Curve
Where stablecoins actually trade, and the protocol drained for $73.5m in 2023 by a bug in the Vyper compiler rather than in its own code.
- Founded
- 2020
- Registered
- Switzerland
- Site
- curve.fi
The short answer
It is infrastructure other infrastructure depends on — Curve’s pools are where stablecoins and pegged assets actually trade, and several tokens elsewhere on this site rely on that depth to hold their peg. In July 2023 a reentrancy bug in specific Vyper compiler versions, not in Curve’s own code, drained about $73.5m from four pools; roughly 73% came back within a week because two of the attackers negotiated. We score its record 5 out of 10 and its coverage 9.
Key facts
| Role | Where stablecoins and pegged assets actually trade. Several tokens rated elsewhere on this site depend on Curve depth to hold their peg.as of 14 Jul 2026 |
|---|---|
| July 2023 exploit | A reentrancy bug in specific Vyper compiler versions — not in Curve’s code — drained about $73.5m from four poolsas of 14 Jul 2026 |
| Recovery | Roughly 73% returned within a week, because two of the attackers negotiatedas of 14 Jul 2026 |
| Record score | 5 out of 10as of 14 Jul 2026 |
| Coverage | 9 out of 10 on the DeFi cardas of 14 Jul 2026 |
| Capital efficiency | 3 out of 10 on the DEX card — the weakest criterion it carriesas of 14 Jul 2026 |
| Rating cards | Two: decentralised exchanges and DeFi protocolsas of 14 Jul 2026 |
The 2023 exploit was in the compiler, not the contract
In July 2023 about $73.5m was drained from four Curve pools. The bug was a reentrancy flaw in specific versions of the Vyper compiler — the tool that turns source code into deployed bytecode — and not in anything Curve wrote.
That distinction matters and it does not absolve. A protocol is responsible for its dependencies: choosing a language, pinning a compiler version and reviewing what that toolchain produces are all part of shipping contracts that hold other people’s money. The failure was real. It was a supply-chain failure rather than a design failure, which is the same category as the compromised signing tool that cost Bybit $1.4–1.5bn.
Roughly 73% of the funds came back within a week, because two of the attackers negotiated and returned them. That is a genuinely good recovery rate and it rested on the goodwill of people who had just stolen the money, which is not a control anyone should count on twice.
We score its record 5 out of 10 — middling, reflecting a real loss with a substantial recovery, against protocols like Aave that have had no depositor-loss event at all.
Infrastructure that other infrastructure depends on
Curve’s importance is not captured by its own volume. Its pools are where stablecoins and pegged assets actually trade against each other, which means the depth sitting in them is what holds several other tokens near their peg — including assets we rate elsewhere on this site.
That makes it a systemic dependency in a way a comparably sized general-purpose exchange is not. If Curve depth thins, the effect shows up in the peg stability of things that are not Curve, and the people holding those assets will mostly not know why.
Coverage scores 9 out of 10 on the DeFi card, reflecting how widely deployed it is. Capital efficiency scores 3 out of 10 on the DEX card, the weakest criterion it carries: the stableswap design that makes pegged assets trade tightly does so by holding a great deal of liquidity relative to the volume it turns over. That is a trade, not a flaw — the depth is the product.
Incident record
| Date | Type | Amount | Were users made whole? |
|---|---|---|---|
| 30 Jul 2023 | Hack or exploit | $73,500,000 | Roughly 73% came back within a week, because two of the attackers negotiated and returned funds. The bug was in specific Vyper compiler versions rather than in Curve’s own contracts — a dependency failure, which is a different thing from a design failure and still a loss.$53,000,000 returnedsource |
In our ratings
Compared with
Our coverage of Curve
- How to spot a fake proof of reserves27 Sept 2026
- Bitget loses $351.6m — and the fund it says covers it is one we could not verify25 Sept 2026
- Is Kraken safe? The evidence, and what it lacks25 Sept 2026
- What happens to your coins if an exchange goes bankrupt23 Sept 2026
- Is Coinbase safe? What its own filings say19 Sept 2026
- How to move crypto off an exchange, step by step17 Sept 2026
- Token approvals: the permission that drains wallets15 Sept 2026
- What "not your keys, not your coins" leaves out9 Sept 2026
- The seed phrase mistakes that cost people everything7 Sept 2026
- Hardware wallet or software wallet: how to decide5 Sept 2026
Questions people ask
Was Curve hacked?
In July 2023 about $73.5m was drained from four pools by a reentrancy bug in specific Vyper compiler versions — not in Curve’s own code. Roughly 73% came back within a week because two attackers negotiated. We score its record 5 out of 10.
Is it fair to blame Curve for a compiler bug?
Partly. Choosing a language, pinning a compiler version and reviewing the toolchain’s output are part of shipping contracts that hold other people’s money. It is a supply-chain failure rather than a design failure — the same category as the signing tool that cost Bybit $1.4-1.5bn.
Why does Curve matter beyond its own volume?
Its pools are where stablecoins and pegged assets actually trade, so the depth in them is what keeps several other tokens near their peg — including assets rated elsewhere on this site. If Curve depth thins, the effect appears in things that are not Curve.
Why is Curve’s capital efficiency score low?
It scores 3 out of 10 because the stableswap design holds a lot of liquidity relative to the volume it turns over. That is the mechanism that makes pegged assets trade tightly rather than a flaw — the depth is the product.
What changed
- 27 Sept 2026 — Profile published.