Fun

Curve Finance awards dev $250K for finding reentrancy vulnerability

News Feed - 2024-05-01 07:05:33

Arijit Sarkar13 hours agoCurve Finance awards dev $250K for finding reentrancy vulnerabilityCurve Finance awarded cybersecurity researcher Marco Croc with its maximum bug bounty award of $250,000 after thoroughly investigating the security flaw.2452 Total views3 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksA security researcher was rewarded $250,000 for discovering a vulnerability that has historically allowed hackers to pull out millions of dollars from cryptocurrency protocols. 


Pseudonymous cybersecurity researcher Marco Croc from Kupia Security identified a reentrancy vulnerability in decentralized finance (DeFi) protocol Curve Finance.


In an X thread, he explained how the bug could be exploited to manipulate balances and withdraw funds from liquidity pools.


Curve Finance acknowledged potential security flaws and “recognized the severity of the vulnerability,” Marco Croc explained. After a thorough investigation, Curve Finance awarded Marco Croc its maximum bug bounty award of $250,000.Source: Curve Finance


According to Curve Finance, the threat was classified as “not as dangerous,” and they believed they could recover the stolen funds in such a case. 


However, the protocol said a security incident of any scale “could have caused serious panic if it had happened.”


Related:Curve Finance debt will cause "one more stress test" in February — Analyst


Curve Finance recently recovered from a $62 million hack in July. As part of returning to normalcy, the DeFi protocol voted to reimburse $49.2 million worth of assets to the liquidity providers (LPs).Source: Curve Finance


On-chain data confirms that 94% of tokenholders approved the disbursement of tokens worth over $49.2 million to cover the losses of the Curve, JPEG’d (JPEG), Alchemix (ALCX) and Metronome (MET) pools.


According to Curve’s proposal, the community fund will supply the Curve DAO (CRV) tokens. The final amount also includes a deduction for the tokens recovered since the incident.


“The overall ETH to recover was calculated as 5919.2226 ETH, the CRV to recover was calculated as 34,733,171.51 CRV and the total to distribute was calculated as 55’544’782.73 CRV,” reads the proposal.


The attacker exploited a vulnerability on stable pools using some versions of the Vyper programming language. The bug made Vyper’s 0.2.15, 0.2.16 and 0.3.0 versions vulnerable to reentrancy attacks.


Magazine:68% of Runes are in the red — Are they really an upgrade for Bitcoin?# Business# Rewards# Awards# Hackers# Hacks# DeFi# Curve FinanceAdd reaction

News Feed

Bitcoin 'needs to clear' $57K liquidity for post-halving rally — Trader
William Suberg8 hours agoBitcoin "needs to clear" $57K liquidity for post-halving rally — TraderBTC price continues its tests of bid liquidity after the latest Wall Street open, but confidence over the Bitcoin bull ma
UK Digital Bank Ziglu Launches P2P Payments for Bitcoin and Bitcoin Cash
UK Digital Bank Ziglu Launches P2P Payments for Bitcoin and Bitcoin CashLondon-based challenger bank Ziglu said Monday that it has been licensed as an Electronic Money Institution (
Zhiyuan Sun8 hours agoBinance to reimburse users $1M for Cyber Earn incidentUsers were prevented from withdrawing their CYBER Earn assets on the exchange due to a cross-chain bridging issue.2210 Total views20 Total share
Bitcoin, Ethereum Technical Analysis: BTC, ETH Extend Recent Declines on Saturday
Bitcoin, Ethereum Technical Analysis: BTC, ETH Extend Recent Declines on Saturday Bitcoin was trading lower on Saturday, as cryptocurrency prices continued to trade in the red foll
Earnfinance Is a Powerful DeFi Platform for Staking, Farming and Borrowing – YFE Presale Is Live
Earnfinance Is a Powerful DeFi Platform for Staking, Farming and Borrowing - YFE Presale Is Live PRESS RELEASE. What is yield farming? Yield farming, also referr
Meta Will Continue to Push Metaverse Investments in 2023 According to Head Of Reality Labs
Meta Will Continue to Push Metaverse Investments in 2023 According to Head Of Reality Labs Meta will continue to invest in VR (virtual reality) tech in 2023, according to statement
New DeFi Project NEW KANGEN (NEWG) Presale Will Start on 2nd October 2020
New DeFi Project NEW KANGEN (NEWG) Presale Will Start on 2nd October 2020As the cryptocurrency world is experiencing rapid growth, decentralized finance (DeFi) platforms are also ri
CFTC Commissioner Opposes Regulation by Enforcement, Says Crypto Needs Clearer Rules
CFTC Commissioner Opposes Regulation by Enforcement, Says Crypto Needs Clearer Rules A commissioner with the Commodity Futures Trading Commission (CFTC), Dawn Stump, has voiced con
Dogecoin Rival Shiba Inu Spikes in Value While DOGE Prices Flounder, SHIB Jumps 21% in 24 Hours
Dogecoin Rival Shiba Inu Spikes in Value While DOGE Prices Flounder, SHIB Jumps 21% in 24 Hours While the dogecoin’s token price has floundered during the last seven days, t
Elizabeth Warren Blames ‘Crypto Risk’ for Silvergate Bank’s Liquidation, Critics Dismiss Senator’s Claims as ‘Terribly Misinformed’
Elizabeth Warren Blames ‘Crypto Risk’ for Silvergate Bank"s Liquidation, Critics Dismiss Senator’s Claims as ‘Terribly Misinformed’ After Silvergate Bank announced its vo
Wall Street must be accountable for Bitcoin mining emissions — Greenpeace
Daniel Ramirez-Escudero1 minute agoWall Street must be accountable for Bitcoin mining emissions — GreenpeaceGreenpeace alleges that Wall Street titans such as BlackRock or Vanguard contribute to the environmental harm
Zhiyuan Sun14 hours agoAzuki DAO rebrands to ‘Bean’ as it drops lawsuit against founderThe DAO previously proposed a lawsuit against Azuki creator Zagabond over a dilutive $39 million NFT minting that took place in J