Share this article

DeFi Platform Kyber Network Discloses $265K Exploit, Vows to Reimburse All Funds

This most recent attack on a decentralized finance platform resulted from malicious website code.

Updated May 11, 2023, 6:16 p.m. Published Sep 1, 2022, 8:17 p.m.
Victims of the Kyber Network attack will be reimbursed (Mika Baumeister/Unsplash)
Victims of the Kyber Network attack will be reimbursed (Mika Baumeister/Unsplash)

Kyber, a multi-chain decentralized finance (DeFi) platform, discovered a vulnerability to its website code that allowed exploiters to run away with approximately $265,000.

Two “whale” addresses appeared to be impacted by the attack, according to Kyber, which plans to reimburse the losses. Kyber said it discovered the exploit, which let attackers insert a “false approval, allowing a hacker to transfer a user’s funds to his address,” on Sept. 1 and “neutralized” the threat within two hours.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

The exploit hit KyberSwap, a decentralized exchange that allows users to swap between currencies on different blockchains. KyberSwap’s blockchain contracts were not affected. The problem stemmed from malicious Google Tag Manager code in the KyberSwap website, according to a statement from Kyber.

“We strongly urge all #DeFi projects to conduct a thorough check on your frontend code & associated Google Tag Manager (GTM) scripts as the attacker may have targeted multiple sites,” Kyber tweeted.

The attack on Kyber was relatively small in comparison with other recent attacks on DeFi projects, which have seen numerous multimillion-dollar thefts of users’ funds. However, it once again highlights the wide range of ways DeFi users are vulnerable to attacks.

Read more: DeFi Has Become Crypto Crime’s Main Arena, Crystal Blockchain Says

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

ZKsync Lite to Shut Down in 2026 as Matter Labs Moves On

Sunset in San Salvador. Credit: Ricky Mejia, Unsplash

The company framed the move, happening in early 2026, as a planned sunset.

What to know:

  • Matter Labs plans to deprecate ZKsync Lite, the first iteration of its Ethereum layer-2 network, the team said in a post on X over the weekend.
  • The company framed the move, happening in early 2026, as a planned sunset for an early proof-of-concept that helped validate their zero-knowledge rollup design choices before newer systems went live.