Curve Finance:
the original vote-escrow DEX, genuinely battle-tested and genuinely not risk-free.
We tore apart Curve Finance, running since January 2020 and purpose-built for low-slippage trading between stablecoins and other correlated-price assets, across the same seven-category scorecard we've used throughout this series. From genuinely the lowest, most transparent fees we've found in this niche (0.04% on stablecoin pools), a real, credible, reasonably consistent multi-billion-dollar TVL, and the actual origin of the vote-escrow governance model that newer protocols, including Aerodrome's ve(3,3) system reviewed earlier in this series, have since adapted, to genuinely the most security incidents of any DEX we've reviewed so far: a 2023 Vyper compiler exploit (not Curve's own contract code) costing tens of millions before roughly 70% was recovered, a 2025 DNS hijack and frontend compromise, and a third, more recent incident in March 2026, plus a real, specific, well-documented governance-concentration risk tied to a single named third-party protocol; and landed on a score the marketing page won't show you.
Our take, up front: Curve Finance, launched in January 2020 by Michael Egorov, uses a specialized AMM algorithm purpose-built for assets that should trade at similar prices, stablecoins and liquid staking derivatives specifically, delivering genuinely tighter pricing and lower slippage for these pairs than a general-purpose formula like Uniswap's. Real, genuinely competitive, precisely quantified fees: 0.04% on stablecoin pools, substantially lower than Uniswap's 0.3% base tier, with volatile-asset pools (Curve V2) ranging from 0.04% to 0.4% depending on volatility, split between liquidity providers and veCRV holders. Real, genuinely large, reasonably consistent total value locked across our sources, cited variously as "over $2 billion" and "in the low billions," without the extreme discrepancy we found researching Aerodrome. Real, genuinely significant fee-capture dominance within its niche: reportedly capturing roughly 44% of all DEX fees on Ethereum as of 2026. Real, genuinely the origin of the vote-escrow governance model that newer protocols have since adapted, including Aerodrome's ve(3,3) system reviewed earlier in this series: locking CRV for one week to four years grants non-transferable veCRV, which votes on gauge weights directing CRV emissions, earns 50% of protocol fees, and boosts LP rewards up to 2.5x. Real, genuinely extensive, multi-firm audits from Trail of Bits, MixBytes, and Quantstamp, backed by a $250,000 bug bounty. Real, crvUSD, Curve's own stablecoin, with supply exceeding $120 million, plus expansion into lending and yield products. What we can't set aside: genuinely the most security incidents of any DEX we've reviewed in this series, three in total per independent data aggregation. The most significant, July 2023, involved a reentrancy-style vulnerability in the Vyper programming language's compiler itself, not Curve's own contract logic specifically, exploited across multiple Curve pools and unrelated protocols using the same compiler, with losses reported around $69-70 million, though roughly 70% was ultimately recovered through a genuinely collaborative response involving MEV searchers and partner protocols pausing their own contracts. A separate 2025 incident involved a DNS hijack and frontend compromise. Most recently, March 2, 2026, a third, distinct incident involved $240,000, classified as a token and share accounting issue. Real, honest, specific, well-documented governance-concentration risk: Convex, a separate protocol, accumulates large veCRV voting blocs on behalf of its own users, creating what one detailed source describes directly as a second governance layer on top of Curve itself. We weighted all of it below.
Real, genuinely extensive, well-documented, multi-firm audits: Trail of Bits, MixBytes, and Quantstamp, backed by a $250,000 bug bounty. Real, however, genuinely the most security incidents of any DEX we've reviewed in this series: three recorded incidents per independent data aggregation. The most significant, July 2023, involved a reentrancy-style vulnerability in the Vyper programming language's compiler itself, not Curve's own contract logic specifically, exploited across multiple Curve pools and unrelated protocols using the same compiler, with losses reported around $69-70 million, though roughly 70% was ultimately recovered through a genuinely collaborative response involving MEV searchers and partner protocols pausing their own contracts. A separate 2025 incident involved a DNS hijack and frontend compromise. Most recently, March 2, 2026, a third, distinct incident involved $240,000, classified as a token and share accounting issue. Real, honest, useful framing worth adopting directly: Curve is genuinely one of DeFi's most battle-tested liquidity layers, but "battle-tested" isn't the same as "risk-free."
Pros
- Multi-firm audits (Trail of Bits, MixBytes, Quantstamp) plus a $250K bug bounty
- Genuinely collaborative 2023 incident response; ~70% of losses recovered
- 2023 root cause was a third-party compiler bug, not a flaw unique to Curve's own code
Cons
- Three separate, distinct security incidents (2023 compiler exploit, 2025 DNS/frontend, 2026 accounting)
- Most incidents of any DEX we've reviewed in this series
Real, genuinely large, reasonably consistent total value locked across our sources, cited variously as "over $2 billion" and "in the low billions," a real, credible range without the extreme discrepancy we found researching Aerodrome. Real, genuinely significant fee-capture dominance within its specific niche: reportedly capturing roughly 44% of all DEX fees on Ethereum as of 2026.
Pros
- Reasonably consistent, credible multi-billion-dollar TVL across sources
- ~44% of all DEX fees on Ethereum, a genuinely significant niche dominance
Cons
- TVL has historically dropped sharply following incidents (from $3B+ to ~$1.7B post-2023)
Real, genuinely the original source of the vote-escrow governance model that several newer protocols, including Aerodrome's ve(3,3) system reviewed earlier in this series, have since adapted: locking CRV for one week to four years grants non-transferable veCRV, which votes on gauge weights directing CRV emissions, earns 50% of protocol fees, and boosts LP rewards up to 2.5x. What we can't set aside: a real, specific, well-documented governance-concentration risk. Convex, a separate protocol, accumulates large veCRV voting blocs on behalf of its own users, creating what one detailed source describes directly as a second governance layer on top of Curve itself, a real, structural concentration of influence beyond ordinary token holders.
Pros
- Genuinely the original vote-escrow model, directly influencing newer protocols in this series
- Real, functioning 50% fee-switch to long-term participants
Cons
- Real, specific, named governance-concentration risk via Convex's voting blocs
- Effectively a second governance layer sits on top of ordinary token holders
Real, genuinely broad, multi-chain reach: operates as an independent application across Ethereum, Polygon, and other networks. Real, genuinely distinctive, specialized focus on stablecoins and other correlated-price assets, with a purpose-built AMM algorithm for tight pricing and low slippage on these specific pairs. Real, crvUSD, Curve's own stablecoin, with supply exceeding $120 million, plus expansion into lending and yield products beyond pure swapping.
Pros
- Multi-chain reach across Ethereum, Polygon, and other networks
- Specialized, genuinely tight pricing for stablecoins and correlated-price assets
- crvUSD stablecoin and lending/yield product expansion
Cons
- Not well-suited for general, uncorrelated-asset trading by design
Real, genuinely straightforward stablecoin swap interface, consistently described as reliable for its specific use case. Real, honest, notable complexity: the gauge, voting-escrow, and emissions system requires real, genuine understanding to participate in beyond simple swapping, and the so-called "Curve Wars" among protocols competing for veCRV influence adds a layer most casual users won't need to track, but that shapes the platform's incentive structure regardless.
Pros
- Genuinely reliable, straightforward core swap experience
Cons
- Gauge/veCRV/emissions system carries real, genuine complexity beyond simple swapping
- "Curve Wars" dynamics add a layer of incentive complexity most casual users won't track
Real, genuinely competitive, precisely quantified fees: 0.04% on stablecoin pools, substantially lower than Uniswap's 0.3% base tier, with volatile-asset pools (Curve V2) ranging from 0.04% to 0.4% depending on volatility. Real, fees split between liquidity providers and veCRV holders under a 50% fee-switch mechanism.
Pros
- 0.04% stablecoin swap fee, substantially lower than most general-purpose AMMs
- Transparent 50% fee-switch to LPs and veCRV holders
Cons
- Full fee-sharing benefit requires locking CRV, not available to simple swappers
Real, genuinely distinctive crvUSD stablecoin and expansion into lending and yield products. Real, the original vote-escrow model that has directly influenced newer protocols across the industry, including at least one other platform reviewed in this series.
Pros
- crvUSD stablecoin plus lending/yield product expansion
- Foundational, industry-influencing vote-escrow governance design
Cons
- None significant found in our research
Access only through Curve's official app, and bookmark the genuine domain given the 2025 DNS-hijack history.
Keep any locked veCRV position sized to what you're comfortable committing for years, and treat governance-vote outcomes as genuinely shaped by large third-party voting blocs like Convex, not purely by individual token holders.
Genuinely foundational infrastructure, honest that a long history means a longer incident list too.
Curve deserves real credit for being the actual origin of a governance model that's since spread across the industry, for genuinely the lowest, most transparent fees we've found in the stablecoin niche, and for a credible, collaborative response to its most serious incident that recovered the large majority of stolen funds. What holds this score down is simple and specific: three separate, real security incidents spanning three different attack vectors is the most we've found for any DEX in this series, and a well-documented concentration of governance influence in a single third-party protocol is a real, structural fact about how Curve actually gets governed in practice, not merely a theoretical risk. None of this erases what Curve got right; it does mean "battle-tested" is doing real work in that description, not just serving as a compliment.
The scorecard above is deliberately general. Whether Curve is right for you depends heavily on which of these you already are.
The trader who specifically needs low-slippage swaps between stablecoins or other correlated-price assets
The 0.04% fee and purpose-built AMM algorithm genuinely serve this exact use case better than general-purpose DEXs.
The long-term liquidity provider willing to lock CRV for veCRV and participate in governance
The 50% fee-switch and up to 2.5x reward boost genuinely reward this kind of committed participation.
The trader comfortable with a platform that has survived and recovered from multiple, real incidents
The collaborative 2023 recovery is genuinely reassuring, though it doesn't erase the fact that three incidents occurred.
Traders wanting general-purpose, uncorrelated-asset swapping, or anyone wary of concentrated governance influence
Curve's specialized design and the real, documented Convex concentration make this a better fit for stablecoin-focused use cases specifically.
The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; all three security incidents timelined precisely, the Convex governance-concentration risk explained, the veCRV mechanics broken down, and Curve against the full field.
Three distinct incidents, timelined precisely
| Date | Type | Amount | Root cause |
|---|---|---|---|
| July 30, 2023 | Reentrancy exploit | ~$69-70M (≈70% recovered) | Vyper compiler vulnerability, not Curve's own contract code |
| 2025 | DNS hijack / frontend compromise | Not fully quantified in our research | Frontend infrastructure, not smart contracts |
| March 2, 2026 | Token & share accounting issue | $240,000 | Contract-level accounting error |
Three genuinely different attack vectors, a compiler-level supply chain issue, a frontend/DNS compromise, and a contract accounting bug, is a broader pattern of exposure than we've found for any other DEX in this series, even though each individual incident has a distinct, specific explanation.
The Convex governance-concentration risk, explained
| Detail | |
|---|---|
| What Convex is | A separate protocol that locks CRV on behalf of its own users |
| What this creates | Convex votes as a large veCRV holder, routing influence through its own vote-locked CVX community |
| Real effect | A second, real governance layer sits on top of ordinary individual CRV lockers |
This isn't unique to Curve as a design flaw, meta-governance layers are a known feature of vote-escrow systems generally, but it's a real, specific, well-documented fact about how voting power actually concentrates in practice.
veCRV mechanics, broken down
| Detail | |
|---|---|
| Lock duration | 1 week to 4 years |
| Transferability | Non-transferable |
| Decay | Balance decays as lock approaches expiry |
| Benefits | Gauge-weight voting, 50% of protocol fees, up to 2.5x LP reward boost |
This is the original template that Aerodrome's veAERO system, reviewed earlier in this series, adapted; the core mechanics (lock, decay, vote, earn) are genuinely similar across both.
Curve against the full field
| Curve | Aerodrome | Uniswap | Raydium | Hyperliquid | Lighter | |
|---|---|---|---|---|---|---|
| Since | 2020 | 2023 | 2018 | 2021 | 2023 | 2025 (TGE) |
| Confirmed security incidents | Three | One | One | Two | None (JELLY was governance) | None found |
| Governance model | veCRV (original) | veAERO (derived) | Token-based, no ve-lock | RAY buyback | Validator-based | LIT governance token |
| Specialized niche | Stablecoins/correlated assets | Base-native general AMM | General-purpose | Solana-native general AMM | Perpetuals | Perpetuals |
Curve is genuinely the ve-model pioneer in this comparison, but also carries the most security incidents; a real reminder that a foundational role and a clean record aren't the same thing.
We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. We've flagged two sources as notably dated (2024-2025) relative to our other, more current 2026 research, and weighted them accordingly.
Our score lands meaningfully below the aggregated industry average; most sources weight the genuinely low fees and foundational governance role heavily, while giving comparatively less weight to the third, more recent 2026 incident and the specific Convex concentration risk than our methodology does.
| Source | Score | Type |
|---|
Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.
Yes, three separate, distinct incidents on record: a July 2023 reentrancy exploit via a Vyper compiler vulnerability (~$69-70M, ~70% recovered), a 2025 DNS hijack and frontend compromise, and a March 2026 token and share accounting issue ($240,000).
Not entirely. The vulnerability was in the Vyper programming language's compiler itself, not unique to Curve's own contract code, and it affected multiple unrelated protocols using the same compiler. Curve was one of several projects affected by the same underlying tooling bug.
Vote-escrowed CRV, received by locking CRV for one week to four years. It's non-transferable, decays as the lock approaches expiry, and grants gauge-weight voting power, 50% of protocol fees, and up to a 2.5x LP reward boost. This is the original model that Aerodrome's veAERO system later adapted.
Nominally, veCRV holders, but a real, well-documented concentration exists: Convex, a separate protocol, locks large amounts of CRV on behalf of its own users and votes with that combined influence, creating a genuine second governance layer.
0.04% on stablecoin pools, substantially lower than Uniswap's 0.3% base tier. Volatile-asset pools (Curve V2) range from 0.04% to 0.4% depending on volatility.
Curve's own stablecoin, with supply exceeding $120 million as of 2025, part of the protocol's expansion into lending and yield products beyond pure AMM swapping.
Ethereum, Polygon, and other networks, operating as an independent application across each.
It's possible via Curve V2, but the platform's core design and pricing advantage is specifically for stablecoins and correlated-price assets; general-purpose DEXs like Uniswap are typically a better fit for uncorrelated pairs.
More Reviews
THORChain – DEX Review
Score: 46/100. Unmatched native cross-chain swaps, carrying 2021 hacks, a $200M 2025 crisis, and use as a laundering conduit.
Read MoreHyperliquid – DEX Review
Score: 73/100. Dominant perp DEX, but closed-source code and the JELLY delisting controversy are real, unresolved trust questions.
Read MoreVertex – DEX Review
Score: 62/100. Sophisticated cross-margin trading, reviewed mid-migration to a new chain with conflicting founder accounts.
Read MoreRaydium – DEX Review
Score: 68/100. Solana's liquidity leader, carrying two confirmed incidents and a real, wide gap in third-party security ratings.
Read More



