Scam Alert

KyberSwap Vulnerability Appears Due To Elastic Function Leads To $46M In Losses

Key Points:

  • KyberSwap Elastic recently experienced an attack resulting in the misappropriation of around $46 million in various cryptocurrencies.
  • CertiK identified a KyberSwap vulnerability in the computeSwapStep() function, allowing the attacker to strategically deplete pools with low liquidity.
  • The KyberSwap team responded to the attacker, offering a 10% reward for the return of the stolen assets.
In a recent incident, KyberSwap Elastic, a decentralized exchange, fell victim to an attack resulting in the misappropriation of approximately $46 million in various cryptocurrencies.

Blockchain security firm CertiK identified a KyberSwap vulnerability, specifically in the computeSwapStep() function’s implementation. This function, responsible for calculating exchange input/output amounts, fees, and sqrtP, erroneously generated a slightly larger price than the targetSqrtP due to a miscalculation in the calcFinalPrice call.

The attacker exploited this KyberSwap vulnerability by performing precise calculations within the empty scale range of the liquidity pool. By strategically utilizing cross-exchange liquidity counts, they managed to deplete KyberSwap pools containing low liquidity, leading to the successful attack.

The stolen funds, totaling $46 million, have been dispersed across various chains, including Arbitrum, Optimism, Ethereum, Polygon, and Base. Blockchain investigator “Spreek” clarified that the issue is not related to approvals but pertains to the total value locked (TVL) in Kyber’s liquidity pools.

In response to the attack, the KyberSwap team directly engaged with the hacker, offering a 10% reward, approximately $4.7 million, for the return of the stolen assets.

KyberSwap co-founder Victor Tran urged the attacker to refund 90% of the hacked amount to a specified wallet address before 06:00 AM on November 25 UTC.

DISCLAIMER: The information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Harold

With a passion for untangling the complexities of the financial world, I've spent over four years in financial journalism, covering everything from traditional equities to the cutting edge of venture capital. "The financial markets are a fascinating puzzle," I often say, "and I love helping people make sense of them." That's what drives me to bring clear and insightful financial journalism to the readers of Coincu.

Recent Posts

Best Cryptos with 1000X Potential: Qubetics Revolutionises Blockchain as Polkadot and Cosmos Shape the Future

Discover why Qubetics, Polkadot, and Cosmos are the best cryptos with 1000X potential, offering innovation,…

3 hours ago

Best Coins to Buy in December 2024: Qubetics Offer 630% ROI, Polkadot Delivers on Interoperability and Near Protocol’s Scalability is Talk of the Town

Explore the best coins to buy in December 2024—Qubetics with its thrilling presale, Polkadot’s interoperability,…

9 hours ago

Crypto Market Outlook 2025 Key Factors to Watch

The Crypto Market Outlook 2025 highlights key areas: stablecoin growth, tokenization, crypto ETFs, DeFi innovation,…

12 hours ago

Bitcoin Quantum Computing Threat Expected to Take Decades

The Bitcoin quantum computing threat is years away, but reserves already support post-quantum signatures via…

12 hours ago

Best New Meme Coins to Invest in Today: BTFD Coin Wows Investors with Unmissable Stage-7 Price Reversal as Book of Meme and Snek Crash

Don't miss BTFD Coin's Stage-7 presale dip! Find out why it's leading the pack of…

12 hours ago

Crypto Hedge Funds Banking Issues Persist Over Recent Years

A WSJ survey reveals crypto hedge funds banking issues over three years, with 120 out…

12 hours ago

This website uses cookies.