Firepan AI identified a critical vulnerability in Curve's latest AMM before exploitation; scope limited to $193,660 across four twocrypto-ng pools.
Security & Exploits ·
Firepan's AI-driven audit uncovered a critical flaw in Curve Finance's FXSwap twocrypto-ng AMM during independent review in April 2026, before the code reached production. The vulnerability exploited how the pool's donation-protection mechanism—designed to prevent new liquidity providers from immediately claiming shares of external deposits—could be circumvented through a specific sequence of actions that bypassed the safeguard window. This composition bug combined individually benign properties in ways that proved invisible to standard review processes, even within a heavily audited codebase.
Curve patched the flaw before deployment, and no live funds faced exposure. The potential impact was bounded to four twocrypto-ng pools, with maximum at-risk value under $250,000 against $334 million in TVL across the staged pools. Firepan disclosed the finding privately on April 27, 2026, Curve confirmed and fixed the mechanism within one day, and the firm re-verified the patch by May 26, 2026, when the formal report was issued.
The case underscores the role of continuous security review for immutable contracts against shifting threat models, particularly as DeFi exploits reached nine figures during the same month. Details of Firepan's methodology and findings are documented in its technical report, with additional context available through the firm's case study materials.