MEV Operator Refunds $5.4m To Curve Amidst Major Exploit

An extraordinary surge in maximum extractable value MEV block rewards occurred on Ethereum following a turbulent exploit targeting specific liquidity pools on the decentralized exchange Curve Finance. https://twitter.com/CurveFinance/status

Yusoff Kim2 min read
ShareXLinkedInTelegram
MEV Operator Refunds $5.4m To Curve Amidst Major Exploit

An extraordinary surge in maximum extractable value (MEV) block rewards occurred on Ethereum following a turbulent exploit targeting specific liquidity pools on the decentralized exchange Curve Finance.

https://twitter.com/CurveFinance/status/1685925429041917952?s=20

Yesterday witnessed the most lucrative day for MEV since the Merge that took place last year, with approximately 6,006 ETH ($11.1 million) distributed as MEV rewards to validators, according to data from mevboost.pics.

https://twitter.com/econoar/status/1685778343697018881?s=20

Detailed examination of on-chain data from the Ethereum blockchain highlighted multiple slots that yielded significant MEV rewards.

Notably, slot 6,992,273 recorded a reward of 584 ETH (approximately USD$1m) , slot 6,993,342 offered 345 ETH (~USD$640,000), and slot 6,992,050 closely followed with a reward of 247 ETH (SD$459,000).

These observations were first made by analyst and investor Eric Conner, also known as Eric.eth on Twitter,and all three events occurred within the past 24 hours. These figures bear importance, considering that the average MEV payment per block stands at about USD$100, or 0.06 ether per block.

White Hat MEV Operator Saves Curve $5.4m

On-Chain MEV Operator c0ffeebabe.eth managed to front-run any potential exploits on the affected curve pool, just moments before any other malicious transactions were able to fully drain the CRV-ETH pool.

https://twitter.com/bantg/status/1685780920693846016?s=20

The white hat hacker managed to front-run a malicious hacker, saving 2,879 ETH, or approximately USD$5.4m in the process, and later returning it to the curve deployer address.

https://twitter.com/PeckShieldAlert/status/1685696196839649280?s=20

However, approximately USD$52 million in funds were still stolen from Curve in multiple other attacks, affecting the treasuries of protocols such as MetronomeDAO and JPEGd.

While a full post-mortem has yet to be published, security audit firm PeckShield has notified users that the vulnerability laid in reentrancy issues in Curve's smart contract code due to using an outdated version of the Vyper programming langugage.

Reentrancy exploits allow malicious users to "call" the same function multiple times, such as multiple illicit withdrawals above the appropriate threshold.

Also Read: 30 Crypto Hacks Over $30M, Broken Down

[Editor’s Note: This article does not represent financial advice. Please do your own research before investing.]

Featured Image Credit: Chain Debrief

ShareXLinkedInTelegram

Get the Chain Debrief newsletter

Crypto & Web3 analysis, weekly.

Related reading

Trump's Impact on Cryptocurrency Regulations Explained
Top Stories

Trump's Impact on Cryptocurrency Regulations Explained

On March 6, 2025, President Donald Trump signed an executive order to establish a Strategic Bitcoin Reserve and a Digital Asset Stockpile. This new approach contrasts with the past, where the U.S. government sold seized Bitcoin early, missi

ThorChain, A Tool for Laundering Stolen Assets
Top Stories

ThorChain, A Tool for Laundering Stolen Assets

On March 4, 2025, Bybit CEO Ben Zhou confirmed that $1.07 billion of the stolen assets from the recent $1.4 billion breach could still be traced. The hack occurred on February 21, 2025, when hackers managed to steal over 499,000 ETH along w