Encyclopedia DeFi · Entry 74
Documented DeFi exploits: separating mechanism, scope and outcome
In this article
At a glance
Key facts
| Fact | Detail | Source |
|---|---|---|
| Euler scope | The cited retrospective concerns the March 2023 Euler V1 incident. | [1] |
| Vyper scope | Affected compiler versions are 0.2.15, 0.2.16 and 0.3.0. | [2] |
| Vyper fix | The advisory identifies 0.3.1 as the patched version for this defect. | [2] |
Euler V1: a missing check in account accounting
Euler Labs’ 10 January 2024 retrospective attributes the March 2023 exploit to a missing health check in donateToReserves. It describes how donating collateral could create an unhealthy account that was then self-liquidated for a bonus. This is the team’s primary account of the failure.
That mechanism should not be summarized as proof that all loans or all later Euler versions contain the same issue. The source explicitly distinguishes V1 history from the rebuilt V2 system. Its recovery narrative is also a separate claim from explaining the original defect.
Vyper: the compiler changed the lock behavior
The Vyper maintainers’ advisory says that named reentrancy locks were allocated separately across functions in versions 0.2.15, 0.2.16 and 0.3.0. Under the specified conditions, functions intended to share a lock could permit cross-function reentrancy.
The advisory narrows the issue to a particular compiler defect, vulnerable versions and contract conditions; it does not say every Vyper contract was exploitable. Its listed patched release addresses this defect, not every possible future vulnerability.
Explain the defect before labeling the financing
Flash borrowing can provide temporary capital, but a loan’s presence does not identify the rule that failed. The defect might instead concern accounting, an oracle, authority or generated code. Keeping these layers separate makes an incident useful for learning.
A defensible incident record preserves date, chain, affected implementation, source provenance, mechanism and uncertainty. Loss valuations require a price date and recovery needs a separate ledger. This entry deliberately avoids combining historical dollar figures measured at different times into one loss statistic.
Direct answers
Questions people ask
Does a recovered loss mean the original exploit was harmless?
No. Recovery is a later outcome and does not undo the original failure or establish that all affected users had the same timing or experience. It should be documented separately from the mechanism.
Inspect the evidence
The answer and key facts have stable claim links. These records retain the scope and qualification when reused.
A useful exploit explanation identifies the failed rule, affected version and observed consequences. Euler’s March 2023 V1 incident involved a missing account-health check according to its team’s retrospective. Vyper’s 2023 advisory documents incorrectly allocated reentrancy locks in specific compiler versions, a different failure layer.
Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.
Link to this claimEuler scope: The cited retrospective concerns the March 2023 Euler V1 incident.
Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.
Link to this claimVyper scope: Affected compiler versions are 0.2.15, 0.2.16 and 0.3.0.
Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.
Link to this claimVyper fix: The advisory identifies 0.3.1 as the patched version for this defect.
Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.
Link to this claimRevision history
- — First publication after primary-source research and independent automated verification.
Source register
Sources and references
Retrieval dates and locators are recorded individually.- Euler V1 exploit and recovery accountEuler Labs
The team attributes the 2023 exploit to a missing health check and describes affected integrations.
Locator: March 13th; WTF is the donateToReserves function?; The exploit in real-time · Version / scope: 2024-01-10 retrospective of March 2023 · Retrieved: 2026-10-02Open source - Incorrectly allocated named re-entrancy locksVyper maintainers
Vyper versions 0.2.15, 0.2.16 and 0.3.0 had cross-function reentrancy-lock defects.
Locator: Affected versions; Impact; Patches · Version / scope: GHSA-5824-cm3x-3c38; 2023-08-05 · Retrieved: 2026-10-02Open source - Aave V3 flash loansAave
Atomic repayment, receiver callbacks and distinct debt-opening options.
Locator: Overview; Execution Flow; Flash loan fee · Version / scope: Aave V3 · Retrieved: 2026-10-02Open source
Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.
Editorial method and correctionsDegrees of Satoshi editorial project. “Documented DeFi exploits: separating mechanism, scope and outcome.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/documented-defi-exploits/