{
  "id": 12309234,
  "title": "Security Audit Report: Reentrancy & Access Control Review: Curve DEX",
  "url": "https://urgent.news/2026/10/06/security-audit-report-reentrancy-access-control-review-curve-dex",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T05:33:34.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/dannydoes_2abdf9c/security-audit-report-reentrancy-access-control-review-curve-dex-oa6"
  },
  "original_language": "en",
  "account": "The security audit report examines Curve DEX, a top DeFi protocol specializing in stablecoin and wrapped asset swaps. As of the audit, Curve holds about $1.28 billion across Ethereum and other rollups like Arbitrum, Optimism, and zkSync.\n\nThe audit focused on three key areas: reentrancy vulnerabilities, access control mechanisms, and overall risk assessment. No critical reentrancy or access control flaws were found that could drain funds or seize governance. However, several medium-severity vulnerabilities were identified that could be exploited in coordinated attacks or with future contract changes.\n\nThe highest-priority vulnerability involves reentrancy risks in the swap() function when swapping ERC-20 or ERC-777 tokens. Malicious tokens could re-enter the swap() function before the initial call is completed, manipulating the pool's internal balances and leading to funds being stolen or the pool's reserves being imbalanced. This could result in users losing their LP shares and funds.\n\nAnother serious issue is improper access control for setting the protocol's admin functions. The admin role is granted to a single EOA address without any time lock or multi-signature guard. If an attacker compromises this address, they could upgrade any proxy contract to malicious code, giving them control over the entire protocol.\n\nAdditionally, the report highlights a medium-severity risk in the Gauge reward distribution mechanism. The distribute() function transfers rewards to a caller before updating the last claimed timestamp. A malicious reward token could exploit this by re-entering the function and claiming rewards multiple times, inflating the supply of the gauge token and potentially double-spending rewards.\n\nThe audit also found lower-severity vulnerabilities related to improper input validation in the factory contract for creating new pools, potential reentrancy in staking withdrawals, and risks from cross-chain bridge callbacks that could trigger state changes before external calls.\n\nOverall, the protocol's existing defensive measures, including checks-effects-interactions, OpenZeppelin ReentrancyGuard, role-based access control, and multi-sig governance, help mitigate most attack paths. However, the report recommends further hardening to protect against evolving threats and improve auditability for future upgrades.",
  "summary": "Security Audit Report: Reentrancy & Access Control Review: Curve DEX Target Protocol : Curve DEX (TVL: $1281.5M) Security Audit Report Reentrancy & Access‑Control Review – Curve DEX Date: 6 Oct 2026 Prepared by: [Your Name] – Senior DeFi Security Researcher & Smart‑Contract Auditor 1. Executive Summary Curve Finance is a high‑value, low‑slippage automated market maker (AMM) that specializes in…",
  "key_points": [
    "Curve DEX holds $1.28B across Ethereum and rollups",
    "No critical reentrancy or access control flaws found",
    "Medium-severity vulnerabilities identified in swap(), admin functions, and Gauge rewards"
  ],
  "editors_take": "The audit's findings highlight the need for Curve DEX to further harden its defenses, particularly in addressing medium-severity vulnerabilities that could be exploited with coordinated attacks or future contract changes.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}