Share this article

DeFi Platform Kyber Network Discloses $265K Exploit, Vows to Reimburse All Funds

This most recent attack on a decentralized finance platform resulted from malicious website code.

Updated May 11, 2023, 6:16 p.m. Published Sep 1, 2022, 8:17 p.m.
Victims of the Kyber Network attack will be reimbursed (Mika Baumeister/Unsplash)
Victims of the Kyber Network attack will be reimbursed (Mika Baumeister/Unsplash)

Kyber, a multi-chain decentralized finance (DeFi) platform, discovered a vulnerability to its website code that allowed exploiters to run away with approximately $265,000.

Two “whale” addresses appeared to be impacted by the attack, according to Kyber, which plans to reimburse the losses. Kyber said it discovered the exploit, which let attackers insert a “false approval, allowing a hacker to transfer a user’s funds to his address,” on Sept. 1 and “neutralized” the threat within two hours.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

The exploit hit KyberSwap, a decentralized exchange that allows users to swap between currencies on different blockchains. KyberSwap’s blockchain contracts were not affected. The problem stemmed from malicious Google Tag Manager code in the KyberSwap website, according to a statement from Kyber.

“We strongly urge all #DeFi projects to conduct a thorough check on your frontend code & associated Google Tag Manager (GTM) scripts as the attacker may have targeted multiple sites,” Kyber tweeted.

The attack on Kyber was relatively small in comparison with other recent attacks on DeFi projects, which have seen numerous multimillion-dollar thefts of users’ funds. However, it once again highlights the wide range of ways DeFi users are vulnerable to attacks.

Read more: DeFi Has Become Crypto Crime’s Main Arena, Crystal Blockchain Says

More For You

Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Title Image

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.

What to know:

Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.

The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.

More For You

Deus X CEO Tim Grant: We aren't replacing finance; we're integrating it

Deus X CEO Tim Grant (Deus X)

The Deus X CEO discussed his journey into digital assets, the company's infrastructure-led growth strategy, and why his Consensus Hong Kong panel promises "real talk only."

What to know:

  • Tim Grant entered crypto in 2015 after early exposure to Ripple and Coinbase, drawn by blockchain’s ability to improve traditional finance rather than replace it.
  • Deus X combines investing and operating to build regulated digital finance infrastructure across payments, prime services, and institutional DeFi.
  • Grant will be speaking at Consensus Hong Kong in February.