Skip to article
Degrees of SatoshiFollow the connections.
Degrees of Satoshi/ Encyclopedia

Encyclopedia DeFi · Entry 74

Documented DeFi exploits: separating mechanism, scope and outcome

Theme
DeFi
Sources
3 cited records
Reading time
About 3 minutes
Automated verification
Substantive update
In this article

At a glance

Key facts

Key facts for Documented DeFi exploits: separating mechanism, scope and outcome
FactDetailSource
Euler scopeThe cited retrospective concerns the March 2023 Euler V1 incident.[1]
Vyper scopeAffected compiler versions are 0.2.15, 0.2.16 and 0.3.0.[2]
Vyper fixThe advisory identifies 0.3.1 as the patched version for this defect.[2]
01

Euler V1: a missing check in account accounting

Euler Labs’ 10 January 2024 retrospective attributes the March 2023 exploit to a missing health check in donateToReserves. It describes how donating collateral could create an unhealthy account that was then self-liquidated for a bonus. This is the team’s primary account of the failure.

That mechanism should not be summarized as proof that all loans or all later Euler versions contain the same issue. The source explicitly distinguishes V1 history from the rebuilt V2 system. Its recovery narrative is also a separate claim from explaining the original defect.

02

Vyper: the compiler changed the lock behavior

The Vyper maintainers’ advisory says that named reentrancy locks were allocated separately across functions in versions 0.2.15, 0.2.16 and 0.3.0. Under the specified conditions, functions intended to share a lock could permit cross-function reentrancy.

The advisory narrows the issue to a particular compiler defect, vulnerable versions and contract conditions; it does not say every Vyper contract was exploitable. Its listed patched release addresses this defect, not every possible future vulnerability.

03

Explain the defect before labeling the financing

Flash borrowing can provide temporary capital, but a loan’s presence does not identify the rule that failed. The defect might instead concern accounting, an oracle, authority or generated code. Keeping these layers separate makes an incident useful for learning.

A defensible incident record preserves date, chain, affected implementation, source provenance, mechanism and uncertainty. Loss valuations require a price date and recovery needs a separate ledger. This entry deliberately avoids combining historical dollar figures measured at different times into one loss statistic.

Direct answers

Questions people ask

Does a recovered loss mean the original exploit was harmless?

No. Recovery is a later outcome and does not undo the original failure or establish that all affected users had the same timing or experience. It should be documented separately from the mechanism.

Inspect the evidence

The answer and key facts have stable claim links. These records retain the scope and qualification when reused.

A useful exploit explanation identifies the failed rule, affected version and observed consequences. Euler’s March 2023 V1 incident involved a missing account-health check according to its team’s retrospective. Vyper’s 2023 advisory documents incorrectly allocated reentrancy locks in specific compiler versions, a different failure layer.

Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.

Link to this claim
Euler scope: The cited retrospective concerns the March 2023 Euler V1 incident.

Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.

Link to this claim
Vyper scope: Affected compiler versions are 0.2.15, 0.2.16 and 0.3.0.

Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.

Link to this claim
Vyper fix: The advisory identifies 0.3.1 as the patched version for this defect.

Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.

Link to this claim
Revision history
  1. — First publication after primary-source research and independent automated verification.

Source register

Sources and references

Retrieval dates and locators are recorded individually.
  1. Euler V1 exploit and recovery accountEuler Labs

    The team attributes the 2023 exploit to a missing health check and describes affected integrations.

    Locator: March 13th; WTF is the donateToReserves function?; The exploit in real-time · Version / scope: 2024-01-10 retrospective of March 2023 · Retrieved: 2026-10-02Open source
  2. Incorrectly allocated named re-entrancy locksVyper maintainers

    Vyper versions 0.2.15, 0.2.16 and 0.3.0 had cross-function reentrancy-lock defects.

    Locator: Affected versions; Impact; Patches · Version / scope: GHSA-5824-cm3x-3c38; 2023-08-05 · Retrieved: 2026-10-02Open source
  3. Aave V3 flash loansAave

    Atomic repayment, receiver callbacks and distinct debt-opening options.

    Locator: Overview; Execution Flow; Flash loan fee · Version / scope: Aave V3 · Retrieved: 2026-10-02Open source
How this article was made

Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.

Editorial method and corrections

Degrees of Satoshi editorial project. “Documented DeFi exploits: separating mechanism, scope and outcome.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/documented-defi-exploits/