Alchemix Announces Full Return of Stolen Funds
Lending platform Alchemix has successfully recovered all funds stolen by the Curve Finance hacker. The attack, which occurred on July 30, resulted in the loss of over $61 million in cryptocurrencies, including $13.6 million from Alchemix’s alETH-ETH pool. Other pools affected include JPEGd’s pETH-ETH pool with $11.4 million drained and Metronome’s sETH-ETH pool with over $1.6 million stolen. The hacker exploited vulnerable versions of the Vyper programming language through reentrancy attacks on stable pools in Curve Finance.
Key Points:
– Alchemix announces the return of all stolen funds by the Curve Finance hacker.
– The attack resulted in over $61 million in cryptocurrencies being drained.
– Alchemix’s alETH-ETH pool lost $13.6 million, while JPEGd and Metronome pools lost $11.4 million and $1.6 million, respectively.
– The hacker used reentrancy attacks on vulnerable versions of the Vyper programming language.
– Alchemix, Curve, and Metronome offered a 10% bounty of seized funds for the return of stolen funds.
The return of funds began after the hacker accepted a bug bounty offer. Alchemix, Curve, and Metronome jointly announced the initiative on August 3, offering a 10% reward of the seized funds. They urged the hacker to return the remaining 90%, bringing the bounty close to $7 million. In less than 24 hours after the offer, the hacker began returning the stolen funds, starting with 4,820.55 Alchemix ETH (alETH) on August 5.
The attacker left a message indicating their willingness to return the funds but not because they were afraid of being caught. Instead, they claimed they didn’t want to “ruin” the involved projects. JPEG’d, the nonfungible token protocol, also confirmed that the hacker returned 5,495 Ether. As part of the bounty offer, JPEG’d will not pursue legal action against the perpetrator, viewing the incident as a white-hat rescue.
Hot Take:
The successful recovery of stolen funds by Alchemix is a significant win for the crypto industry. It demonstrates the power of collaboration and bug bounty programs in mitigating the impact of attacks. This incident highlights the importance of robust security measures and constant vigilance to protect users’ funds in decentralized finance.