CryptoReal
CASE FILE — Nov 14, 2020

Curve Oracle Blind Spot Costs Value DeFi $7 Million

Reputations built on confidence rather than caution tend to be the first to crack. Value DeFi found this out on November 14, 2020, when an attacker drained $7,000,000 from the protocol using a flash loan — the latest in a string of DeFi projects to be caught out by the technique.

The token took a hit as news spread: VALUE traded around $2.73 before the incident and slipped to $1.87 afterward.

Ironically, the team had published a tweet touting the strength of their security measures just one day before the exploit. That tweet was later deleted, though a screenshot of it survives.

The root problem was architectural. Value DeFi's team had apparently assumed withdrawals could only flow through the main Bank contract, overlooking the fact that the Vault contract, accessible via a Proxy, offered a second route out. Compounding this, the protocol relied on Curve's spot price as its oracle, a value that could be manipulated. Researchers traced the manipulation to two specific steps in the exploit sequence, followed by a withdrawal step that invoked the wrong Curve function for its calculations. Analysis of the mechanism was credited to researchers @emilianobonassi and @FrankResearcher.

Sums referenced in this case file

The timing added an extra layer of embarrassment. The attack landed at 15:24, just twenty minutes ahead of a scheduled AMA session with the team. By 15:41, community members in the project's Discord were already asking about a sudden drop in total value locked — TVL had stood at over $11M earlier that day. A minute later, at 15:42, unease was spreading through the channel, with some members still hoping it was merely a display glitch. That hope evaporated at 15:49 when a link to the relevant Etherscan transaction was posted in the chat, confirming that $7,000,000 had been pulled from the vault. Of that, $2,000,000 was sent back along with an accompanying message.

At 16:00 — exactly when the AMA was set to begin — Aave founder Stani Kulechov weighed in publicly on Twitter about the situation. Inside the AMA itself, the Value team acknowledged the breach in Discord at 16:05, yet the live session carried on for another 40 minutes covering unrelated subject matter before the topic was properly addressed.

This made Value DeFi the latest in a run of flash-loan casualties following Harvest Finance ($FARM) and Akropolis ($AKRO), joining a pattern where semi-established projects — those with meaningful trading volume and TVL — get targeted, exploited, and then see a partial refund gesture as an act of "good faith."

There's a broader question worth asking: are these repeated attacks accidentally functioning as a teaching mechanism for the industry? Flash loans remain contentious, having enabled numerous exploits in recent months, but they arguably compress a learning curve that would otherwise unfold much more slowly — weeding out fragile protocols faster than waiting for a well-capitalized attacker to do the same thing manually. In an ecosystem this young, absorbing these lessons early, while builders are still iterating rapidly and launching new products daily, may be the least painful path forward.

Rather than framing flash loans purely as an exploit vector, it's worth remembering they're a genuinely novel capability unique to DeFi — impossible to replicate in traditional finance — and in that sense a defining feature of the technology rather than a flaw in it. Protocols with solid foundations tend to shrug these attacks off, and some even come out ahead. In effect, flash loans function as a forcing mechanism, pushing developer standards higher across the board. Until those standards catch up, more projects and people will get burned, often publicly, but the resulting pressure should ultimately yield sturdier code and a safer environment for everyone building and using these systems.

flash loanvalue defi
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.