T
iTokenly

dForce hack — February 2023

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedFebruary 10, 2023
Target typeLending protocol
Loss$3,650,000Published estimates range $3,650,000 to $5,400,000Price at time of incident
Recovered$3,650,000
MethodReentrancyRead-only reentrancy in a Curve wstETH/ETH pool used as a price oracle. Curve's Vyper remove_liquidity sent ETH to the caller before decrementing LP token supply, so a contract re-entering from its fallback saw get_virtual_price computed against a stale supply, producing an understated price. dForce's wstETH/ETH Curve gauge vaults on Arbitrum and Optimism read that distorted virtual price, and the attacker, funded by flash loans, used it to liquidate positions on terms the true price would not have supported.
ChainsArbitrum, Optimism
Audited beforehandYes
OutcomeSettled as bug bounty

What happened

On 10 February 2023 an attacker drained dForce's wstETH/ETH Curve gauge vaults on Arbitrum and Optimism. dForce confirmed the attack the same day, said it had immediately paused its vaults, and stated that the rest of the protocol and funds in dForce Lending were unaffected.

The mechanism was read-only reentrancy in a Curve pool. Curve's Vyper implementation of remove_liquidity transferred ETH to the caller before it decremented the LP token supply, so a contract that re-entered from its fallback function saw get_virtual_price calculated against a stale supply figure, and therefore an understated price. The affected dForce vaults used that virtual price as an oracle. The attacker took flash loans, entered the pool, re-entered during the withdrawal while the price was distorted, and liquidated positions at terms the true price would not have supported. Halborn noted the flaw sat outside the scope of dForce's audit and that the same class of bug had already affected other Curve integrators.

Published loss figures differ. dForce's own accounting, matching PeckShield's alert and reported by crypto.news, is $3.65m: 1,236.65 ETH and 719,437 USX on Arbitrum, and 1,037,492 USDC on Optimism. Halborn rounds this to $3.6m. Numen Cyber's technical write-up puts the total near $5.4m, counting 2,364 ETH alongside the same stablecoin amounts. The whole gap sits in the ETH figure.

dForce contacted the attacker on-chain and offered a bounty. The full amount was returned to dForce's multisig wallets on both chains and the attacker presented themselves as a white hat. dForce said it would pay an undisclosed bounty and drop its investigation and law enforcement referrals. No individual has been identified.

Sources

  1. crypto.newsSecondary · retrieved 2026-08-01
  2. HalbornSecondary · retrieved 2026-08-01
  3. Numen CyberSecondary · retrieved 2026-08-01
  4. Web3 Is Going Just GreatAggregator · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "dForce hack — February 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/dforce
https://itokenly.com/hacks/dforce

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.