Curve Stablecoin Exchange Hit by $50 Million Cyber Attack Due to Vyper Vulnerability
Join Our Telegram channel to stay up to date on breaking news coverage Curve stablecoin exchange suffered a cyber attack leading to losses of $50 million due to vulnerabilities in some version of Vyper programming language. Vyper tweeted that its 0.2.15, 0.2.16 and 0.3.0 versions are vulnerable to malfunctioning of so-called reentrancy locks. Curve Finance Suffers an Exploit Unlike other exchanges which use middlemen, Curve Finance uses smart contracts to provide users with services such as stablecoin borrowing, lending, and trading. These smart contracts can be written in a variety of languages including Solidity, Yul, and Vyper. According to Vyper, any projects using the 0.2.15, 0.2.16, and 0.3.0 versions of the languages are vulnerable to malfunctioning reentrancy locks. Reentrancy is a common flaw that lets attackers fool a smart contract by repeatedly calling a protocol in order to take money. PSA: Vyper versions 0.2.15, 0.2.16 and 0.3.0 are vulnerable to malfunctioni...