Curve Finance awards dev $250k for finding reentrancy vulnerability

cyptouser6 months agoCryptocurrencies News106
55966e89>

A security researcher was rewarded $250,000 for discovering a vulnerability that has historically allowed hackers to pull out millions of dollars from cryptocurrency protocols. 

Pseudonymous cybersecurity researcher Marco Croc from Kupia Security identified a reentrancy vulnerability in decentralized finance (DeFi) protocol Curve Finance.

In an X thread, he explained how the bug could be exploited to manipulate balances and withdraw funds from liquidity pools.

Curve Finance acknowledged potential security flaws and “recognized the severity of the vulnerability,” Marco Croc explained. After a thorough investigation, Curve Finance awarded Marco Croc its maximum bug bounty award of $250,000.

Source: Curve Finance

According to Curve Finance, the threat was classified as “not as dangerous,” and they believed they could recover the stolen funds in such a case. 

However, the protocol said a security incident of any scale “could have caused serious panic if it had happened.”

Related: Curve Finance debt will cause 'one more stress test' in February — Analyst

Curve Finance recently recovered from a $62 million hack in July. As part of returning to normalcy, the DeFi protocol voted to reimburse $49.2 million worth of assets to the liquidity providers (LPs).

Source: Curve Finance

On-chain data confirms that 94% of tokenholders approved the disbursement of tokens worth over $49.2 million to cover the losses of the Curve, JPEG’d (JPEG), Alchemix (ALCX) and Metronome (MET) pools.

According to Curve’s proposal, the community fund will supply the Curve DAO (CRV) tokens. The final amount also includes a deduction for the tokens recovered since the incident.

“The overall ETH (ETH) to recover was calculated as 5919.2226 ETH, the CRV to recover was calculated as 34,733,171.51 CRV and the total to distribute was calculated as 55’544’782.73 CRV,” reads the proposal.

The attacker exploited a vulnerability on stable pools using some versions of the Vyper programming language. The bug made Vyper’s 0.2.15, 0.2.16 and 0.3.0 versions vulnerable to reentrancy attacks.

Magazine: 68% of Runes are in the red — Are they really an upgrade for Bitcoin?

The content on this website comes from the Internet. Due to the inconvenience of proofreading the authenticity and accuracy of the copyright or content of some content, it may be temporarily impossible to confirm the authenticity and accuracy of the copyright or content. For copyright issues or other issues caused by this, please Call or email this site. It will be deleted or changed immediately after verification.

related articles

Privado ID spins off from Polygon Labs to target $101B digital identity market

Privado ID has rebranded from Polygon ID and spun off from Polygon Labs to focus on the mainstream d...

Blockchain has a role to play in countering the ill effects of AI

55966e89˃The rise of generative AI has raised questions for policymakers about how to govern these p...

Sky Mavis recovers $5.7M from Ronin Bridge hack

Sky Mavis recovers $5.7M from Ronin Bridge hack

55966e89˃Sky Mavis, the company behind the popular play-to-earn (P2E) game Axie Infinity, has announ...

‘No clear catalyst’ for bloodbath as top altcoins fall double digits

‘No clear catalyst’ for bloodbath as top altcoins fall double digits

55966e89˃Crypto markets tumbled into a sea of red on Monday, with some altcoins bleeding more than 1...

Bitcoin and Altcoins: Recent Drop in Prices Explained

Bitcoin’s (BTC) price dropped to a one-month low following three consecutive trading days of outflow...

SEC defers decision on Bitwise, Grayscale Bitcoin ETF options

SEC defers decision on Bitwise, Grayscale Bitcoin ETF options

1205f261˃The United States securities regulator has delayed its decision on whether to allow the New...