A reentrancy-lock flaw in specific versions of the Vyper compiler was exploited across several Curve stable pools, draining roughly $73M. Part of it was returned by white-hat actors and MEV bots.
No verified attacker addresses are listed for this incident. We only publish addresses confirmed against an authoritative source.
Figures are approximate, compiled from public reporting. Attacker addresses are included only where verified against an authoritative source. Attribution (e.g. Lazarus Group) is shown only when publicly stated by an official body.
© 2026 ChainAnalyzer. All rights reserved.