# Documented DeFi exploits: separating mechanism, scope and outcome

A useful exploit explanation identifies the failed rule, affected version and observed consequences. Euler’s March 2023 V1 incident involved a missing account-health check according to its team’s retrospective. Vyper’s 2023 advisory documents incorrectly allocated reentrancy locks in specific compiler versions, a different failure layer.

Evidence: [Euler V1 exploit and recovery account](https://www.euler.finance/blog/war-peace-behind-the-scenes-of-eulers-240m-exploit-recovery); [Incorrectly allocated named re-entrancy locks](https://github.com/vyperlang/vyper/security/advisories/GHSA-5824-cm3x-3c38)

Canonical: https://degreesofsatoshi.com/encyclopedia/documented-defi-exploits/
Published: 2026-10-02
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T15:08:18.373Z

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Euler scope:** The cited retrospective concerns the March 2023 Euler V1 incident. ([Euler V1 exploit and recovery account](https://www.euler.finance/blog/war-peace-behind-the-scenes-of-eulers-240m-exploit-recovery))
- **Vyper scope:** Affected compiler versions are 0.2.15, 0.2.16 and 0.3.0. ([Incorrectly allocated named re-entrancy locks](https://github.com/vyperlang/vyper/security/advisories/GHSA-5824-cm3x-3c38))
- **Vyper fix:** The advisory identifies 0.3.1 as the patched version for this defect. ([Incorrectly allocated named re-entrancy locks](https://github.com/vyperlang/vyper/security/advisories/GHSA-5824-cm3x-3c38))

## Euler V1: a missing check in account accounting

Euler Labs’ 10 January 2024 retrospective attributes the March 2023 exploit to a missing health check in donateToReserves. It describes how donating collateral could create an unhealthy account that was then self-liquidated for a bonus. This is the team’s primary account of the failure.

That mechanism should not be summarized as proof that all loans or all later Euler versions contain the same issue. The source explicitly distinguishes V1 history from the rebuilt V2 system. Its recovery narrative is also a separate claim from explaining the original defect.

Evidence: [Euler V1 exploit and recovery account](https://www.euler.finance/blog/war-peace-behind-the-scenes-of-eulers-240m-exploit-recovery)

## Vyper: the compiler changed the lock behavior

The Vyper maintainers’ advisory says that named reentrancy locks were allocated separately across functions in versions 0.2.15, 0.2.16 and 0.3.0. Under the specified conditions, functions intended to share a lock could permit cross-function reentrancy.

The advisory narrows the issue to a particular compiler defect, vulnerable versions and contract conditions; it does not say every Vyper contract was exploitable. Its listed patched release addresses this defect, not every possible future vulnerability.

Evidence: [Incorrectly allocated named re-entrancy locks](https://github.com/vyperlang/vyper/security/advisories/GHSA-5824-cm3x-3c38)

## Explain the defect before labeling the financing

Flash borrowing can provide temporary capital, but a loan’s presence does not identify the rule that failed. The defect might instead concern accounting, an oracle, authority or generated code. Keeping these layers separate makes an incident useful for learning.

A defensible incident record preserves date, chain, affected implementation, source provenance, mechanism and uncertainty. Loss valuations require a price date and recovery needs a separate ledger. This entry deliberately avoids combining historical dollar figures measured at different times into one loss statistic.

Evidence: [Aave V3 flash loans](https://aave.com/docs/aave-v3/guides/flash-loans); [Euler V1 exploit and recovery account](https://www.euler.finance/blog/war-peace-behind-the-scenes-of-eulers-240m-exploit-recovery); [Incorrectly allocated named re-entrancy locks](https://github.com/vyperlang/vyper/security/advisories/GHSA-5824-cm3x-3c38)

## Questions

### Does a recovered loss mean the original exploit was harmless?

No. Recovery is a later outcome and does not undo the original failure or establish that all affected users had the same timing or experience. It should be documented separately from the mechanism.

Evidence: [Euler V1 exploit and recovery account](https://www.euler.finance/blog/war-peace-behind-the-scenes-of-eulers-240m-exploit-recovery)

## Claims and scope

### documented-defi-exploits-quick-answer

A useful exploit explanation identifies the failed rule, affected version and observed consequences. Euler’s March 2023 V1 incident involved a missing account-health check according to its team’s retrospective. Vyper’s 2023 advisory documents incorrectly allocated reentrancy locks in specific compiler versions, a different failure layer.

Scope: {"collection":"defi","dataAsOf":null,"blockHeight":null}

### documented-defi-exploits-fact-euler-scope

Euler scope: The cited retrospective concerns the March 2023 Euler V1 incident.

Scope: {"collection":"defi","dataAsOf":null,"blockHeight":null}

### documented-defi-exploits-fact-vyper-scope

Vyper scope: Affected compiler versions are 0.2.15, 0.2.16 and 0.3.0.

Scope: {"collection":"defi","dataAsOf":null,"blockHeight":null}

### documented-defi-exploits-fact-vyper-fix

Vyper fix: The advisory identifies 0.3.1 as the patched version for this defect.

Scope: {"collection":"defi","dataAsOf":null,"blockHeight":null}

## Sources

- [Euler V1 exploit and recovery account](https://www.euler.finance/blog/war-peace-behind-the-scenes-of-eulers-240m-exploit-recovery) — Euler Labs. The team attributes the 2023 exploit to a missing health check and describes affected integrations. Locator: March 13th; WTF is the donateToReserves function?; The exploit in real-time. Retrieved: 2026-10-02.
- [Incorrectly allocated named re-entrancy locks](https://github.com/vyperlang/vyper/security/advisories/GHSA-5824-cm3x-3c38) — Vyper maintainers. Vyper versions 0.2.15, 0.2.16 and 0.3.0 had cross-function reentrancy-lock defects. Locator: Affected versions; Impact; Patches. Retrieved: 2026-10-02.
- [Aave V3 flash loans](https://aave.com/docs/aave-v3/guides/flash-loans) — Aave. Atomic repayment, receiver callbacks and distinct debt-opening options. Locator: Overview; Execution Flow; Flash loan fee. Retrieved: 2026-10-02.

## Revision history

- 2026-10-02: First publication after primary-source research and independent automated verification.

## Cite this entry

Degrees of Satoshi editorial project. “Documented DeFi exploits: separating mechanism, scope and outcome.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/documented-defi-exploits/
