T
iTokenly

Conic Finance hack — July 2023

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJuly 21, 2023
Target typeOther
Loss$3,200,000Price at time of incident
Recovered$150,000
MethodReentrancyRead-only reentrancy against the ETH Omnipool. Conic's oracle identified ETH-holding Curve pools by looking for the 0xeee...eee placeholder address, but Curve v2 pools hold WETH, so the _isETH check returned false and the rETH pool's reentrancy guard was never applied. The attacker re-entered during a Curve operation, read a manipulated rETH Curve LP token price, and cycled deposits and withdrawals to extract more than deposited. Roughly $134 million of flash-borrowed assets were used to move the price.
ChainsEthereum
OutcomePartially recovered

What happened

On 21 July 2023 an attacker drained the ETH Omnipool of Conic Finance, a protocol that spread user deposits across Curve pools, taking 1,724 ETH worth about $3.2 million. Conic's core team was alerted by threat-monitoring firm Hexagate at 10:51 UTC.

Conic's post-mortem attributes the attack to read-only reentrancy. Its oracle decided whether a Curve pool held ETH by looking for the 0xeee...eee placeholder address; Curve v2 pools hold WETH instead, so the check returned false and the reentrancy guard for the rETH pool was never applied. With the guard bypassed the attacker could re-enter during a Curve operation, read a manipulated price for the rETH Curve LP token, and cycle deposits and withdrawals to take out more than had been put in. CertiK's analysis records the attacker flash-borrowing roughly $134 million in total - 20,000 stETH from Aave plus 20,550 rETH, 3,000 cbETH and 28,504.2 WETH from Balancer - to move the pool price far enough. BlockSec's Matthew Jiang said the flash-loaned stETH was used to amplify the profit.

Hours later a second, separate problem hit the crvUSD Omnipool: bots arbitraged the imbalance, and Conic shut all Omnipools starting with that pool at 19:23 UTC. Conic's post-mortem puts the crvUSD episode at about $934,000 gross, of which roughly $300,000 was captured as profit; one operator returned 81.30 ETH, about $150,000, under a negotiated bounty. Totals across both episodes are reported between $3.2 million and $3.5 million depending on what is counted, with DL News giving a combined $3.3 million.

Conic disabled deposits and set up a debt pool for affected depositors. Deposits fell from about $156 million before the attacks to under $600,000, recovered to over $30 million during 2024 before settling around $5 million, and the team shut the protocol down on 7 March 2025 after failing to fix flaws found in a new version.

Sources

  1. Conic FinancePrimary · retrieved 2026-08-01
  2. CertiKSecondary · retrieved 2026-08-01
  3. The BlockSecondary · retrieved 2026-08-01
  4. DL NewsSecondary · retrieved 2026-08-01
  5. DefiLlamaAggregator · retrieved 2026-08-01

Official post-mortem: https://medium.com/@ConicFinance/post-mortem-eth-and-crvusd-omnipool-exploits-c9c7fa213a3d

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Conic Finance hack — July 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/conic-finance
https://itokenly.com/hacks/conic-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.