The smart contracts were fine.
That is the first thing to understand about what happened to Curve Finance on August 9, 2022, and it is the part that still unsettles security engineers years later. Curve's on-chain code — the audited, battle-tested automated market maker holding billions in stablecoins — was never touched. No reentrancy bug. No oracle manipulation. No flash-loan exploit. The blockchain did exactly what it was supposed to do.
This is a companion discussion topic for the original entry at https://namefi.io/r/en/blog/the-curve-finance-dns-hijack