Curve Finance; Reviewed & Scored | The Block Note
DEX Review · Updated August 2026

Curve Finance:
the original vote-escrow DEX, genuinely battle-tested and genuinely not risk-free.

We tore apart Curve Finance, running since January 2020 and purpose-built for low-slippage trading between stablecoins and other correlated-price assets, across the same seven-category scorecard we've used throughout this series. From genuinely the lowest, most transparent fees we've found in this niche (0.04% on stablecoin pools), a real, credible, reasonably consistent multi-billion-dollar TVL, and the actual origin of the vote-escrow governance model that newer protocols, including Aerodrome's ve(3,3) system reviewed earlier in this series, have since adapted, to genuinely the most security incidents of any DEX we've reviewed so far: a 2023 Vyper compiler exploit (not Curve's own contract code) costing tens of millions before roughly 70% was recovered, a 2025 DNS hijack and frontend compromise, and a third, more recent incident in March 2026, plus a real, specific, well-documented governance-concentration risk tied to a single named third-party protocol; and landed on a score the marketing page won't show you.

Type Decentralized Exchange (stablecoin-specialized AMM) Platforms Web · Ethereum, Polygon, and other chains Fees 0.04% stable pools; 0.04%-0.4% volatile pools Discount Offer None
curve
DEX
StableSwap AMM · Origin of veCRV
Three distinct incidents on record

Our take, up front: Curve Finance, launched in January 2020 by Michael Egorov, uses a specialized AMM algorithm purpose-built for assets that should trade at similar prices, stablecoins and liquid staking derivatives specifically, delivering genuinely tighter pricing and lower slippage for these pairs than a general-purpose formula like Uniswap's. Real, genuinely competitive, precisely quantified fees: 0.04% on stablecoin pools, substantially lower than Uniswap's 0.3% base tier, with volatile-asset pools (Curve V2) ranging from 0.04% to 0.4% depending on volatility, split between liquidity providers and veCRV holders. Real, genuinely large, reasonably consistent total value locked across our sources, cited variously as "over $2 billion" and "in the low billions," without the extreme discrepancy we found researching Aerodrome. Real, genuinely significant fee-capture dominance within its niche: reportedly capturing roughly 44% of all DEX fees on Ethereum as of 2026. Real, genuinely the origin of the vote-escrow governance model that newer protocols have since adapted, including Aerodrome's ve(3,3) system reviewed earlier in this series: locking CRV for one week to four years grants non-transferable veCRV, which votes on gauge weights directing CRV emissions, earns 50% of protocol fees, and boosts LP rewards up to 2.5x. Real, genuinely extensive, multi-firm audits from Trail of Bits, MixBytes, and Quantstamp, backed by a $250,000 bug bounty. Real, crvUSD, Curve's own stablecoin, with supply exceeding $120 million, plus expansion into lending and yield products. What we can't set aside: genuinely the most security incidents of any DEX we've reviewed in this series, three in total per independent data aggregation. The most significant, July 2023, involved a reentrancy-style vulnerability in the Vyper programming language's compiler itself, not Curve's own contract logic specifically, exploited across multiple Curve pools and unrelated protocols using the same compiler, with losses reported around $69-70 million, though roughly 70% was ultimately recovered through a genuinely collaborative response involving MEV searchers and partner protocols pausing their own contracts. A separate 2025 incident involved a DNS hijack and frontend compromise. Most recently, March 2, 2026, a third, distinct incident involved $240,000, classified as a token and share accounting issue. Real, honest, specific, well-documented governance-concentration risk: Convex, a separate protocol, accumulates large veCRV voting blocs on behalf of its own users, creating what one detailed source describes directly as a second governance layer on top of Curve itself. We weighted all of it below.

Real, genuinely extensive, well-documented, multi-firm audits: Trail of Bits, MixBytes, and Quantstamp, backed by a $250,000 bug bounty. Real, however, genuinely the most security incidents of any DEX we've reviewed in this series: three recorded incidents per independent data aggregation. The most significant, July 2023, involved a reentrancy-style vulnerability in the Vyper programming language's compiler itself, not Curve's own contract logic specifically, exploited across multiple Curve pools and unrelated protocols using the same compiler, with losses reported around $69-70 million, though roughly 70% was ultimately recovered through a genuinely collaborative response involving MEV searchers and partner protocols pausing their own contracts. A separate 2025 incident involved a DNS hijack and frontend compromise. Most recently, March 2, 2026, a third, distinct incident involved $240,000, classified as a token and share accounting issue. Real, honest, useful framing worth adopting directly: Curve is genuinely one of DeFi's most battle-tested liquidity layers, but "battle-tested" isn't the same as "risk-free."

Why this scores below the midpoint: genuinely extensive, credible audit investment and a real, collaborative incident-response track record are positives, tempered by three separate, real, distinct security incidents spanning three different attack vectors, more than any other DEX we've reviewed in this series.

Pros

  • Multi-firm audits (Trail of Bits, MixBytes, Quantstamp) plus a $250K bug bounty
  • Genuinely collaborative 2023 incident response; ~70% of losses recovered
  • 2023 root cause was a third-party compiler bug, not a flaw unique to Curve's own code

Cons

  • Three separate, distinct security incidents (2023 compiler exploit, 2025 DNS/frontend, 2026 accounting)
  • Most incidents of any DEX we've reviewed in this series

Real, genuinely large, reasonably consistent total value locked across our sources, cited variously as "over $2 billion" and "in the low billions," a real, credible range without the extreme discrepancy we found researching Aerodrome. Real, genuinely significant fee-capture dominance within its specific niche: reportedly capturing roughly 44% of all DEX fees on Ethereum as of 2026.

Why this scores well: genuinely large, reasonably consistent liquidity and a real, significant fee-capture dominance within the stablecoin and correlated-asset niche specifically.

Pros

  • Reasonably consistent, credible multi-billion-dollar TVL across sources
  • ~44% of all DEX fees on Ethereum, a genuinely significant niche dominance

Cons

  • TVL has historically dropped sharply following incidents (from $3B+ to ~$1.7B post-2023)

Real, genuinely the original source of the vote-escrow governance model that several newer protocols, including Aerodrome's ve(3,3) system reviewed earlier in this series, have since adapted: locking CRV for one week to four years grants non-transferable veCRV, which votes on gauge weights directing CRV emissions, earns 50% of protocol fees, and boosts LP rewards up to 2.5x. What we can't set aside: a real, specific, well-documented governance-concentration risk. Convex, a separate protocol, accumulates large veCRV voting blocs on behalf of its own users, creating what one detailed source describes directly as a second governance layer on top of Curve itself, a real, structural concentration of influence beyond ordinary token holders.

Why this scores below the midpoint: genuinely the original, influential governance model in this space is a real point of credit, tempered by a real, specific, well-documented concentration of voting power in a single third-party protocol.

Pros

  • Genuinely the original vote-escrow model, directly influencing newer protocols in this series
  • Real, functioning 50% fee-switch to long-term participants

Cons

  • Real, specific, named governance-concentration risk via Convex's voting blocs
  • Effectively a second governance layer sits on top of ordinary token holders

Real, genuinely broad, multi-chain reach: operates as an independent application across Ethereum, Polygon, and other networks. Real, genuinely distinctive, specialized focus on stablecoins and other correlated-price assets, with a purpose-built AMM algorithm for tight pricing and low slippage on these specific pairs. Real, crvUSD, Curve's own stablecoin, with supply exceeding $120 million, plus expansion into lending and yield products beyond pure swapping.

Why this scores well: genuinely broad multi-chain reach and a real, specialized product focus, extended by crvUSD and lending products beyond pure AMM swapping.

Pros

  • Multi-chain reach across Ethereum, Polygon, and other networks
  • Specialized, genuinely tight pricing for stablecoins and correlated-price assets
  • crvUSD stablecoin and lending/yield product expansion

Cons

  • Not well-suited for general, uncorrelated-asset trading by design

Real, genuinely straightforward stablecoin swap interface, consistently described as reliable for its specific use case. Real, honest, notable complexity: the gauge, voting-escrow, and emissions system requires real, genuine understanding to participate in beyond simple swapping, and the so-called "Curve Wars" among protocols competing for veCRV influence adds a layer most casual users won't need to track, but that shapes the platform's incentive structure regardless.

Why this scores below the midpoint: a genuinely reliable, straightforward core swap experience is a real positive, tempered by real, honest complexity in the governance and incentive layers beyond basic swapping.

Pros

  • Genuinely reliable, straightforward core swap experience

Cons

  • Gauge/veCRV/emissions system carries real, genuine complexity beyond simple swapping
  • "Curve Wars" dynamics add a layer of incentive complexity most casual users won't track

Real, genuinely competitive, precisely quantified fees: 0.04% on stablecoin pools, substantially lower than Uniswap's 0.3% base tier, with volatile-asset pools (Curve V2) ranging from 0.04% to 0.4% depending on volatility. Real, fees split between liquidity providers and veCRV holders under a 50% fee-switch mechanism.

Why this scores well: genuinely among the lowest, most transparent fees for its specific stablecoin niche in this entire series.

Pros

  • 0.04% stablecoin swap fee, substantially lower than most general-purpose AMMs
  • Transparent 50% fee-switch to LPs and veCRV holders

Cons

  • Full fee-sharing benefit requires locking CRV, not available to simple swappers

Real, genuinely distinctive crvUSD stablecoin and expansion into lending and yield products. Real, the original vote-escrow model that has directly influenced newer protocols across the industry, including at least one other platform reviewed in this series.

Pros

  • crvUSD stablecoin plus lending/yield product expansion
  • Foundational, industry-influencing vote-escrow governance design

Cons

  • None significant found in our research
Where to get it

Access only through Curve's official app, and bookmark the genuine domain given the 2025 DNS-hijack history.

Keep any locked veCRV position sized to what you're comfortable committing for years, and treat governance-vote outcomes as genuinely shaped by large third-party voting blocs like Convex, not purely by individual token holders.

0/ 100

Genuinely foundational infrastructure, honest that a long history means a longer incident list too.

Curve deserves real credit for being the actual origin of a governance model that's since spread across the industry, for genuinely the lowest, most transparent fees we've found in the stablecoin niche, and for a credible, collaborative response to its most serious incident that recovered the large majority of stolen funds. What holds this score down is simple and specific: three separate, real security incidents spanning three different attack vectors is the most we've found for any DEX in this series, and a well-documented concentration of governance influence in a single third-party protocol is a real, structural fact about how Curve actually gets governed in practice, not merely a theoretical risk. None of this erases what Curve got right; it does mean "battle-tested" is doing real work in that description, not just serving as a compliment.

Best forTraders and liquidity providers who specifically need low-slippage stablecoin swaps and understand the real trade-offs of vote-escrow governance
Not forTraders wanting general-purpose asset swapping, or anyone uncomfortable with a platform carrying the most security incidents in this series
Score Ledger
curve · 7 line items
01Security16.5
02Liquidity15.0
03Decentralization8.25
04Assets7.0
05UX6.0
06Fees8.0
07Extras3.5
TOTAL64.25
≈ 64 / 100; Battle-tested, and it shows both ways

The scorecard above is deliberately general. Whether Curve is right for you depends heavily on which of these you already are.

Best fit

The trader who specifically needs low-slippage swaps between stablecoins or other correlated-price assets

The 0.04% fee and purpose-built AMM algorithm genuinely serve this exact use case better than general-purpose DEXs.

Good fit

The long-term liquidity provider willing to lock CRV for veCRV and participate in governance

The 50% fee-switch and up to 2.5x reward boost genuinely reward this kind of committed participation.

Workable fit

The trader comfortable with a platform that has survived and recovered from multiple, real incidents

The collaborative 2023 recovery is genuinely reassuring, though it doesn't erase the fact that three incidents occurred.

Poor fit

Traders wanting general-purpose, uncorrelated-asset swapping, or anyone wary of concentrated governance influence

Curve's specialized design and the real, documented Convex concentration make this a better fit for stablecoin-focused use cases specifically.

The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; all three security incidents timelined precisely, the Convex governance-concentration risk explained, the veCRV mechanics broken down, and Curve against the full field.

Three distinct incidents, timelined precisely

DateTypeAmountRoot cause
July 30, 2023Reentrancy exploit~$69-70M (≈70% recovered)Vyper compiler vulnerability, not Curve's own contract code
2025DNS hijack / frontend compromiseNot fully quantified in our researchFrontend infrastructure, not smart contracts
March 2, 2026Token & share accounting issue$240,000Contract-level accounting error

Three genuinely different attack vectors, a compiler-level supply chain issue, a frontend/DNS compromise, and a contract accounting bug, is a broader pattern of exposure than we've found for any other DEX in this series, even though each individual incident has a distinct, specific explanation.

The Convex governance-concentration risk, explained

Detail
What Convex isA separate protocol that locks CRV on behalf of its own users
What this createsConvex votes as a large veCRV holder, routing influence through its own vote-locked CVX community
Real effectA second, real governance layer sits on top of ordinary individual CRV lockers

This isn't unique to Curve as a design flaw, meta-governance layers are a known feature of vote-escrow systems generally, but it's a real, specific, well-documented fact about how voting power actually concentrates in practice.

veCRV mechanics, broken down

Detail
Lock duration1 week to 4 years
TransferabilityNon-transferable
DecayBalance decays as lock approaches expiry
BenefitsGauge-weight voting, 50% of protocol fees, up to 2.5x LP reward boost

This is the original template that Aerodrome's veAERO system, reviewed earlier in this series, adapted; the core mechanics (lock, decay, vote, earn) are genuinely similar across both.

Curve against the full field

CurveAerodromeUniswapRaydiumHyperliquidLighter
Since202020232018202120232025 (TGE)
Confirmed security incidentsThreeOneOneTwoNone (JELLY was governance)None found
Governance modelveCRV (original)veAERO (derived)Token-based, no ve-lockRAY buybackValidator-basedLIT governance token
Specialized nicheStablecoins/correlated assetsBase-native general AMMGeneral-purposeSolana-native general AMMPerpetualsPerpetuals

Curve is genuinely the ve-model pioneer in this comparison, but also carries the most security incidents; a real reminder that a foundational role and a clean record aren't the same thing.

We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. We've flagged two sources as notably dated (2024-2025) relative to our other, more current 2026 research, and weighted them accordingly.

The Block Note (us)N/A / 100
Industry averageN/A / 100

Our score lands meaningfully below the aggregated industry average; most sources weight the genuinely low fees and foundational governance role heavily, while giving comparatively less weight to the third, more recent 2026 incident and the specific Convex concentration risk than our methodology does.

SourceScoreType

Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.

Yes, three separate, distinct incidents on record: a July 2023 reentrancy exploit via a Vyper compiler vulnerability (~$69-70M, ~70% recovered), a 2025 DNS hijack and frontend compromise, and a March 2026 token and share accounting issue ($240,000).

Not entirely. The vulnerability was in the Vyper programming language's compiler itself, not unique to Curve's own contract code, and it affected multiple unrelated protocols using the same compiler. Curve was one of several projects affected by the same underlying tooling bug.

Vote-escrowed CRV, received by locking CRV for one week to four years. It's non-transferable, decays as the lock approaches expiry, and grants gauge-weight voting power, 50% of protocol fees, and up to a 2.5x LP reward boost. This is the original model that Aerodrome's veAERO system later adapted.

Nominally, veCRV holders, but a real, well-documented concentration exists: Convex, a separate protocol, locks large amounts of CRV on behalf of its own users and votes with that combined influence, creating a genuine second governance layer.

0.04% on stablecoin pools, substantially lower than Uniswap's 0.3% base tier. Volatile-asset pools (Curve V2) range from 0.04% to 0.4% depending on volatility.

Curve's own stablecoin, with supply exceeding $120 million as of 2025, part of the protocol's expansion into lending and yield products beyond pure AMM swapping.

Ethereum, Polygon, and other networks, operating as an independent application across each.

It's possible via Curve V2, but the platform's core design and pricing advantage is specifically for stablecoins and correlated-price assets; general-purpose DEXs like Uniswap are typically a better fit for uncorrelated pairs.

Affiliate & editorial disclosure: This page may contain affiliate links. If you buy through one, we may earn a commission at no extra cost to you. That relationship does not influence the category weightings or scores above; those are set by our editorial methodology before any offer is placed. Decentralized exchanges reduce custodial risk but do not eliminate risk: smart-contract, bridge, oracle, validator, and market-structure risk remain real regardless of how "decentralized" a platform's marketing describes it as. Leverage trading can result in losses exceeding your initial deposit. Nothing here is financial advice.
Features, pricing, and security details verified against public sources as of Aug 2026; always confirm current terms directly with Curve.

More Reviews

Vertex – DEX Review

Score: 62/100. Sophisticated cross-margin trading, reviewed mid-migration to a new chain with conflicting founder accounts.

Read More
raydium logo cover image

Raydium – DEX Review

Score: 68/100. Solana's liquidity leader, carrying two confirmed incidents and a real, wide gap in third-party security ratings.

Read More