KiloEx reveals $7m smart contract exploit in post-mortem report

by shayaan

Decentralized perpetual exchange KiloEx published a post-mortem on its $7 million exploit that stemmed from a critical smart contract vulnerability.

According to the reportthe problem stemmed from the TrustedForwarder contract, which inherited from OpenZeppelin’s MinimalForwarderUpgradeable, but failed to override the “execute” method, leaving it without permission.

This surveillance allowed the attacker to manipulate trading positions across chains. On April 13, the attacker initiated the exploit by withdrawing 1 ETH (ETH) from Tornado Cash to fund wallets on different chains.

The attacker performed the exploit in less than an hour by abusing the open method to open and close positions at favorable prices.

The exploit was first discovered by Cyvers Alerts, which flagged suspicious cross-chain activity in Base, Taiko and BNB Chain. According to PeckSchildthe losses were spread across Base, opBNB and BSC.

Hacker negotiations

According to the report, and after lengthy negotiations, the hacker agreed to a 10% bounty retention and systematically returned all stolen assets to KiloEx’s designated Safe multi-signature wallets.

KiloEx said the vulnerability has been fixed and stressed that no open positions will be liquidated. Instead, all positions are closed based on price snapshots taken before the attack. Profits and losses from the operating period do not count towards the end user’s balance.

The platform also said it was working with police and SlowMist to investigate the hack.

Source link

See also  Trump Wants All Future Bitcoin Mined in US—Is That Even Possible?

You may also like

Latest News

Copyright © Sovereign Wealth Signals