failure to hack the physicist's formula 🗣👀
kerman looked into iearn+curve [ycurve] post-mortem transactions closely and wrote a report: https://defiweekly.substack.com/p/part-1-defi-madness-ft-curve-iearn
well he's probably realised that if he can drain the USDC then the exchange rate between USDC to BUSD will be highly favourable allowing him to profit $246,747. Similarly, he could drain the DAI pool and exchange it for USDT and profit another $44,692
since curve formula is not linear, but is a market maker, a certain threshold can turn the calculations from minimizing the slippage rate to maximizing it in order to rebalance the pool...
a-ha! no. that's what the guys estimate the "hacker" was trying to do, but it would have not worked in either case
see curve response 🦄 https://twitter.com/CurveFinance/status/1234842704506507264
The attacker could either end up with net zero (minus fees), or lose money if he was front-ran. And the latter is what has happened.
check what smart people are saying on the matter -> @lobsters_chat
Post #793
1.4K
crab notes 🦀 lobsterdao Net gain 420,182 🌀 ycurve [Curve + iearn] post-mortem Wrapping tokens can be tricky. If they are algorithmically-pegged, going in <-> out requires liquidity. Liquidity can sometimes be there, and sometimes not. It’s not the same as cashing your USDC 1:1 USD…