Aug 07, 2023
SOC Team
Recap of the shocking Curve Finance exploiter
1. Curve Finance and parties got hacked:
- July 30 UTC, around $61M worth of digital assets was exploited in the Curve Finance hack:
- Alchemix: 7,259 $ETH ($13.5M) + 4,819 $alETH ($8.97M)
- JPEG'd: 6,106 $ETH ($11.4M)
- Metronome: 866 $ETH ($1.6M) + 955 $smETH ($1.74M)
- CRV-ETH pool: 10,560 $ETH ($19.4M) and 7,193,401 $CRV ($4.42M)
- check out the previous signal here
2. Curve Finance founder sold $CRV via OTC:
- After sharp $CRV price drop post-hack made his $168M worth of $CRV-collateralized loan position at risk of liquidation, Curve Finance's founder, Michael Egorov, started to sell $CRV via OTC to pay off debt.
- From Aug 1 to Aug 6 (just now), the founder has sold:
- total sold: 142.8M $CRV
- avg OTC price: $0.4
- number of entities involved: 32
- prominent buyers: DWF Labs (12.5M $CRV), xDai (6.25M $CRV) and Justin Sun (5M $CRV)
- For more details, visit our Dune dashboard here
- Curve Finance's founder's address: 0x7a16ff8270133f063aab6c9977183d9e72835428
3. Curve exploiter returned stolen funds:
- July 30 (right after the exploit): exploiter coffeebabe.eth returned 786 $ETH ($1.45M) & 955 $smETH ($1.74M) to Metronome DAO and 2,879 $ETH ($5.36M) to Curve Finance
- 955 smETH txid: 0x7c4ba39dad59ad91f9f0102de833fbc5a8f40122d796e73022ec57c6d29e439f
- 786 $ETH txid: 0x650a73bfff233815ec6c4de22f105ddff8d5194d10b7375b3cdcd23ec6469f9a
- 2,879 $ETH txid: 0xb76754124fdde090f25129105ed2907e3c62e0db87ecb8ffcefcb1dede0954fd
- August 3: CRV foundation sent an on-chain message to the exploiter, offering them a 10% bounty of any funds stolen, if they were to return the remaining 90% by Aug 6, 8 AM UTC.
- August 4:
- exploiter 0x6ec returned 5,495 $WETH ($10M) to JPEG'd and kept 610 $ETH ($1.1M) as 10% bounty via address 0x9d1ec3375252d4ab3c128f9774be266f67faa0bd
- exploiter 0xdce returned 2,258 $ETH ($4.15M) and 4,820 $alETH ($8.82M) to Alchemix Finance
- address 1: 0x6ec21d1868743a44318c3c259a6d4953f9978538
- address 2: 0xdce5d6b41c32f578f875efffc0d422c57a75d7d8
- August 5: exploiter 0xdce the remaining 4,999 $ETH ($9.18M) to Alchemix Fi (all were returned)
- txid 1: 0xdbf1d8dca9858119e3852d52f18821754640013d9914d692589b13f8181a08e8
- txid 2: 0x0bf820a8fb3656d2f57be119d801a08bfbd0d78b6653c62b928df70a2f10df0b
- End of August 5: 68% of the stolen assets (or $40.7M) has been returned in total.
- August 6: Curve Finance closed deadline for the exploiter to return the stolen fund
- 32% of the stolen assets (~$18.8M) has not been recovered: 80 $ETH ($147K) from MetronomeDAO (kept by coffeebabe.eth); 7,681 $ETH ($14.4M) and 7.19M $CRV ($4.43M) from CRV-ETH pool
- 10% bounty is now extended to the public
Fig. $CRV price dropped sharply after the exploit.