Analysis of the Blockchain Security Chain Events Caused by Vyper Compiler Vulnerabilities

Analysis of the Blockchain Security Chain Events Caused by Vyper Compiler Vulnerabilities

On July 31, 2023, according to Secure3, a blockchain security audit contest platform, multiple protocols including Curve were attacked. Further analysis revealed that the root cause was vulnerabilities in the underlying Vyper compiler for the Ethereum smart contract programming language. Versions 0.2.15, 0.2.16 and 0.3.0 contained serious flaws, resulting in multiple attacks on projects like Curve Finance, Alchemix and JPEG’d, inflicting losses totaling around $70 million. The Secure3 security team determined that the fundamental reason behind the attacks was the failure of reentrancy locks in the vulnerable Vyper versions. Secure3’s security team analyzed the factors behind this incident.

Secure3
·1 min read

Boost Security, Fuel Innovation

Get straight to the insights

Empowering Blockchain Security with Data and Intelligence.

Language:

© All rights reserved by Secure3