ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Crypto

Hackers Offered 10% of Funds Recovered After $16M Curio Smart Contract Exploit

Kyle by Kyle
March 26, 2024
in Crypto
Reading Time: 2 mins read
16M Curio Smart Contract Exploit Crypto
Share on FacebookShare on Twitter

Curio, a leading firm in real-world asset (RWA) liquidity, has recently fallen victim to a smart contract exploit. This breach, which involved a critical vulnerability related to voting power privileges, enabled the attacker to abscond with digital assets worth approximately $16 million.

Immediate Response and Assurance from Curio

Upon discovery of the exploit, Curio promptly notified its community and reassured them that measures were being taken to address the situation. The breach was traced back to a MakerDAO-based smart contract utilized within Curio’s operations.

Despite the severity of the exploit, Curio was quick to assure its users that the breach was confined to the Ethereum side of operations. All contracts on Polkadot and the Curio Chain were confirmed to be secure and unaffected by the exploit.

You might also like

Betterment Investment Users Targeted by “Triple Crypto” Scam Notification

Bitcoin Fog Operator Sentenced to 12.5 Years for $400M Cryptocurrency Laundering Scheme

Pump.fun Bundlers Assist in Crypto “Pump and Dump” Schemes

Estimated Losses and Nature of the Exploit

Web3 security firm Cyvers has estimated the losses from the exploit to be around $16 million. The firm identified the exploit as a “permission access logic vulnerability.”

Curio Stolen Cyvers Alerts

Post-Mortem Report and Compensation Plan

On March 25, Curio released a detailed post-mortem report of the exploit, along with a compensation plan for the affected users. The report pinpointed the root cause of the problem – a flaw in the access control of voting power privileges.

The attacker managed to acquire a small number of Curio Governance (CGT) tokens, which allowed them to gain access and elevate their voting power within the project’s smart contract. With this elevated voting power, the attacker was able to execute arbitrary actions within the Curio DAO contract, leading to the unauthorized minting of 1 billion CGT.

Restitution and Future Measures

In the wake of the exploit, Curio has pledged to return all the funds affected. The team plans to release a new token, CGT 2.0, promising to restore 100% of the funds for CGT holders.

For liquidity providers, Curio has announced a fund compensation program. The compensation will be paid in four stages, each lasting 90 days. This implies that full payment could potentially span one year. The team stated:

“The compensation program will consist of 4 consecutive stages, each lasting for 90 days. During each stage: compensation will be paid in USDC/USDT, amounting to 25% of the losses incurred by the second token in the liquidity pools.”

In addition, Curio has also announced a reward for white hat hackers who can aid in recovering the lost funds. Hackers could receive a reward equivalent to 10% of funds recovered in the initial recovery phase.

Previous Post

GoFetch Exploit Impacting Both Apple M-series and Intel Raptor Lake CPUs

Next Post

Large Surge in Zero-Day Vulnerabilities, Google Reports

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Betterment investments hacked for crypto scam

Betterment Investment Users Targeted by “Triple Crypto” Scam Notification

January 11, 2026
Roman Sterlingov Sentenced to 12.5 years

Bitcoin Fog Operator Sentenced to 12.5 Years for $400M Cryptocurrency Laundering Scheme

November 11, 2024

Pump.fun Bundlers Assist in Crypto “Pump and Dump” Schemes

October 16, 2024 - Updated on October 24, 2024

FBI’s Covert Operation Token Mirrors Exposes Massive Crypto Fraud Ring

October 11, 2024

FBI Warns of Sophisticated North Korean Social Engineering Attacks on Crypto Firms

September 4, 2024

Trezor’s Official X Account Compromised in Suspected SIM-Swap Attack

March 21, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.