Exploit_type: Access-Control Logic Vulnerability in Governance / Token Minting
Loss: ~$16 million
Entry_point: Governance mint and privilege execution logic within Curio DAO contracts (CGT token minting function)
Exploit_vector: Attacker acquired a small number of governance tokens and used flawed access control to elevate privileges, allowing them to mint 1 billion CGT (~$16 M)
Severity: Critical
Attack_steps:
Attacker obtained a minimal amount of Curio governance tokens (CGT) to meet the voting threshold.
Exploited a logic flaw in the governance contract that failed to enforce strict access control during mint function execution.
Submitted a malicious governance proposal using limited privileges to execute on-chain mint logic.
Proposal passed, triggering unauthorized minting of 1 billion CGT.
Attacker transferred minted tokens to external addresses, converting them to other assets.