Close Menu
    Facebook X (Twitter) Instagram
    Saturday, July 5
    X (Twitter) Instagram LinkedIn YouTube
    Chain Tech Daily
    Banner
    • Altcoins
    • Bitcoin
    • Crypto
    • Coinbase
    • Litecoin
    • Ethereum
    • Blockchain
    • Lithosphere News Releases
    Chain Tech Daily
    You are at:Home » KiloEx reveals $7m smart contract exploit in post-mortem report
    Crypto

    KiloEx reveals $7m smart contract exploit in post-mortem report

    James WilsonBy James WilsonApril 21, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Decentralized perpetual exchange KiloEx published a post-mortem on its $7 million exploit stemming from a critical smart contract vulnerability. 

    According to the report, the issue originated from the TrustedForwarder contract, which inherited from OpenZeppelin’s MinimalForwarderUpgradeable but failed to override the “execute” method, leaving it permissionless.

    This oversight allowed the attacker to manipulate trading positions across several chains. On April 13, the attacker initiated the exploit by withdrawing 1 ETH (ETH) from Tornado Cash to fund wallets across chains. 

    The attacker executed the exploit in under an hour by abusing the open method to open and close positions at favorable prices.

    The exploit was first detected by Cyvers Alerts, which flagged suspicious cross-chain activity across Base, Taiko, and BNB Chain. According to PeckShield, losses were spread across Base, opBNB, and BSC.

    Hacker negotiations 

    According to the report, and after sustained negotiations, the hacker agreed to a 10% bounty retention and systematically returned all stolen assets to KiloEx’s designated Safe multi-signature wallets.

    KiloEx said the vulnerability has been fixed and emphasized that no open positions will face liquidation. Instead, all positions will be closed based on price snapshots taken before the attack. Profits and losses from the exploit period will not count toward final user balances.

    The platform also said it worked with police and SlowMist to investigate the hack.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThis might be the last chance to buy BTC at under $100K: analyst
    Next Article Strategy buys 6,556 Bitcoin after BTC reaches monthly high
    James Wilson

    Related Posts

    Will SOL rally to $200?

    July 5, 2025

    Bitcoin treasuries divide crypto bros: Just a fiat disguise?

    July 5, 2025

    BitMine raises $250m, TWL Miner bags $85m

    July 5, 2025
    Leave A Reply Cancel Reply

    Don't Miss

    Will SOL rally to $200?

    Bitcoin treasuries divide crypto bros: Just a fiat disguise?

    BitMine raises $250m, TWL Miner bags $85m

    NFT sales jump 10% to $136.5m, CryptoPunks shows 26% pop

    About
    About

    ChainTechDaily.com is your daily destination for the latest news and developments in the cryptocurrency space. Stay updated with expert insights and analysis tailored for crypto enthusiasts and investors alike.

    X (Twitter) Instagram YouTube LinkedIn
    Popular Posts

    Will SOL rally to $200?

    July 5, 2025

    Bitcoin treasuries divide crypto bros: Just a fiat disguise?

    July 5, 2025

    BitMine raises $250m, TWL Miner bags $85m

    July 5, 2025
    Lithosphere News Releases

    AGII Refines Sync Performance Across Chains to Boost Response Efficiency

    July 4, 2025

    Imagen AI (IMAGE) Developer to Enable Ripple Labs Stablecoin RLUSD for Service Payments

    July 3, 2025

    Imagen Network Begins Strategic Expansion with Bitcoin-Funded AI Infrastructure Rollout

    July 2, 2025
    Copyright © 2025

    Type above and press Enter to search. Press Esc to cancel.