Curve Finance escalated its response to the previous week’s liquidity-pool attacks on August 6, 2023, offering the public a reward valued at $1.85 million for information that identified a remaining exploiter and led to a conviction in court.
The terms were embedded in an Ethereum transaction sent from an address labeled Curve: Deployer 2 to an address labeled CRV/ETH Exploiter 2. The successful zero-value transaction was recorded at 16:10:23 UTC on August 6. Its message said a voluntary-return deadline had passed at 08:00 UTC and valued the new reward at 10% of the remaining exploited funds.
Curve also left the settlement route open: the message said the protocol would not pursue the matter further if the exploiter returned the funds in full. That condition made the notice both a public attribution bounty and a final inducement for restitution.
From private settlement to public attribution
Curve and other affected protocols had offered attackers a 10% bounty on August 3 in exchange for returning the assets. That earlier proposal promised not to pursue further legal action if the remaining 90% was restored by the stated deadline.
Assets connected with the Alchemix and JPEG’d pools were subsequently returned, but the recoveries did not close every part of the incident. The August 6 message changed who could claim the 10% reward. Instead of paying only the exploiter for voluntarily returning funds, Curve offered it to any person able to produce identification that resulted in a conviction.
The distinction matters. The Ethereum record proves that the message was sent, including its stated terms, timestamp and destination. It does not establish that Curve had a binding agreement with every affected protocol or liquidity provider, that a court would accept any submitted identification, or that the bounty was ultimately paid. Etherscan’s human-readable address labels are attribution metadata rather than cryptographic proof of legal identity.
The unresolved balance was still an estimate
The $1.85 million figure came from Curve’s own transaction message. Because the offer was defined as 10% of remaining exploited funds, it implied that Curve valued the relevant remainder at approximately $18.5 million when composing the notice.
That calculation should not be mistaken for an audited loss statement. The surviving message does not identify its asset-price source, valuation timestamp, component tokens or exchange-rate methodology. It also does not reconcile gross pool outflows with assets held by apparent attackers, white-hat recoveries, returned funds, protocol liabilities or eventual liquidity-provider losses.
Contemporaneous reports used different totals for the broader July 30 incident because they measured different sets of pools and classified rescue transactions and recoveries differently. The defensible event-day claim is therefore limited: Curve stated that the outstanding funds relevant to this bounty were worth about $18.5 million and offered 10% of that stated value.
Why the escalation mattered
The July 30 attacks had exposed a defect in several versions of the Vyper smart-contract compiler, allowing cross-function reentrancy under specific contract conditions. Vyper’s maintainers formally classified the defect as critical on August 5 and identified versions 0.2.15, 0.2.16 and 0.3.0 as affected.
By August 6, the response had moved beyond technical containment. Curve was using Ethereum itself as a public communications and evidence channel while explicitly connecting an economic reward to conventional court enforcement. That combination illustrated how decentralized protocols still depended on off-chain investigators, legal identity and judicial process when voluntary on-chain restitution stopped short.
The bounty did not repair vulnerable contracts, guarantee recovery or resolve losses across the affected pools. It marked a change in strategy: the remaining exploiter was no longer being offered only a confidential path to retain a negotiated share, but was being exposed to a public search backed by the same percentage incentive.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

