In a shocking turn of events, several stable pools on Curve Finance, along with other decentralized finance (DeFi) projects, fell victim to a devastating exploit on July 30, causing losses amounting to $24 million at the time of reporting. The exploit was traced back to vulnerabilities in specific versions of the Vyper compiler, with versions 0.2.15, 0.2.16, and 0.3.0 being identified as the culprits. Vyper, the Python-based smart contract programming language, acknowledged the seriousness of the situation and urged all projects relying on the affected versions to reach out immediately. The exploit’s mechanism, known as “malfunctioning reentrancy locks,” allowed attackers to bypass the intended safeguards and drain funds from the targeted contracts.