It seems @Convergence_fi was just exploited (w/ ~$210k loss) to mint 58m $CVG (58,718,395.05681812), which are swapped to 60 WETH and 15.9k crvFRAX. The bug is part of the CvxRewardDistributor contract, which does not validate the (untrusted) user input to claim rewards. Here is the hack tx:
44,99K