Official MASTR logo MASTR Support the work
Contents
← Wiki home

Crypto history

Curve Vyper reentrancy incident

Several Curve pools were exploited in 2023 after a compiler issue affected protections in specific Vyper versions.

Reference note · Sources below

Research articles and reference entries are published in English. Navigation is available in seven languages.

People & projects

In this article
  1. Overview
  2. Why it matters
  3. What to check
  4. Sources

Overview

Several Curve pools were exploited in 2023 after a compiler issue affected protections in specific Vyper versions.

Why it matters

Source intent, compiler output and deployed bytecode all mattered.

What to check

Do not generalise the vulnerable version to every pool or Vyper contract.

Sources

Related reading

security

Reentrancy

An external call transfers control before the caller finishes state updates.

MASTR

Support independent research

The investigations, original evidence and guides here are free to read. Voluntary donations help fund the research and keep MASTR’s tools available.

Open wallet