyper is designed with a stronger emphasis on security and simplicity, it is not immune to reentrancy attacks, which are a pervasive problem in the world of smart contracts. During a reentrancy attack, an exploiter can drain funds from a contract by recursively calling a function that withdraws funds. In this case, the exploiter managed to drain more than $61 million from several of Curve's stable pools, illustrating the severity of the attack and the poterntial impact of these types of vulnerabilities in the DeFi space. The incident underscores the importance of proper security practices and rigorous code review in the development of smart contracts. Despite the relative maturity of DeFi, the risk of smart contract vulnerabilities like reentrancy attacks remains, necessitating ongoing vigilance and robust security measures from DeFi projects.What's at stake for Curve Finance? Curve has now extended its bounty to the public, promising a reward equivalent to 10% of the remaining exploited funds (currently $1.85 million) to anyone who can identify the exploiter in a way that results in legal conviction. However, the firm has stated that it will not pursue the issue further if the exploiter chooses to return the stolen funds in full. Prior to returning some of the funds, the exploiter had sent a message to the Alchemix and Curve teams, stating that they were refunding the money not because the teams could find them, but because they didn't want to ruin the projects. The July 30 attack targeted several of Curve’s pools, including those of Alchemix, JPEGd, and Metronome, resulting in significant losses. The exploit exposed vulnerabilities across DeFi projects and triggered industry-wide efforts to recover stolen funds. Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.