A detailed walkthrough of the Damn Vulnerable DeFi challenge 'Curvy Puppet', described as the hardest in the series. The exploit combines read-only reentrancy in Curve's remove_liquidity function with flash loans to manipulate LP token pricing. By borrowing ~173,429 stETH from AaveV2 and ~37,991 WETH from Balancer (fee-free),

6m read time From coinsbench.com
Post cover image
Table of contents
Exploit: Read-Only Reentrancy:The MathFlashLoanPrice Manipulation Phase

Sort: