Preview surface — demo data. Where real data exists today (e.g. RealT, BlackRock BUIDL, Lift Dollar) we render it; everywhere else we render synthetic enrichment generated deterministically from public signal and clearly marked Demo or Inferred. The Phase 3 roadmap replaces every synthetic source with live ingestion — see Methodology → Exposure Graph & Similarity Engine.

Curve Finance

Smart-Contract DEXs, AMMs & Aggregatorsmedium·risk 0.4300·TVL ·blast $0·active
Static profile (Identity / Contract / Dependency / Governance / Reputation)

Identity

Sector
Smart-Contract DEXs, AMMs & Aggregators
Subsector tags
infra_tooling, consumer_app, general_defiDemo
Chain deployments
Website
https://www.curve-finance.xyzDemo
Launch date
Immutable
noDemo
Permissionless
yesDemo

Contract

Primary address
Proxy pattern
UNKNOWN
Upgrade authority
UNKNOWN
Multisig threshold
Compiler
0.7.6
Uses assembly
yesDemo
Bug bounty
noneDemo
Contract addresses
0x67c5e39ac6ca8aa476b6a2741e585b70c31f5603Demo
Audits tier
3

Dependency

Oracle providers
Curve Internal
Bridge dependencies
Stablecoin dependencies
crvUSD, DAI, FRAX, USDC, USDT
LST / LRT deps
Demo
DEX liquidity venues
uniswap_v4, aerodromeDemo
CEX listings
Demo
Custodian
Demo
KMS provider
unknownDemo
RPC provider
quicknodeDemo
Frontend host
vercelDemo
npm lockfile sha
sha256:586ad7ff467b1b8ef2db968c407992383a681aea08e4097497df7faf33f0e983Demo

Governance

Governance type
token_votingDemo
Governance token
0xfc27e53c5c10aa9d8a2f980956b45dd673ea9313Demo
Treasury size
$0Demo
Team size
15Demo
Jurisdiction
KRDemo
Incorporated entity
Curve Finance Labs Ltd.Demo
Anonymous team
noDemo
Security disclosure
yesDemo
IR SLA (hours)
48Demo

Reputation

GitHub
https://github.com/curve-finance/curve-financeDemo
Commit velocity (30d)
6Demo
Contributors
20Demo
Twitter
@curve-financeDemo
Discord
https://discord.gg/1jalq18Demo
Last incident
Nov 19, 2024Demo
KYT screening
cleanDemo

Threat History

2 recorded incidents
price impact ammprotocolunknownDemo
$660.7K

On 2024-11-19, Curve Finance suffered a price impact amm incident resulting in approximately $660,738 in losses. The exploit targeted the protocol layer. A flash loan was used to amplify the attack. Attribution: unknown. This is a demonstration entry — not a real incident.

DEMO:AADAPT.TA0040
phishing drainerhuman opunattributed_criminalDemo
$755.7K

On 2024-10-03, Curve Finance suffered a phishing drainer incident resulting in approximately $755,738 in losses. The exploit targeted the human_op layer. Attribution: unattributed_criminal. This is a demonstration entry — not a real incident.

DEMO:AADAPT.TA0001DEMO:AADAPT.TA0040

Peer Incidents · Method B

7 root-cause predicate matches

Vulnerable to: flash loan governance

Matches the flash loan governance predicate

18 historical peer events
  • ThirdwebDemo
    $33.2M
  • LayerZero Labs (physical verification context only)Demo
    $40.2M
  • First Digital USDDemo
    $12.1M
  • Protocol-Native Treasury Agents (DAO-embedded)Demo
    $13.8M
  • F2PoolDemo
    $3.5M
  • + 13 more

Vulnerable to: phishing drainer

Matches the phishing drainer predicate

17 historical peer events
  • GoldfinchDemo
    $1M
  • BitgetDemo
    $739.9K
  • OrcaDemo
    $180.8K
  • Ether.fiDemo
    $443.4K
  • Alchemy PayDemo
    $334.2K
  • + 12 more

Vulnerable to: price impact amm

Matches the price impact amm predicate

17 historical peer events
  • MatchaDemo
    $15.6M
  • Trader JoeDemo
    $3.6M
  • OrcaDemo
    $528.8K
  • BalancerDemo
    $24.3M
  • MeteoraDemo
    $1.5M
  • + 12 more

Vulnerable to: frontend dns hijack

Matches the frontend dns hijack predicate

12 historical peer events
  • Bridge.xyz / StripeDemo
    $10.4M
  • UK FCA Digital SandboxDemo
    $3.6M
  • Three SigmaDemo
    $2.7M
  • CryptoQuantDemo
    $517.3K
  • Celsius (defunct)Demo
    $22M
  • + 7 more

Vulnerable to: supply chain npm

Matches the supply chain npm predicate

10 historical peer events
  • Beefy FinanceDemo
    $176.2K
  • PowerledgerDemo
    $7.4M
  • UnichainDemo
    $8.8M
  • MEXCDemo
    $1M
  • Mango MarketsDemo
    $915.6K
  • + 5 more

Vulnerable to: dvn collapse

Matches the dvn collapse predicate

8 historical peer events
  • Blast, Blockdaemon Wallet +2Demo
    $93.6M
  • Fordefi, XSGDDemo
    $17M
  • Element Finance, QuantozDemo
    $1.1M
  • Mercado Bitcoin, SwellDemo
    $15.3M
  • Internet Computer (DFINITY), Mantle +1Demo
    $10.3M
  • + 3 more

Vulnerable to: governance proposal malicious

Matches the governance proposal malicious predicate

5 historical peer events
  • Stripe CryptoDemo
    $1.5M
  • Notional V3Demo
    $507.1K
  • Hong Kong Monetary Authority — Ethereum pilotsDemo
    $18.9M
  • FalconXDemo
    $4.8M
  • AvailDemo
    $30.8M

Dependency Twins · Method A + B + C ensemble

Top 10 of 25 precomputed
#1

Aevo

Smart-Contract DEXs, AMMs & Aggregators · medium
Ensemble
0.470
A · Jaccard0.14
B · Overlap2
C · Cosine0.89
Matches on
  • kms_provider = unknown
  • frontend_host = vercel
  • subsector_tags = consumer_app, infra_tooling, general_defi
  • method_b_root_causes = price_impact_amm
#2

Shell Protocol

Smart-Contract DEXs, AMMs & Aggregators · high
Ensemble
0.429
A · Jaccard0.10
B · Overlap2
C · Cosine0.80
Matches on
  • kms_provider = unknown
  • subsector_tags = general_defi, infra_tooling, consumer_app
  • method_b_root_causes = flash_loan_governance, price_impact_amm
#3

Balancer

Smart-Contract DEXs, AMMs & Aggregators · low
Ensemble
0.428
A · Jaccard0.10
B · Overlap2
C · Cosine0.80
Matches on
  • subsector_tags = infra_tooling, consumer_app, general_defi
  • method_b_root_causes = price_impact_amm
  • stablecoin_dependencies = USDC, USDT, DAI
#4

Orca

Smart-Contract DEXs, AMMs & Aggregators · critical
Ensemble
0.421
A · Jaccard0.12
B · Overlap2
C · Cosine0.75
Matches on
  • frontend_host = vercel
  • subsector_tags = consumer_app, general_defi, infra_tooling
  • method_b_root_causes = price_impact_amm, phishing_drainer
  • stablecoin_dependencies = USDC, USDT
#5

Thirdweb

RPC, Node & Dev Infrastructure · medium
Ensemble
0.407
A · Jaccard0.07
B · Overlap2
C · Cosine0.76
Matches on
  • frontend_host = vercel
  • subsector_tags = infra_tooling, general_defi
  • method_b_root_causes = flash_loan_governance, phishing_drainer
#6

Protocol-Native Treasury Agents (DAO-embedded)

AI Agents & Autonomous On-Chain Systems · medium
Ensemble
0.401
A · Jaccard0.07
B · Overlap2
C · Cosine0.74
Matches on
  • frontend_host = vercel
  • subsector_tags = general_defi, consumer_app
  • method_b_root_causes = flash_loan_governance
#7

Element Finance

Lending, Money Markets & CDPs · medium
Ensemble
0.390
A · Jaccard0.14
B · Overlap1
C · Cosine0.89
Matches on
  • kms_provider = unknown
  • frontend_host = vercel
  • subsector_tags = general_defi, consumer_app, infra_tooling
  • method_b_root_causes = dvn_collapse
#8

Internet Computer (DFINITY)

L1 & L2 Network Operators · medium
Ensemble
0.390
A · Jaccard0.14
B · Overlap1
C · Cosine0.89
Matches on
  • kms_provider = unknown
  • frontend_host = vercel
  • subsector_tags = infra_tooling, consumer_app, general_defi
  • method_b_root_causes = dvn_collapse
#9

Mercado Bitcoin

Centralized Exchanges & Brokerages · medium
Ensemble
0.390
A · Jaccard0.14
B · Overlap1
C · Cosine0.89
Matches on
  • kms_provider = unknown
  • frontend_host = vercel
  • subsector_tags = infra_tooling, general_defi, consumer_app
  • method_b_root_causes = dvn_collapse
#10

Unichain

Rollups, Data Availability & ZK Infra · high
Ensemble
0.383
A · Jaccard0.09
B · Overlap2
C · Cosine0.66
Matches on
  • kms_provider = unknown
  • subsector_tags = general_defi, consumer_app
  • method_b_root_causes = frontend_dns_hijack, supply_chain_npm