Hackers Begin Returning Funds to Curve Finance

After Curve Finance sent on-chain messages to the hackers, the first batches of funds have started being returned to the affected projects.

Background on the Curve Finance Exploit
On July 30, vulnerabilities in the liquidity pools of Curve Finance, which use the Vyper language, were exploited by hackers. The projects impacted include:
- JPEG'd: approximately $11 million
- Metronome: approximately $1.6 million
- Alchemix: $11 million (already returned by a white-hat hacker) + $20.6 million
- CRV-ETH Pool: $19 million still held by the hacker + $5.3 million returned by white-hat hacker coffeebabe.eth
Funds Being Returned
As of the evening of August 04, front-running accounts and hackers have started returning the stolen funds. The first return was from the front-running hacker of the pETH-ETH pool of JPEG'd, who refunded a total of 6,107 ETH, valued at approximately $11 million.
Seems like @JPEGd_69 exploiter refunded 6,106.75 $ETH.https://t.co/x18BuDYzYN pic.twitter.com/xDKIQNRKN0
— MistTrack🕵️ (@MistTrack_io) August 4, 2023
"Seems like @JPEGd_69 exploiter refunded 6,106.75 $ETH." — MistTrack (@MistTrack_io) August 4, 2023
By the morning of August 05, the JPEG'd team confirmed they had received 5,495.4 WETH from the hacker, and they committed not to pursue legal action, allowing the hacker to keep 10% of the stolen funds as a bug bounty.
The JPEG'd DAO confirms receipt of 5,494.4 WETH back to the JPEG'd Multisig for a total of 5,495.4 WETH. A 10% white-hat bounty of 610.6 WETH was awarded to the owner of the address that recovered funds from the pETH exploit.https://t.co/nIBwHHxfQU
— JPEG'd (@JPEGd_69) August 4, 2023
Similarly, the hacker of the Alchemix pool sent 1 alETH to the Curve Finance Deployer wallet as a test transaction.
In response, Curve Finance representatives sent a message asking the hacker to return the funds to the Alchemix multisig address.
Confirming that Curve Deployer 2 [0xbabe61887f1de2713c6f97e567623453d3C79f67] sends a message to alETH pool hackerhttps://t.co/abgkFlSbeN
— Curve Finance (@CurveFinance) August 4, 2023
Alchemix later confirmed that their multisig address had started receiving returned funds from the hacker.
We have received the test tx funds at 0x9e2b6378ee8ad2A4A95Fe481d63CAba8FB0EBBF9https://t.co/FZraob2wMq
— Alchemix (@AlchemixFi) August 4, 2023
Remaining Pools and Future Actions
As of now, the CRV-ETH and Metronome pools have not been contacted by the hackers for fund returns. On the morning of August 04, Curve Finance also sent an on-chain message offering a 10% reward if these hackers return the stolen funds by August 06.