Close Menu
    X (Twitter)
    Blockchain Journal
    • News
      • Blockchain News
      • Bitcoin News
      • Ethereum News
      • NFT
      • DeFi News
      • Polkadot News
      • Chainlink News
      • Ripple News
      • Cardano News
      • EOS News
      • Litecoin News
      • Monero News
      • Stellar News
      • Tron News
      • Press Releases
      • Opinion
      • Sponsored
    • Price Analisys
    • Learn Crypto
    • Contact
    • bandera
    Facebook X (Twitter) Instagram
    Blockchain Journal
    Home » Curve Pools Suffers Exploit: ‘MEV’ Bot Causes $2 Million Loss

    Curve Pools Suffers Exploit: ‘MEV’ Bot Causes $2 Million Loss

    0
    By fernandoo on November 8, 2023 Blockchain News, DeFi News, News
    MEV Bot Attack on Curve Pools Results in $2 Million Loss
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In the blockchain and decentralized finance (DeFi) world, the security and integrity of smart contracts is of utmost importance. Unfortunately, a new incident at Curve Pools has highlighted the risks that persist in this ever-evolving ecosystem.

    An unknown Miner Extractable Value (MEV) bot fell victim to an exploit, resulting in a massive loss of approximately $2 million on the famous Curve Pools.

    The exploitation occurred due to a vulnerability in an arbitration function, identified by PeakShieldAlert as 0xf6ebebbb(), the case was quickly sent to the community through X.

    #MEV An unknown MEV bot was exploited (with $2m loss) to make multiple large swaps in #curve pools, causing arb with simple reverse swaps.
    https://t.co/POY91xvwC4 pic.twitter.com/vu1CaxSrdt

    — PeckShieldAlert (@PeckShieldAlert) November 8, 2023

    This feature lacked proper authentication, giving the attacker an open door to manipulate trades across multiple Curve Pools.

    Resulted in a Significant Slippage in Exchanges, Strongly Affecting Curve Pools

    What makes this exploit even more disturbing is the ingenuity of the attacker. After manipulating the exchanges, he cunningly reversed the trades to maximize his profits, further compounding the impact of the incident.

    To achieve this, the attacker exploited an exposed feature in the arbitrage bot, allowing him to initiate a transaction from Wrapped Ether (WETH) to Wrapped Bitcoin (WBTC).

    He then executed a flash loan for 27,255 WETH (equivalent to $51.36 million), which he used to significantly alter the price relationship between WETH and WBTC on the Curve Pool.

    As a result, the conversion of 1,339.8 WETH (approximately $2.52 million) into 6.95 WBTC (around $244,000) occurred by destabilizing the pool.

    Importantly, the owner of the MEV bot had already withdrawn funds from the contract before the attack, which further complicated the situation.

    Curve Pools Incident: Downed MEV Bot Results in $2 Million Loss

    This incident is reminiscent of a series of previous exploits on Curve Finance in late July 2023, which resulted in losses of around $70 million. These attacks were possible due to a vulnerability in Vyper, a Python programming language used by smart contracts on Ethereum, including those on Curve and other decentralized protocols.

    However, after this exploit, both ethical hackers and MEV bot operators worked together to recover a portion of the lost funds, which could reduce the value of the initial reported losses.

    Additionally, the attacker returned a portion of the stolen funds, providing some relief to the community.

    Despite these efforts, Curve Finance has extended a $1.85 million reward offer to anyone who could identify the attacker of this recent exploit, demonstrating the DeFi community’s determination to address and prevent future exploits.

    DeFi Featured
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    fernandoo

    Related Posts

    ARK Invest Unloads Coinbase and GBTC Shares by Millions Amid Market Boom

    December 6, 20232 Mins Read

    GBTC Discount Shrinks as Bitcoin Price Surges

    December 6, 20232 Mins Read

    IBM Introduces OSO, Designed for Cold Storage of Digital Assets

    December 6, 20232 Mins Read

    Marathon Digital Produced 1,187 Bitcoins in November and Held 14,025 Unrestricted BTC

    December 5, 20232 Mins Read

    Volume Counterfeiting Allegations Rock RATS Token on Gate Exchange

    December 5, 20232 Mins Read

    A New Era for Cryptocurrency: Zodia Custody’s Integration with Harmonize

    December 4, 20232 Mins Read

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 Blockchain Journal

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.