Hacker removed $47 million worth of cryptoassets from CyberSwap pools

Lord777

Professional
Messages
2,579
Reaction score
1,471
Points
113
Representatives of the decentralized exchange KyberSwap reported on the hacking of the Elastic Pools liquidity pool, as a result of which hackers withdrew about $47 million from the protocol.

Urgent

Dear KyberSwap Elastic Users,
We regret to inform you that KyberSwap Elastic has experienced a security incident.

As a precautionary measure, we strongly advise all users to promptly withdraw their funds. Our team is diligently investigating the situation, and we…
— Kyber Network (@KyberNetwork) November 22, 2023

"As a precautionary measure, we strongly recommend that all users withdraw their funds immediately," the project team warned.

The first hack was discovered by user X under the pseudonym Spreek, indicating a suspicious withdrawal of funds.

Kyber being exploited on all chains rn. here's an example tx on base. 20m+ lost already pic.twitter.com/gvv7M9HWH6
— Spreek (@spreekaway) November 22, 2023

According to his calculations, the stolen assets include $7.5 million in the Ethereum network, $15 million in Optimism, $16 million in Arbitrum, $2.8 million in Polygon and $870,000 in Base.

The hacker also left a message attached to the transaction:

"Dear KyberSwap developers, employees, DAO members and partners, negotiations will begin in a few hours when I am fully rested. Thank you."

Cinneamhain Ventures general Partner Adama Cochran believes that the exploit was made possible by using flash credits and "some mathematical calculations." He came to this conclusion because each transaction of the attacker began with the receipt of ETH to pay for the swap.

Looks like the Kyber exploits is flash loans and some sort of math/rounding issue.

Each tx is starting with an ETH balance coming in, looped mint/redeem/swap.

So likely not a risk to approvals from non-LPs but worth staying frosty
— Adam Cochran (adamscochran.eth) (@adamscochran) November 22, 2023
 
Top