Decentralized exchange KiloEx says $7.5M exploit has been contained

Decentralized exchange KiloEX has confirmed it has suspended usage of its platform and is tracing stolen funds after suffering a $7.5 million exploit.
The exploit has been contained, with use of the platform suspended and an investigation underway, the KiloEX team said in an April 14 statement to X.
“The team has immediately suspended platform usage and is working with security partners to trace the flow of funds,” KiloEX said.
“We are analyzing the attack vector and affected assets. We are collaborating with ecosystem partners to trace and recover funds where possible.”
Source: KiloEX
A bounty program and a full report on how the exploit occurred is also in the works, according to KiloEX.
In an update, the KiloEX team said it was collaborating with BNB Chain, Manta Network, and cybersecurity firms Seal-911, SlowMist and Sherlock in an effort spanning “multiple ecosystems.”
“Our investigation has confirmed that the stolen assets are currently being routed through zkBridge and Meson,” KiloEX said.
“We are urgently attempting to engage with both protocols to halt ongoing transactions and prevent additional losses.”
KiloEX attacker exploited price oracle issue, say analysts
Cybersecurity firm PeckShield said in an April 14 post to X the exploiter looted $7.5 million in total, $3.3 million Base, $3.1m opBNB and $1m BSC.
The firm has speculated the exploit is likely a “price oracle issue,” where the information used by a smart contract to determine the price of an asset is manipulated or inaccurate, leading to the exploit.
“Our initial analysis on one transaction exploit indicates a price oracle issue,” PeckShield said.
Source: PeckShield
“The hacker exploits it to create a new position with initial given ETH/USD price of 100 and then immediately close the position with inflated ETH/USD price of 10000, netting the $3.12m profit in one single transaction.”
Chaofan Shou, co-founder of blockchain analytics firm Fuzzland, also weighed in, speculating the exploit was likely due to a price oracle issue.
“Anyone can change the Kilo’s price oracle. They did verify that the caller shall be a trusted forwarder, though, but didn’t verify the forwarded caller,” Shou said.
Shou added it was a “very simple vulnerability” when a user asked about the complexity of the exploit.
Source: Chaofan Shou
The news has sent the KiloEX’s native token, Kilo, plunging over 27% to trade at $0.03596, according to CoinGecko. It’s still down over 78% from its all-time high of $0.1648, which it hit on March 27.
Related: Mantra CEO says OM token recovery ‘primary concern’ but in early stages
KiloEx was established in 2023 and is backed by Binance Labs, which is a lead investor and strategic partner.
This exploit comes just days after the exchange announced a partnership with Dubai-based Web3 venture capitalist firm DWF Labs on April 13, which promised to expand KiloEx’s market presence and accelerate growth.
On March 25, DWF Labs launched a $250 million Liquid Fund to accelerate the growth of mid- and large-cap blockchain projects and drive real-world adoption of Web3 technologies.
Magazine: Bitcoin eyes $100K by June, Shaq to settle NFT lawsuit, and more: Hodler’s Digest, April 6–12
Bitcoin (BTC) $ 119,292.00
Ethereum (ETH) $ 3,861.09
XRP (XRP) $ 3.25
Tether (USDT) $ 1.00
BNB (BNB) $ 848.04
Solana (SOL) $ 189.25
USDC (USDC) $ 0.999789
Dogecoin (DOGE) $ 0.239881
Lido Staked Ether (STETH) $ 3,857.93
TRON (TRX) $ 0.320156
Cardano (ADA) $ 0.833119
Wrapped stETH (WSTETH) $ 4,658.93
Wrapped Bitcoin (WBTC) $ 119,118.00
Sui (SUI) $ 4.31
Hyperliquid (HYPE) $ 43.70
Stellar (XLM) $ 0.444329
Chainlink (LINK) $ 19.08
Wrapped Beacon ETH (WBETH) $ 4,135.04
Hedera (HBAR) $ 0.285974
Bitcoin Cash (BCH) $ 591.15
Avalanche (AVAX) $ 25.97
Wrapped eETH (WEETH) $ 4,132.01
WETH (WETH) $ 3,864.61
Litecoin (LTC) $ 114.55
Toncoin (TON) $ 3.40
Shiba Inu (SHIB) $ 0.000014
LEO Token (LEO) $ 8.96
USDS (USDS) $ 0.999589
Ethena USDe (USDE) $ 1.00
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998527
Uniswap (UNI) $ 10.88
WhiteBIT Coin (WBT) $ 44.70
Polkadot (DOT) $ 4.21
Coinbase Wrapped BTC (CBBTC) $ 119,328.00
Monero (XMR) $ 324.92
Bitget Token (BGB) $ 4.72
Pepe (PEPE) $ 0.000013
Cronos (CRO) $ 0.144203
Aave (AAVE) $ 303.81
Ethena Staked USDe (SUSDE) $ 1.19
Ethena (ENA) $ 0.656218
Bittensor (TAO) $ 429.35
Dai (DAI) $ 0.999913
Pi Network (PI) $ 0.469263
NEAR Protocol (NEAR) $ 2.93
Ethereum Classic (ETC) $ 23.09
Ondo (ONDO) $ 1.06
Aptos (APT) $ 4.88
Internet Computer (ICP) $ 5.78
Jito Staked SOL (JITOSOL) $ 230.06
OKB (OKB) $ 49.54
Mantle (MNT) $ 0.831597
Kaspa (KAS) $ 0.104757
Pudgy Penguins (PENGU) $ 0.042683
Bonk (BONK) $ 0.000033
Algorand (ALGO) $ 0.283758
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
Arbitrum (ARB) $ 0.455242
Binance-Peg WETH (WETH) $ 3,850.83
VeChain (VET) $ 0.026110
Cosmos Hub (ATOM) $ 4.85
Render (RENDER) $ 4.31
USD1 (USD1) $ 1.00
Gate (GT) $ 18.23
Worldcoin (WLD) $ 1.20
POL (ex-MATIC) (POL) $ 0.239320
Sky (SKY) $ 0.097412
Official Trump (TRUMP) $ 10.33
SPX6900 (SPX) $ 2.20
Sei (SEI) $ 0.345165
Fasttoken (FTN) $ 4.60
Artificial Superintelligence Alliance (FET) $ 0.755584
Binance Staked SOL (BNSOL) $ 200.77
Filecoin (FIL) $ 2.75
Jupiter (JUP) $ 0.607900
Rocket Pool ETH (RETH) $ 4,392.82
Flare (FLR) $ 0.025020
Kelp DAO Restaked ETH (RSETH) $ 4,048.58
Lombard Staked BTC (LBTC) $ 119,314.00
sUSDS (SUSDS) $ 1.06
Story (IP) $ 5.59
Jupiter Perpetuals Liquidity Provider Token (JLP) $ 5.13
Injective (INJ) $ 15.26
Celestia (TIA) $ 2.04
KuCoin (KCS) $ 11.59
XDC Network (XDC) $ 0.089859
StakeWise Staked ETH (OSETH) $ 4,060.26
USDtb (USDTB) $ 0.999821
Mantle Staked Ether (METH) $ 4,135.01
Liquid Staked ETH (LSETH) $ 4,175.22
Curve DAO (CRV) $ 1.01
USDT0 (USDT0) $ 1.00
First Digital USD (FDUSD) $ 0.998692
Stacks (STX) $ 0.854407
Fartcoin (FARTCOIN) $ 1.35
NEXO (NEXO) $ 1.33
Optimism (OP) $ 0.735394
Renzo Restaked ETH (EZETH) $ 4,057.97
FLOKI (FLOKI) $ 0.000131
Polygon Bridged USDT (Polygon) (USDT) $ 0.999987