Curve Finance Hackers Exploit Vyper Vulnerabilities - Could State-Sponsored Hackers Be Involved?
Hackers Exploit Vyper Vulnerabilities The exploit targeted versions 0.2.15 to 0.3.0 of the Vyper compiler. According to Vyper contributor @fubuloubu, this sophisticated attack likely took weeks, if not months, to prepare. The hackers meticulously trawled through Vyper’s past releases, pinpointing specific vulnerabilities to exploit – an uncommon tactic hinting at the high level of expertise and resources behind the operation. advertisement The impacted pools include CRV /eth, aleth/eth, mseth/eth, and peth/eth. The tri-crypto pool on Arbitrum might also be affected. While auditors and Vyper developers have not identified a profitable exploit in this pool, users are advised to exit as a precaution. Vyper’s code base, being smaller and less frequently updated than most, has generally been perceived as more secure and easier to audit. However, this incident highlights the challenges even in scrutinized and relatively stable compilers. The attack u...