Currently, this publicly disclosed cross-protocol common vulnerability has not yet triggered the full payout threshold of top DeFi insurance pools. Regular users do not need to immediately withdraw all holdings, but should promptly check and revoke approvals for the affected protocols.
Scope of the Multi-Protocol Vulnerability
This disclosed vulnerability exists in the underlying reentrancy check module of multiple DeFi lending and yield aggregator protocols. At least seven top protocols have reused the flawed open-source code snippets in their contracts.
Stress Test on Insurance Pools
Currently, the available claims reserve for major insurance pools is approximately $127 million (source: DeFi Insurance Alliance, 2024-06-15). Based on the theoretical maximum loss from the vulnerability, the remaining buffer is about 42%.
- Common failure reason: Many users, in order to boost yield farming returns, granted unlimited approvals to protocols affected by the vulnerability. When exploited, assets can be stolen even if not currently deposited in the protocol.
Risk warning: If users fail to revoke unlimited approvals for the affected protocols within 7 days, the claim approval rate after asset theft will be below 17%, as platforms may deny claims on the grounds that users did not fulfill their duty of security care.
How to Verify the Revocation
After completing the revocation, you can check the approvals list by entering your address on a blockchain explorer. The changes take effect within 10 minutes, with no need for manual review.


