Revoke.cash logo

Curve Frontend Hack

Check if your address is affected.

9 Aug 2022
$610k stolen
Ethereum Logo

Curve is one of the largest decentralized exchanges and is best known for swapping stablecoins. On 9 August 2022, attackers took over the DNS settings of its main website, curve.fi, which decide where the web address leads. Curve's founder said the domain registrar iwantmyname had its nameservers compromised, rather than Curve's own account being hacked. For a few hours, visitors to curve.fi were sent to a cloned version of the site that looked the same but asked them to approve a malicious contract controlled by the attackers.

Users who approved that contract had their stablecoins, such as USDC and DAI, drained from their wallets. In total about $610k was taken on Ethereum. The attacker swapped the stolen funds to ETH and sent most of it to the exchange service FixedFloat, with smaller amounts going to Binance and Tornado Cash. FixedFloat froze 112 ETH, and Binance said it had recovered a large share of the stolen funds and was working with law enforcement to return them to their owners.

Only the website was attacked. Curve's pools and smart contracts were never at risk, and the alternative site curve.exchange was not affected. However, the malicious contract still belongs to the attackers, so any approval given to it can still be used to take the approved tokens. If you used curve.fi on 9 August 2022, check your wallet for approvals to this contract and revoke them. At the time, Curve asked everyone who had approved contracts on its site in the hours before to revoke them immediately.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits