Historical retrospective · Security
A Vyper compiler bug contributed to a DeFi reentrancy crisis
In July 2023 a bug affecting specific Vyper compiler versions was linked to reentrancy vulnerabilities in several Curve pools and other contracts.
The episode showed that smart-contract risk can originate in compilers and shared tooling, not only application code.
It renewed interest in compiler version pinning, reproducible builds and dependency auditing.
Audits need to include toolchains and deployed bytecode; reviewing source code alone may miss compiler-specific behavior.
Primary source
This retrospective summarizes the source below in original language. The displayed year refers to the dated event, proposal or specification; it is not the article’s publication date. This is not investment, legal or security advice.