MKT
DeFi protocol

Curve

Where stablecoins actually trade, and the protocol drained for $73.5m in 2023 by a bug in the Vyper compiler rather than in its own code.

Founded
2020
Registered
Switzerland

The short answer

It is infrastructure other infrastructure depends on — Curve’s pools are where stablecoins and pegged assets actually trade, and several tokens elsewhere on this site rely on that depth to hold their peg. In July 2023 a reentrancy bug in specific Vyper compiler versions, not in Curve’s own code, drained about $73.5m from four pools; roughly 73% came back within a week because two of the attackers negotiated. We score its record 5 out of 10 and its coverage 9.

Key facts

RoleWhere stablecoins and pegged assets actually trade. Several tokens rated elsewhere on this site depend on Curve depth to hold their peg.as of 14 Jul 2026
July 2023 exploitA reentrancy bug in specific Vyper compiler versions — not in Curve’s code — drained about $73.5m from four poolsas of 14 Jul 2026
RecoveryRoughly 73% returned within a week, because two of the attackers negotiatedas of 14 Jul 2026
Record score5 out of 10as of 14 Jul 2026
Coverage9 out of 10 on the DeFi cardas of 14 Jul 2026
Capital efficiency3 out of 10 on the DEX card — the weakest criterion it carriesas of 14 Jul 2026
Rating cardsTwo: decentralised exchanges and DeFi protocolsas of 14 Jul 2026

The 2023 exploit was in the compiler, not the contract

In July 2023 about $73.5m was drained from four Curve pools. The bug was a reentrancy flaw in specific versions of the Vyper compiler — the tool that turns source code into deployed bytecode — and not in anything Curve wrote.

That distinction matters and it does not absolve. A protocol is responsible for its dependencies: choosing a language, pinning a compiler version and reviewing what that toolchain produces are all part of shipping contracts that hold other people’s money. The failure was real. It was a supply-chain failure rather than a design failure, which is the same category as the compromised signing tool that cost Bybit $1.4–1.5bn.

Roughly 73% of the funds came back within a week, because two of the attackers negotiated and returned them. That is a genuinely good recovery rate and it rested on the goodwill of people who had just stolen the money, which is not a control anyone should count on twice.

We score its record 5 out of 10 — middling, reflecting a real loss with a substantial recovery, against protocols like Aave that have had no depositor-loss event at all.

Infrastructure that other infrastructure depends on

Curve’s importance is not captured by its own volume. Its pools are where stablecoins and pegged assets actually trade against each other, which means the depth sitting in them is what holds several other tokens near their peg — including assets we rate elsewhere on this site.

That makes it a systemic dependency in a way a comparably sized general-purpose exchange is not. If Curve depth thins, the effect shows up in the peg stability of things that are not Curve, and the people holding those assets will mostly not know why.

Coverage scores 9 out of 10 on the DeFi card, reflecting how widely deployed it is. Capital efficiency scores 3 out of 10 on the DEX card, the weakest criterion it carries: the stableswap design that makes pegged assets trade tightly does so by holding a great deal of liquidity relative to the volume it turns over. That is a trade, not a flaw — the depth is the product.

Incident record

DateTypeAmountWere users made whole?
30 Jul 2023Hack or exploit$73,500,000Roughly 73% came back within a week, because two of the attackers negotiated and returned funds. The bug was in specific Vyper compiler versions rather than in Curve’s own contracts — a dependency failure, which is a different thing from a design failure and still a loss.$53,000,000 returnedsource

In our ratings

Compared with

Our coverage of Curve

Questions people ask

Was Curve hacked?

In July 2023 about $73.5m was drained from four pools by a reentrancy bug in specific Vyper compiler versions — not in Curve’s own code. Roughly 73% came back within a week because two attackers negotiated. We score its record 5 out of 10.

Is it fair to blame Curve for a compiler bug?

Partly. Choosing a language, pinning a compiler version and reviewing the toolchain’s output are part of shipping contracts that hold other people’s money. It is a supply-chain failure rather than a design failure — the same category as the signing tool that cost Bybit $1.4-1.5bn.

Why does Curve matter beyond its own volume?

Its pools are where stablecoins and pegged assets actually trade, so the depth in them is what keeps several other tokens near their peg — including assets rated elsewhere on this site. If Curve depth thins, the effect appears in things that are not Curve.

Why is Curve’s capital efficiency score low?

It scores 3 out of 10 because the stableswap design holds a lot of liquidity relative to the volume it turns over. That is the mechanism that makes pegged assets trade tightly rather than a flaw — the depth is the product.

What changed

  • 27 Sept 2026 — Profile published.