And hacking again! This time, the KiloEX crypto exchange suffered.

By Evtuoil | Cryptographic News | 16 Apr 2025


The exchange was hacked on the evening of April 14th! The attacker withdrew $7 million in cryptocurrencies from the decentralized platform using the "oracle attack".

KiloEx, a decentralized perpetual futures exchange, offered the hacker who hacked it $700,000 to return some of the stolen funds. The hacker manipulated the prices of tokens, which allowed him to withdraw $7 million worth of cryptocurrency from the site.

dffe48d41d1e63478aab50074d53f12a400504c565a96ec76f46928681bedb81.jpg

Covers was the first company to report the hack. According to them, the attacker was able to withdraw cryptocurrencies from several blockchains: Base, BNB Chain and Taiko. The KiloEx team later confirmed the hack, suspended the platform, and stated that the "vulnerability has been localized" and an investigation has begun.

During the hack, the hacker took advantage of a vulnerability in the management of the price oracle. Oracles collect quote data from various networks and transmit it to centralized applications such as KiloEx to determine asset prices during trading.

In this case, the attacker took advantage of a loophole in the KiloEx pricing system and forced the platform to accept false quotes. He then conducted several transactions with leverage, according to The Block. The data showed that the profit from one such transaction on KiloEx during the incident amounted to more than $3 million.

On April 15, the KiloEx team approached the hacker with an offer to return 90% of the stolen funds. The platform offered to leave the remaining 10% (about $700 thousand) to the hacker as a "bounty".

"We will post this decision on Twitter, acknowledging your cooperation and closing the case without further action. If you agree, please contact us," the exchange team wrote.

If the attacker ignores KiloEx's offer, the exchange promised to investigate the incident together with law enforcement officers and go to court.:

"If you don't comply with the requirements: We will transfer the investigation materials to law enforcement agencies and cybersecurity partners. Your identity and actions will be disclosed to the relevant authorities. We will tirelessly pursue legal proceedings. The choice is yours. Act right now to avoid irreversible consequences," KiloEx threatened.

The scheme called "oracle attack" has already been used before. In 2022, Abraham Eisenberg stole about $110 million from Mango Markets using what he called a "high-yield trading strategy" that alters futures market prices. A little later, he was arrested in Puerto Rico and extradited to the United States, where he was convicted of fraud in 2024.

 

Be careful and please take care of yourself!

How do you rate this article?

23


Evtuoil
Evtuoil

Writer, poet, philosopher. I love our WORLD and nature. I'm interested in cryptocurrency.


Cryptographic News
Cryptographic News

All about the crypto market

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.