BREAKING: Curve Finance team warns users to avoid using site until further notice

A still undefined exploit of the site’s frontend appears to have resulted in the theft of over $573K USD so far.

On Aug 9, automated market maker Curve Finance took to Twitter to warn users of an ongoing exploit on its site. The team behind the protocol noted that the issue, which appears to be an attack from a malicious actor, was affecting the service’s nameserver and frontend.

Curve stated via Twitter that its exchange — which is a separate product — appeared to be unaffected by the attack, as it uses a different DNS provider. The team still encouraged users to exercise caution when interacting with the site, however.

Twitter user LefterisJP speculated that the alleged attacker had likely utilized DNS spoofing to execute the exploit on the service:

Other participants in the DeFi space quickly took to Twitter to spread the warning to their own followers, with some noting that the alleged thief appears to have stolen more than $573K USD at time of publication.

Back in July, analysts suggested that they were favorably eying Curve Finance, despite the market downturn which continues to affect the larger DeFi space. Among the reasons cited by researchers at Delphi Digital for their bullishness, they specifically called out the platform’s yield opportunities, the demand for CRV deposits, and the protocol’s revenue generation from stablecoin liquidity.

This followed the platform’s release of a new “algorithm for exchanging volatile assets” in June, which promised to allow low-slippage swaps between “volatile” assets. These pools use a combination of internal oracles relying on Exponential Moving Averages (EMAs) and a bonding curve model, previously deployed by popular AMMs such as Uniswap.

This story is in development, and will be updated as more information becomes available.

Leave a Reply

Your email address will not be published. Required fields are marked *