📈 Get daily crypto insights that make you smarter about your money

dForce Protocol Recovers $3.65 Million After Read-Only Reentrancy Exploit Across Arbitrum and Optimism

The decentralized finance protocol dForce has recovered all $3.65 million in exploited funds after a sophisticated read-only reentrancy attack targeted its wstETH/ETH pool integration with Curve Finance on both Arbitrum and Optimism. The incident, which unfolded on February 10, highlighted persistent vulnerabilities in DeFi’s most trusted infrastructure components.

The Exploit Mechanics

The attacker executed a carefully choreographed sequence exploiting a well-documented read-only reentrancy vulnerability in Curve Finance’s liquidity pools. The exploit began with flash-loaned funds deposited into Curve’s wstETH/ETH pool. The attacker then deposited the resulting LP tokens into dForce’s wstETHCRV-gauge vault on both Arbitrum and Optimism.

Upon calling the remove_liquidity function, the attacker’s malicious contract reentered the protocol during the callback, manipulating the virtual price that dForce used as an oracle for wstETHCRV-gauge tokens. This price manipulation allowed the attacker to profit from the liquidation of other users who had used wstETHCRV-gauge as collateral. The operation netted approximately $1.9 million on Arbitrum and $1.7 million on Optimism.

The attacker’s Ethereum address was funded through Railgun on the mainnet, with funds bridged to Optimism and Arbitrum via Synapse. Blockchain security firms SlowMist and PeckShield were among the first to identify and analyze the attack transactions.

Affected Systems

dForce’s lending protocol was the primary target, specifically its wstETHCRV-gauge vault integration. The attack affected users on both Arbitrum and Optimism layer-2 networks. Users who had supplied funds to dForce Lending and other vaults remained safe, as the exploit only affected positions using the wstETHCRV-gauge as collateral.

This was not dForce’s first encounter with a major exploit. In April 2020, the protocol lost $25 million to an ERC-777 reentrancy vulnerability, though those funds were also eventually recovered. The recurring nature of these incidents raises questions about protocol security practices and the thoroughness of pre-deployment audits.

The Mitigation Strategy

dForce responded by immediately pausing all vaults after confirming the incident. The team publicly stated that user funds in lending vaults and other unaffected positions were safe. They also sent on-chain transactions directly to the attacker’s address on both networks, offering a white-hat bounty via transaction input data.

The remarkable turnaround came on February 13, when the exploiter returned all funds to dForce’s multisig wallets on both Arbitrum and Optimism. dForce confirmed the recovery and pledged that all impacted users would be made whole, with distribution details to follow in subsequent days.

Lessons Learned

The most troubling aspect of this exploit is that the vulnerability was already well-known. ChainSecurity originally reported the read-only reentrancy issue to Curve and affected projects in April 2022, nearly a year before the dForce attack. Curve Finance itself had provided a known workaround: calling any method with the nonreentrant lock, such as removing zero liquidity, which represents the cheapest mitigation.

Similar exploits had already hit Midas Capital and Market.xyz using the exact same vector. The pattern underscores a systemic failure in DeFi: known vulnerabilities continue to cause losses because protocols either fail to implement available fixes or are unaware of the disclosures.

User Action Required

For DeFi users, this incident serves as a reminder to diversify collateral types and avoid overconcentration in any single protocol’s vault strategy. Users should verify that protocols they interact with have implemented the latest security patches, particularly for well-documented vulnerabilities like Curve’s read-only reentrancy. With Bitcoin trading at approximately $21,800 and Ethereum at $1,507, the broader market remains sensitive to negative sentiment from exploits, making individual vigilance even more critical.

Disclaimer: This article is for informational purposes only and does not constitute financial advice. Always conduct your own research before interacting with any DeFi protocol.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “dForce Protocol Recovers $3.65 Million After Read-Only Reentrancy Exploit Across Arbitrum and Optimism”

  1. using Curve LP tokens as collateral without an independent oracle is literally the 2021 reentrancy playbook. dForce should have known better

  2. full recovery in 3 days is actually impressive. most protocols just freeze and hope people forget. respect to dForce for negotiating with the attacker

    1. attacker returned the funds. probably saw the heat and decided a whitehat bounty was the better play. smart move honestly

    2. full recovery in 3 days is genuinely rare. dForce must have had serious leverage in those negotiations with the attacker

    3. full recovery is rare. dForce getting the attacker to return everything in 3 days means their comms team earned their paycheck. most teams just post a vague governance proposal and hope

    1. flash loans turned every solidity dev into a potential attacker. the barrier to exploiting a reentrancy bug went from needing capital to needing zero capital overnight

      1. flash_loan_rat_

        Sasha M. flash loans dropped the capital requirement to zero. every broke dev student became a potential attacker overnight

  3. splitting the attack across Arbitrum and Optimism to avoid single chain monitoring is smart tradecraft honestly. most exploiters just brute force one chain

  4. 3.65M recovered in 3 days but the real question is why dForce was using Curve LP tokens as collateral without their own oracle. copy pasta security model

    1. Hassan T. using Curve LP tokens as collateral without an independent oracle is the kind of thing that should fail a basic audit checklist. copy pasta security at its finest

      1. Piotr W. using Curve LP as collateral without independent oracle is the kind of thing that should fail any competent audit. literally page one of integration risks

  5. 1.9M on Arbitrum and 1.7M on Optimism. attacker split across two chains to avoid triggering single-chain alerts. clean execution

    1. arb_op_split splitting across two chains to avoid single-chain alerts is actually sophisticated tradecraft. most attackers are sloppy

      1. splitting the attack across arbitrum and optimism to dodge single chain alerts is actually clean tradecraft. most exploiters are sloppy

  6. reentrancy_log_

    read-only reentrancy is 2021 knowledge. dForce integrating Curve gauge tokens in 2023 without guards means nobody on their team read the Curve docs past page one

  7. read-only reentrancy has been documented since 2021. how many more protocols need to get hit before teams audit their oracle integrations properly

    1. its always Curve integration code. protocols plug in virtual price as an oracle without adding reentrancy guards. how is this still a thing in 2023

      1. copy_pasta_audit

        audit_skip Curve integration code copied without understanding virtual price oracle assumptions. same bug different protocol since 2021

        1. audit_skip copy pasting Curve integration code without understanding virtual price assumptions is how you lose 3.65M in a weekend

        2. copy_pasta_audit the Curve integration pattern is identical every time. deposit LP token, use virtual price as oracle, get drained. copy paste security

          1. deposit Curve LP tokens, use virtual price as oracle, get drained. literally the same pattern since 2021 and teams keep copy pasting

    2. vaultwatch documented since 2021 and teams still plug Curve LP tokens as oracle without reentrancy guards in 2023. some lessons never stick

    3. read-only reentrancy keeps popping up because protocols copy Curve integration code without understanding the oracle assumptions. its the same bug different wrapper every time

  8. 3.65M recovered in 3 days is the exception not the rule. most teams just freeze the protocol and hope everyone forgets

  9. read-only reentrancy on Curve LP tokens used as collateral. this exact pattern was documented in Curve docs and teams still integrated without guards

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,998.00+0.4%ETH$1,919.87+0.6%SOL$76.12+3.9%BNB$604.18+2.2%XRP$1.04+2.7%ADA$0.2001+0.1%DOGE$0.0709+2.0%DOT$0.8176+1.2%AVAX$6.53+2.1%LINK$8.32+1.7%UNI$3.99-0.5%ATOM$1.39+3.0%LTC$45.91+1.2%ARB$0.0791+1.5%NEAR$1.63+2.4%FIL$0.7183+5.6%SUI$0.6940+3.7%BTC$64,998.00+0.4%ETH$1,919.87+0.6%SOL$76.12+3.9%BNB$604.18+2.2%XRP$1.04+2.7%ADA$0.2001+0.1%DOGE$0.0709+2.0%DOT$0.8176+1.2%AVAX$6.53+2.1%LINK$8.32+1.7%UNI$3.99-0.5%ATOM$1.39+3.0%LTC$45.91+1.2%ARB$0.0791+1.5%NEAR$1.63+2.4%FIL$0.7183+5.6%SUI$0.6940+3.7%
Scroll to Top