Skip to main content

Security

Curve Finance prioritizes the security of its protocols and user funds above all else. We maintain a bug bounty program to encourage responsible disclosure of potential vulnerabilities and actively collaborate with security researchers and whitehat hackers to ensure the safety of our ecosystem.

Security Contact & Disclosure Reports

For security-related inquiries and vulnerability reports: [email protected]

Security audits and disclosure reports are available on GitHub


Bug Bounty

Scope — Issues which can lead to substantial loss of money, critical bugs like a broken liveness condition or irreversible loss of funds.

Disclosure Policy — Let us know as soon as possible upon discovery of a potential security issue. Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party.

Exclusions — Already known vulnerabilities. Vulnerabilities in front-end code not leading to smart contract vulnerabilities.

Eligibility — You must be the first reporter of the vulnerability. You must be able to verify a signature from same address. Provide enough information about the vulnerability.

Likelihood / SeverityLowModerateHigh
Almost Certain$10,000$50,000$250,000
Possible$1,000$10,000$50,000
Unlikely$250$1,000$5,000

Security Audits

DAO

TrailOfBits
TrailOfBits
Scope: Curve DAO Contracts
Date: 10. July, 2020
View Full Report →
MixBytes
MixBytes
Scope: Curve DAO Voting Forwarder
Date: 13. July, 2020
View Full Report →
MixBytes
MixBytes
Scope: Curve Voting (Aragon Voting Fork)
Date: 22. July, 2020
View Full Report →
Quantstamp
Quantstamp
Scope: Curve DAO Contracts
Date: 5. August, 2020
View Full Report →
ChainSecurity
ChainSecurity
Scope: FeeSplitter.vy
Date: 25. September, 2024
View Full Report →
ChainSecurity
ChainSecurity
Scope: Curve Cross-chain Governance
Date: 17. September, 2025
View Full Report →

DEX

Quantstamp
Quantstamp
Scope: Curve Metapools
Date: 15. October, 2020
View Full Report →
ChainSecurity
ChainSecurity
Scope: Curve ETH/sETH Liquidity Pool Implementation
Date: 27. September, 2021
View Full Report →
MixBytes
MixBytes
Scope: Stableswap-NG
Date: 1. November, 2023
View Full Report →
ChainSecurity
ChainSecurity
Scope: Tricrypto
Date: 29. September, 2021
View Full Report →
ChainSecurity
ChainSecurity
Scope: Tricrypto-NG
Date: 23. June, 2023
View Full Report →
ChainSecurity
ChainSecurity
Scope: Twocrypto
Date: 1. April, 2022
View Full Report →

Infrastructure

ChainSecurity
ChainSecurity
Scope: FastBridge (Cross-chain crvUSD)
Date: 25. October, 2024
View Full Report →

Stablecoin and Lending

MixBytes
MixBytes
Scope: crvUSD Infrastucture
Date: 5. June, 2023
View Full Report →
ChainSecurity
ChainSecurity
Scope: crvUSD Infrastucture
Date: 24. January, 2024
View Full Report →
ChainSecurity
ChainSecurity
Scope: crvUSD Infrastucture
Date: 21. February, 2025
View Full Report →
ChainSecurity
ChainSecurity
Scope: PegKeeper V2
Date: 12. December, 2023
View Full Report →
StateMind
StateMind
Scope: Curve Lending Infrastucture
Date: 2. February, 2024
View Full Report →
ChainSecurity
ChainSecurity
Scope: Savings-crvUSD (scrvUSD)
Date: 03. December, 2024
View Full Report →