Bankless Analysis of the Spread Risk of Curve Attack Incident

Original Title: A Contagion Event?

Original Author: Bankless

Source: twitter

Translation: Kate, Marsbit

Note: This article is from the official Twitter account @BanklessHQ of Bankless. The original tweet content is organized by MarsBit as follows:

The EVM compiler @vyperlang has exposed a zero-day vulnerability, with the imminent threat of pool depletion and liquidation, DeFi faces the risk of a contagion event!

Attack Vector

Earlier today, Vyper revealed that its compiler version did not correctly implement a reentrant lock

Malicious actors used reentrancy attacks to repeatedly enter the contract, resulting in unauthorized operations or fund theft

Massacre

Multiple protocols have been compromised, with an initial estimate of up to $70 million stolen

Some of these funds are held by white hats and MEV bots and may be recovered

Curve Bomb

@CurveFinance has discovered that 4 different pools have been exploited

Over $45 million in liquidity has been drained from @AlchemixFi, @MetronomeDAO, and @JPEGd_69 Factory pools, and nearly $25 million has been drained from the CRV/ETH pool

Other pools on Curve currently appear to be unaffected

$CRV Compression Crisis

Centralized exchanges show that the $CRV price bottomed out at only $0.583, but the token successfully hit a low of $0.109 on-chain

After the CRV/ETH pool was hacked, on-chain $CRV liquidity became extremely thin, causing on-chain price fluctuations

Waiting Time

Despite the brutal sell-off of $CRV, the hackers still made profits! A failed recovery will result in the sale of $CRV, which could have a serious impact on lending protocols!

There are still 7 million $CRV (approximately $4.5 million) in the wallet

Loan Alarm

The founder of Curve, @newmichwill, has obtained a large amount of loans with his $CRV as collateral on numerous lending protocols, the largest of which is @AaveAave

If the $CRV price reaches the liquidation threshold, the protocol will be forced to liquidate the $CRV position.

Payment Frenzy

To avoid being liquidated upon sale, @newmichwill has been repaying his loan debt.

Due to the repayment efforts, the new liquidation threshold for @newmichwill’s Aave loan has been reduced to $0.37 per $CRV.

Early Warning

It is reported that there is insufficient on-chain liquidity to liquidate @newmichwill’s position.

Last month, @gauntlet_xyz attempted to freeze the $CRV market on Aave, but their proposal was unanimously rejected.

https://app.aave.com/governance/proposal/?proposalId=246

Dire Situation

Liquidity in Curve’s CRV/ETH pool has vanished! $CRV liquidity has dropped even lower than when Gauntlet made their proposal.

If the position is liquidated, bad debt seems inevitable…

DeFi Spillover

Bad debt protocols must tap into insurance funds.

For example, Aave will sell tokens worth $AAVE from its safety module to cover any shortfall, but the sale will reduce the value of the remaining collateral…

Impact on Liquidity

Widespread volatility and lingering unknown factors have led many to suggest withdrawing liquidity from Curve at this time.

As liquidity continues to decrease on Curve and other on-chain DEXs, the price will become increasingly unstable.

https://twitter.com/Jasper_ETH/status/1685745826537103392

Lenders Withdrawing

Lending institutions are rushing to withdraw funds from money market protocols.

The utilization rate of Aave’s $USDT pool has exceeded 50%, pushing borrowing rates up to 91%, putting immense pressure on @newmichwill’s position: If the rates don’t decrease, it will be liquidated within a few days!

Bottom Line

While the damage to the Curve pool may already have been done, the potential impact of this exploit on DeFi may have only just begun…

The lending protocols in the $CRV market may face significant risk of bad debt, even if not bankruptcy!

Like what you're reading? Subscribe to our top stories.

We will continue to update Gambling Chain; if you have any questions or suggestions, please contact us!

Follow us on Twitter, Facebook, YouTube, and TikTok.

Share:

Was this article helpful?

93 out of 132 found this helpful

Gambling Chain Logo
Industry
Digital Asset Investment
Location
Real world, Metaverse and Network.
Goals
Build Daos that bring Decentralized finance to more and more persons Who love Web3.
Type
Website and other Media Daos

Products used

GC Wallet

Send targeted currencies to the right people at the right time.