Coins Explained
What Is Curve? The DEX Built Specifically for Stablecoin Swaps
How Curve's StableSwap formula gets lower slippage than Uniswap for pegged assets, what its crvUSD soft-liquidation stablecoin does, and what the 2023 Vyper exploit revealed.
What problem Curve was built to solve
Curve Finance, launched in January 2020 by Russian physicist Michael Egorov, is a decentralized exchange built for one specific job: swapping between assets that are supposed to trade at (or very near) the same value, mainly stablecoins like USDC and USDT, but also things like different wrapped versions of the same underlying asset (stETH and ETH, for example). If the general idea of a DEX and an AMM is still unfamiliar, What DeFi and a DEX Actually Are covers the mechanics from scratch; this page assumes that background and focuses on what makes Curve’s specific design different from a general-purpose DEX like Uniswap.
That distinction matters more than it might sound. Uniswap’s constant-product formula, covered in detail in What Is Uniswap?, works well for trading pairs whose relative price can move freely, like ETH against USDC, but it’s an inefficient design specifically for two assets that are supposed to already be worth the same amount. A large swap between two stablecoins on a Uniswap-style pool causes more price impact than it should, because the formula doesn’t know in advance that both sides are meant to hold close to $1. Curve exists to fix exactly that inefficiency.
The technical mechanism, in plain language
Curve’s core innovation, called the StableSwap invariant, blends two different pricing formulas rather than relying on just one. Near the point where a pool is balanced, meaning it holds roughly equal value of each stablecoin, StableSwap prices trades almost like a simple 1:1 swap, producing extremely low slippage, since the assets are supposed to be worth the same amount anyway. As a pool becomes more imbalanced, the formula gradually shifts toward behaving more like Uniswap’s constant-product curve, which still lets the pool function and reprice even in unusual conditions, just with more slippage as the imbalance grows. The practical result is that swapping a large amount between two major stablecoins on Curve typically costs a small fraction of what the same swap would cost on a general-purpose AMM, which is why Curve became the default venue for large stablecoin trades and why other protocols route stablecoin swaps through it.
In 2023, Curve extended this specialization further by launching its own stablecoin, crvUSD, backed by crypto collateral locked directly in the protocol rather than by a company’s bank reserves, similar in spirit to how Maker (Sky) backs DAI and USDS. What’s distinctive about crvUSD is its liquidation design, called LLAMMA: instead of liquidating a borrower’s entire collateral position in one shot once a price threshold is crossed, the way most lending protocols work, LLAMMA spreads a borrower’s collateral across a range of price bands and converts it gradually into crvUSD as the market moves against the position, and can convert it back if the price recovers before the position is fully liquidated. That “soft liquidation” approach is meant to reduce the sudden, all-or-nothing losses that a hard liquidation threshold can cause during a fast market move.
The 2023 Vyper exploit: a genuine, instructive DeFi risk event
On July 30, 2023, several Curve liquidity pools were exploited for a combined total commonly reported around $70 million, in an incident that’s worth understanding honestly rather than glossing over, both because of what caused it and because of what happened next. The root cause wasn’t a flaw in Curve’s own pricing logic; it was a bug in specific older versions of Vyper, the programming language some of Curve’s contracts were written in, that broke a security mechanism called a reentrancy lock in a way that let attackers manipulate contract balances mid-transaction. Because other protocols, including JPEG’d, Alchemix, Metronome, and Pendle, had also used the same vulnerable Vyper versions in pools connected to Curve, the exploit spread across several unrelated projects rather than staying contained to one. Some funds were later recovered through the efforts of white-hat hackers and negotiations with the attacker, reducing the final realized loss somewhat below the initial headline figure.
The second part of the story is what made this a systemic concern rather than just a contained exploit: Curve’s own founder, Michael Egorov, held large personal loans across several DeFi lending protocols, collateralized primarily by CRV, the protocol’s governance token, worth roughly $100 million against roughly $140 million of CRV collateral at the time. As the exploit hit confidence in Curve and CRV’s price came under pressure, Egorov’s position moved uncomfortably close to liquidation thresholds; a full liquidation of a position that large, sold into an already stressed market, risked cascading further CRV price declines and leaving some of the lending protocols holding bad debt, since the market likely couldn’t absorb that much CRV being sold at once. Egorov managed the immediate crisis by selling a portion of his CRV holdings over-the-counter to reduce the loan size. The underlying risk resurfaced again in June 2024, when a sharper CRV price decline triggered a larger, more disruptive liquidation of Egorov’s remaining leveraged positions across multiple protocols, this time leaving one protocol, Llamalend, with a small amount of actual bad debt that Egorov subsequently covered by selling more CRV. Both episodes are a genuinely instructive example of a risk that’s easy to overlook when evaluating a DeFi protocol: a founder’s personal, highly leveraged position in the protocol’s own governance token can become a systemic risk to the entire ecosystem around it, not just a personal financial matter, a point directly relevant to the concentration questions raised in How to Evaluate a DeFi Protocol Before Depositing Funds.
Strengths and limitations, honestly
Curve’s genuine strengths are a real, still-used technical innovation (the StableSwap formula measurably outperforms general-purpose AMMs for pegged-asset swaps), a long operating history as the default venue for large stablecoin trades, and a functioning stablecoin, crvUSD, with a liquidation design that’s a genuine improvement over hard, all-or-nothing liquidation for many borrowers. Its real limitations are worth stating just as plainly. The 2023 Vyper exploit shows that even a protocol with sound core logic can be compromised through a dependency, in this case a programming language bug, entirely outside its own code review process. Michael Egorov’s large, CRV-collateralized personal loans have twice created concentrated, systemic risk for the protocol and its lending-partner ecosystem, a governance and key-person risk that’s specific to Curve and worth weighing separately from its smart-contract security. And CRV’s price, like most governance tokens, has been highly sensitive to both of those events, a reminder that a protocol’s technical quality and its token’s price stability are related but genuinely separate questions.
How to actually trade or hold it
CRV is available for spot trading on most major exchanges; check our exchange comparisons for current listings and fees. If you’re new to buying crypto, Spot Trading Explained covers order types and custody basics first. If you’re considering using Curve directly, whether to swap stablecoins, provide liquidity, or borrow crvUSD, rather than just holding CRV, read What DeFi and a DEX Actually Are and How to Evaluate a DeFi Protocol Before Depositing Funds first: Curve’s long track record and specialized design are genuine positives by that checklist’s standards, but its 2023 exploit and its founder’s leveraged-loan history are exactly the kind of specific, checkable risks that checklist exists to surface.
Frequently asked questions
Why is Curve better for stablecoin swaps than Uniswap? Curve’s StableSwap formula is specifically designed around the assumption that two assets should trade near the same value, producing much lower slippage for large stablecoin trades than a general-purpose constant-product AMM like Uniswap’s, which treats every trading pair the same way regardless of whether the two assets are meant to be pegged to each other.
Was Curve’s own code responsible for the 2023 exploit? Not directly. The vulnerability was in specific older versions of Vyper, the programming language some Curve contracts (and contracts on other, unrelated protocols) were written in, rather than a flaw in Curve’s own StableSwap pricing logic. That distinction doesn’t make the loss any less real, but it’s a different failure mode than a bug in Curve’s own custom code.
What actually happened with the founder’s loans, in plain terms? Michael Egorov borrowed heavily against his own large CRV holdings across several DeFi lending protocols. When CRV’s price came under pressure, first after the 2023 exploit and more sharply in June 2024, his positions approached or hit liquidation thresholds; a forced sale of that much CRV at once risked destabilizing CRV’s price further and leaving lending protocols with unrecoverable bad debt, which is exactly what happened on a small scale to one protocol in 2024.
Is crvUSD’s “soft liquidation” the same as not being liquidated at all? No. LLAMMA gradually converts a borrower’s collateral as the market moves against them, and can reverse that conversion if the price recovers, rather than instantly liquidating the full position at one threshold. It’s designed to reduce sudden, complete losses compared to hard liquidation, but a position that keeps moving further underwater can still end up fully liquidated; it changes the shape of the risk, not whether the risk exists.
Risk
Nothing on this page is financial advice, and it is not a complete or current statement of Curve’s technical status, price history, or regulatory situation, all of which can change. Curve has already suffered one major exploit tied to a third-party programming language dependency, and its founder’s history of large, CRV-collateralized personal loans has twice created concentrated liquidation risk for the protocol and its lending partners. Do your own research before buying or holding any crypto asset.