bitcoin
bitcoin

$92880.04 USD 

-1.81%

ethereum
ethereum

$3361.20 USD 

-2.46%

tether
tether

$0.999457 USD 

-0.07%

solana
solana

$233.24 USD 

-2.49%

bnb
bnb

$617.53 USD 

-4.27%

xrp
xrp

$1.38 USD 

-5.15%

dogecoin
dogecoin

$0.391307 USD 

-4.09%

usd-coin
usd-coin

$0.999973 USD 

0.01%

cardano
cardano

$0.952253 USD 

-2.83%

avalanche
avalanche

$43.09 USD 

1.17%

tron
tron

$0.196439 USD 

-1.40%

toncoin
toncoin

$6.27 USD 

0.23%

shiba-inu
shiba-inu

$0.000025 USD 

-2.86%

stellar
stellar

$0.434223 USD 

-15.10%

polkadot-new
polkadot-new

$8.11 USD 

-3.42%

Cryptocurrency News Articles

Curve Finance Rewards Researcher $250k for Critical Bug Discovery

May 02, 2024 at 10:06 pm

Curve Finance, a leading decentralized financial platform, recently rewarded a security researcher for discovering a critical vulnerability in its system. The vulnerability, discovered by Marco Croc of Kupia Security, could have allowed hackers to manipulate balances and withdraw funds from Curve Finance liquidity pools. Curve Finance conducted a thorough investigation and awarded the researcher a maximum bug bounty for their contribution.

Curve Finance Rewards Researcher $250k for Critical Bug Discovery

Curve Finance Rewards Researcher for Critical Vulnerability Discovery

Jakarta, Indonesia - In a significant development, Curve Finance, a prominent decentralized finance (DeFi) platform, has bestowed a reward of 250 thousand US dollars (approximately IDR 4,063,750,000) to Marco Croc, a security researcher from Kupia Security. Croc's astute discovery of a critical vulnerability within Curve Finance's system has garnered widespread attention and underscored the importance of robust cybersecurity measures in the realm of decentralized finance.

Vulnerability Potential for Manipulation and Theft

The reentrancy vulnerability unearthed by Marco Croc possesses the ability to empower malicious actors with the means to manipulate account balances and siphon funds from Curve Finance's liquidity pools. Such a scenario poses substantial risks to the platform's ecosystem, prompting Curve Finance to swiftly initiate a comprehensive investigation and extend the maximum bug bounty récompense to the researcher as a token of appreciation for their invaluable contribution.

Importance of Responsible Hacking Ethics

While the vulnerability was not deemed to be of great severity, Curve Finance acknowledges that security incidents, regardless of their perceived magnitude, have the potential to generate apprehension among users. Consequently, the récompense serves as an incentive to foster responsible hacking ethics, thereby buttressing the defenses of the protocol against future exploitation attempts.

Post-Attack Recovery Efforts

This récompense is an integral aspect of Curve Finance's recovery strategy following a US$ 62 million attack in July. In an effort to restore the trust and assets of liquidity providers, the protocol recently conducted a vote to replace US$ 49.2 million (approximately IDR 799,644,000,0001) of lost assets. The proposal was overwhelmingly supported by 94% of Curve DAO (CRV) token holders, encompassing losses incurred across various pools, including JPEGd (JPEG), Alchemix (ALCX), and Metronome (MET).

Replacement Plan Details

The replacement plan outlines the utilization of CRV tokens from community funds, coupled with the inclusion of tokens successfully recovered since the incident. Consequently, the final distribution will entail the disbursement of 55,544,782.73 CRV, with the computed amount of Ethereum (ETH) and CRV to be retrieved being 5,919.2226 ETH and 34,733,171.51 CRV, respectively.

Technical Details of Vulnerability

As reported by Cryptonews, the vulnerability exploited by the perpetrators specifically targeted the liquidity pool mechanism designed to maintain stability. The vulnerability was found to be present in specific versions of the Vyper programming language (0.2.15, 0.2.16, and 0.3.0), enabling unauthorized withdrawal of funds through reentrancy attacks.

Conclusion

The discovery of this vulnerability and the subsequent reward to the responsible researcher underscore the criticality of cybersecurity measures in the burgeoning DeFi ecosystem. Curve Finance's commitment to responsible hacking ethics and proactive incident response serves as a testament to the importance of collaboration between security researchers and organizations in safeguarding the interests of users and maintaining the integrity of decentralized finance platforms.

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Nov 27, 2024