1/ We confirmed that both @paraswap deployer address (0x490ce4616672e93b1c8f5e43aa80312fd73dee8c) and @curve deployer address(0x07a3458ad662fbcdd4fca0b1b37be6a5b1bcd7ac) are vulnerable to the profanity vulnerability. The private keys can be recovered.

2/ However, it is not likely to be a serious issue as the owners/admins of the deployed contracts of Curve have been changed. Besides, only a few remaining assets (less than 1 ETH/BNB) are stolen by the attacker.

