logo

Curve Conundrum: The dForce Attack via a Read-Only Reentrancy Vector Exploit

ID: b8f8f26c-65d4-5052-9c3c-3b4fef7767d8

STIX ID: report--b8f8f26c-65d4-5052-9c3c-3b4fef7767d8

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2024-01-08

Date Updated: 2026-06-11

...
...

On Feb 9, 2023 dForce's lending protocol was exploited for $3.7M after an attacker used a read-only reentrancy in a Curve-based price oracle to manipulate collateral valuation and withdraw funds; the issue involved price manipulation via external calls and was outside the CertiK audit scope.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.