Odaily Planet Daily News OneKey founder Yishi published a public statement on "Curve Ecosystem DeFi Protocol Resupply suffered a price manipulation attack and lost $9.6 million", demanding Curve to provide a fair solution for every investor and return the user funds lost due to serious technical errors of the project party.
Yishi revealed that he is one of the three major investors of Resupply, and the loss of this incident is as high as millions of dollars. He also accused the team of banning reasonable questioners in Discord and lacking due accountability. He emphasized that the vulnerability originated from the fact that the initial shares of ERC4626 vault were not destroyed when it was deployed, which allowed the attacker to cast unlimited shares at almost zero cost and drain the vault, which was a protocol-level design and deployment error. Yishi said that it made no sense for the Resupply team to pass the losses on to the depositors of the insurance pool. The insurance pool should be used for black swan events and market fluctuations, not to cover the technical negligence of the team. He also pointed out that Curve, Convex and Yearn had participated in supporting Resupply in various forms and gained actual benefits from it, and should not shirk responsibility afterwards. He called on the relevant parties to bear the due costs and return the user's assets. In response to the incident, Curve responded this morning, "Although Resupply was not developed by the Curve team, its creator is experienced and I believe he will do his best to deal with the problem. The insurance pool is designed to provide protection for such security incidents, and if the assets can be recovered, it should be given priority."