250,000 CRVs were dug up in advance before going online, so Curve officially recognizes it?

王也
本文约1052字,阅读全文需要约4分钟
The project contracts that have been launched so far have no official control. Users are advised not to participate in order to avoid asset losses.

On the morning of August 14, the Curve team of the stable currency exchange platform announced the official launch of the token CRV, which has begun to be issued, and launched the CRV/USDC trading pair on the decentralized trading platform Matcha.

The total supply of CRV tokens is 3.03 billion, with an initial issuance of 1.3 billion.

However, just a few hours before Curve officially announced the launch of CRV, according to Twitter netizens, an anonymous developer had previously disclosed the token contract address (CRV contract address: 0xD533a949740bb3306d119CC777fa900bA034cd52) and the application method in advance. Received CRV tokens before the official launch.

According to Twitter netizens, a Twitter user named "0xc4ad" spent 20 ETH (a total of 8460 US dollars) to deploy the CRV contract in advance. Before Curve officially released CRV, "0xc4ad" had dug through the contract address 250,000 CRV, calculated according to the price of CRV (52 USD) before the deadline, the total is 13 million US dollars.

The Curve team was initially skeptical, but later tweeted that the address was an acceptable deployment with the correct code, data, and management keys.

As a result, Curve officials had to adopt the Curve DAO and tokens of Twitter user 0xc4ad.

Seeing this, many people may have doubts: Why can CRV be deployed in advance by others? Can this part of CRV mined in advance be traded in the market normally? Will it have an impact on CRV? And why didn't the Curve team redeploy a contract address?

Hao Tian, ​​Brand Director of PeckShield, told Odaily that the Curve code has been open-sourced before deployment, and anyone can see it. Participants with ulterior motives are among them. Attackers observe the actions of the project side to deploy the contract, for example, Etherscan or For the full-node transaction pool and the like, it was found that the project party had deployed the contract, and the attacker also deployed the exact same contract at the same time, or successfully deployed it with a higher gas deployment fee.

In the time gap after the project party discovered that the deployment failed, the attacker had frantically started pre-mining, and was naturally discovered by the project party at the same time. The project party then began to disclose the situation and negotiate with the attacker on a solution.

One solution is: the project party negotiates with the attacker, requires them to hand over the private key, then destroys the pre-mined tokens, and re-announces the start of mining; the other is: the project party redeploys a new contract to start the project, However, considering the existing popularity of the project, this requires certain other cost considerations.

Hao Tian reminds all investors that no matter what, the project contracts that have been launched so far have no official control. Users are advised not to participate in order to avoid asset losses.

There are also netizens who believe that this is Curve's official dereliction of duty, and think that there is no need for the official to approve a preemptive contract. But at present, this matter has no loss for the official. The 250,000 CRV dug out in advance can only be paid by those who provided liquidity or buyers in the secondary market.