On August 1st, Curve Finance's official account retweeted a post from the crypto risk assessment group LlamaRisk, which detailed a post-mortem analysis of the Curve pool reentrancy exploit. According to LlamaRisk's report, a bug in the older version of the Vyper compiler caused a failure in the security feature used by certain limited Curve pools, allowing attackers to deplete the tokens in the affected pools. While Curve is trying to reach out to the exploiters and recover user funds, the exploitation of this vulnerability directly harmed the interests of Curve liquidity providers in the affected pools. Thanks to the efforts of white-hat hackers, the DAO managed to recover some of the tokens from the affected pools. The Curve eDAO is unable to pause the Curve pools or handle user funds in any way, but it can stop the CRV Gauge emissions to the Curve pools. It is expected that the eDAO will eliminate all Gauge emissions to the affected pools.
In this incident, the affected pools and the corresponding losses are as follows:
pETH/ETH pool: 6,106.65 WETH (approximately $11 million).
msETH/ETH pool: 866.55 WETH (approximately $1.6 million) and 959.71 msETH (approximately $1.8 million).
alETH/ETH pool: 7,258.70 WETH (approximately $13.6 million) and 4,821.55 alETH (approximately $9 million).
CRV/ETH pool: 7,193,401.77 CRV (valued at approximately $5.1 million when exploited), 7,680.49 WETH (approximately $14.2 million), and 2,879.65 ETH (approximately $5.4 million).
The total losses for the above pools amount to approximately $61.7 million.
The report also states that the next immediate steps are to stop Gauge emissions to the affected pools and create new plain pools for alETH, msETH, and pETH. The new ETH pool should be paired with ETH or other ETH pools. Additionally, CRV has introduced a new Tricrypto pool paired with crvUSD and ETH, which is not affected by the reentrancy bug. The Curve team will continue exploring all avenues to recover user funds and provide updates on social channels.

