On July 31, 2023, according to Secure3, a blockchain security audit contest platform, multiple protocols including Curve were attacked. Further analysis revealed that the root cause was vulnerabilities in the underlying Vyper compiler for the Ethereum smart contract programming language. Versions 0.2.15, 0.2.16 and 0.3.0 contained serious flaws, resulting in multiple attacks on projects like Curve Finance, Alchemix and JPEG’d, inflicting losses totaling around $70 million. The Secure3 security team determined that the fundamental reason behind the attacks was the failure of reentrancy locks in the vulnerable Vyper versions. Secure3’s security team analyzed the factors behind this incident.
The root cause of the attacks stemmed from logical defects in the reentrancy lock implementation in Vyper versions 0.2.15, 0.2.16 and 0.3.0, which led to failure of the reentrancy locks. The reentrancy lock variables in different functions do not share the same storage location, resulting in ineffective protection against cross-function reentrancy attacks.
This vulnerability was subsequently fixed in Vyper 0.3.1 by making the reentrancy lock variables share the same storage slot.
The Secure3 security team recommends:
Headquartered in Silicon Valley, Secure3 is an intelligent audit contest platform, aiming to reshape Web3 safety by providing efficient, affordable, and secure smart contract auditing services for all Web3 projects.
Secure3’s audit contest organizes decentralized certified auditors in the form of an audit competition. With 3–10x more auditors (compared to centralized auditing firms) working on the project independently, anonymously, and simultaneously, Secure3 has proven successful in providing cost-efficient and high-quality auditing services. In the past year, Secure3 has done over 100 projects including industry leaders, such as zkSync, Mantle, Manta Network, IoTeX, ParaSpace, MirrorWorld, etc.
Secure3 was incubated by Stanford StartX in 2022, and closed $5M seed funding from Mirana, GGV, Alumni Ventures, Hashkeys, etc.
Boost Security, Fuel Innovation
Get straight to the insights
On August 14, 2023, according to Secure3, a blockchain security audit contest company, the decentralized yield aggregator ZunamiProtocol was attacked, resulting in a loss of more than 2 million US dollars. The Secure3 security team analyzed that the root cause of this attack was that the LP asset price calculation logic in ZunamiProtocol had defects, and the attacker used it to manipulate the price. The Secure3 security team summarized the reasons for this incident.
On July 7, 2023, according to Secure3, a blockchain security audit contest platform, Fantom Bridge from Multichain was attacked. Multichain has announced through its official Twitter that it has suspended all bridge services and has no estimated resume time yet. The Secure3 security team analyzed and found that there is no evidence showing this is caused by smart contract vulnerability, suspecting that the attack may have been caused by the comproise of the MPC wallet multi-signature private key, causing a loss of about $126 million.
Team Secure3 recently discovered a malicious attack on the OMNI Protocol, with the hacker stealing almost 2000 ETH (~2.4M USD) from OMNI.
Get In Touch
audit@secure3.io