T
iTokenly

Curve Finance hack — July 2023

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeDecentralised exchange
Loss$70,000,000Published estimates range $52,000,000 to $73,000,000Price at time of incident
MethodReentrancyVyper 0.2.15–0.3.0 compiled broken reentrancy guards into affected pools
ChainsEthereum
OutcomePartially recovered

What happened

Several Curve Finance liquidity pools were drained on 30 July 2023, along with pools belonging to Alchemix, JPEG'd and Metronome that used the same code.

The bug was not in Curve. Specific versions of the Vyper compiler — 0.2.15, 0.2.16 and 0.3.0 — failed to implement the reentrancy guard correctly, so contracts that had been written with protection in place were compiled without it. Any pool built with those versions was exposed, regardless of how carefully it had been reviewed.

That makes this incident a useful counterexample to the assumption that an audited contract is a safe contract: the source was correct and the compiled bytecode was not.

Recovery was partial and messy. Whitehat operators and MEV bots front-ran parts of the exploit and returned funds, which is why published figures range from roughly $52m of net loss up to about $73m gross. Both bounds are recorded here.

Sources

  1. ChainalysisSecondary · retrieved 2026-08-01
  2. CertiKSecondary · retrieved 2026-08-01
  3. HalbornSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Curve Finance hack — July 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/curve-finance
https://itokenly.com/hacks/curve-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.