CryptoReal
CASE FILE — Apr 17, 2025

Oracle Access Control Gap Lets Attacker Drain $7.5M From KiloEx Across Four Chains

KiloEx, a multi-chain perpetual futures platform backed by Binance, lost close to $7.5 million after an attacker exploited a permissions flaw in its price oracle system. The intruder funded the operation through Tornado Cash and struck across Base, BNB Chain, opBNB, Taiko, and Manta.

01How the alarm was raised

On April 14th, security researcher Chaofan Shou flagged the incident, estimating losses above $6 million and pointing to access-control problems in KiloEx's price oracle. Minutes afterward, Shou pinpointed the root cause: essentially anyone could alter KiloEx's oracle price. Roughly twenty minutes after Shou's initial post, Cyvers Alerts corroborated the scale of the breach, putting the figure near $7 million and noting the exploit was already spreading across several networks simultaneously — moving from BNB Chain to Base to Taiko in short order.

KiloEx later confirmed the incident publicly, pausing the platform and enlisting security firms to trace where the funds had gone.

02Mechanics of the exploit

According to a post-incident analysis from SlowMist, the underlying issue was a chain of four interlinked contracts — KiloPriceFeed, Keeper, PositionKeeper, and MinimalForwarder — each one trusting the contract that called it rather than verifying the caller independently. The weak link was MinimalForwarder, which accepted a forged signature without proper data validation, meaning it would forward calls from essentially anyone.

Using this gap, the attacker pushed the reported ETH price down to $100, opened highly leveraged long positions, then pushed the price back up to $10,000 before closing out — repeating the cycle to extract funds. Base chain took the heaviest hit in this pattern, losing $3.12 million alone. Commentators noted that the fault lay with KiloEx's own implementation rather than with the underlying Pyth Network oracle infrastructure it relied on.

03Tracing the stolen funds

Blockchain analysts traced the attacker's wallet back to a Tornado Cash transaction dated April 13th — a day before the exploit began — with funding transaction 0xa0fa4ab8ded0c07085d244e1981919b440f78b609e1cf8d7f8ee32d358dfdf46.

Sums referenced in this case file

The same address, 0x00fac92881556a90fdb19eae9f23640b95b4bcbd, was reused across chains to execute the attack:

A further Ethereum address, 0x551f3110f12c763D1611d5A63B5F015d1c1a954C, was used to bridge funds onward. In total, the exploit is estimated at approximately $7,491,500. SlowMist's MistTrack system flagged the addresses, though by then funds had already begun moving through cross-chain bridges including zkBridge, deBridge, and Meson. KiloEx asked partner protocols and platforms to blacklist the flagged address as it continued working with security partners.

04The response and its aftermath

KiloEx's initial response followed a familiar playbook: suspend trading, blacklist known addresses, and trace the flow of funds. A follow-up statement the next day confirmed the vulnerability had been identified and that a fix was forthcoming.

The team then published an on-chain message addressed to the attacker, offering to let them keep 10% of the roughly $7.5M as a "whitehat" bounty in exchange for returning the remaining 90%, citing an investigation "supported by law enforcement, cybersecurity agencies, and multiple exchanges & bridge protocols." As of the writing, the attacker had not responded, and the funds remained in the attacker's wallets.

KiloEx subsequently announced it had filed a police report in Hong Kong, saying it was working with a Cybercrime Unit as well as SlowMist. The team said it was freezing positions based on pre-hack snapshots and preparing a compensation plan. In the same statement, KiloEx also addressed — without prompting — rumors that the company itself might have been involved in the hack.

On the audit front, KiloEx's documentation lists five audits since June 2023. The most recent, conducted by ScaleBit in March 2025, did not catch the flaw that was exploited. ScaleBit responded to the incident by saying it was "deeply saddened" but that the root cause fell outside the scope of its audit.

05Takeaway

KiloEx had expanded its perpetuals protocol across four chains while a single unguarded contract — MinimalForwarder — sat at the center of the system's trust chain, ultimately exposing roughly $7.5 million in user funds. Despite five prior audits, the specific access-control weakness went unaddressed until after the exploit occurred.

DefiKiloExOracle Manipulation
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.