CryptoReal
CASE FILE — Nov 23, 2023

Precision Rounding Flaw Lets Attacker Drain $48M From KyberSwap Elastic Across Six Chains

KyberSwap, one of the longer-standing decentralized exchanges in DeFi, has become the latest major hack victim, losing more than $48 million spread across six blockchains.

The exploit hit KyberSwap Elastic, the protocol's concentrated-liquidity product, whose total value locked collapsed from $71M to under $3M. The losses were distributed unevenly across chains: over $20M on Arbitrum, $15M on Optimism, $7.5M on Ethereum, $3M on Polygon, $2M on Base, and roughly $23,000 on Avalanche.

The theft adds to what has already been a brutal month for the industry — cumulative losses in November now exceed $300 million (so far), a running total that includes Poloniex ($126M), dYdX ($8M), Kronos Research ($26M), and the combined HECO Bridge/HTX incident ($99M).

Twitter user Spreek was first to flag the unusual activity, and KyberNetwork confirmed the breach within the hour, telling users:

As a precautionary measure, we strongly advise all users to promptly withdraw their funds. Our team is diligently investigating the situation, and we commit to keeping you informed with regular updates.

Because the attacker appeared to leave on-chain notes resembling a walkthrough of the method used, the community was also advised to withdraw liquidity from any KyberSwap forks, in case copycat attackers try to replicate the exploit elsewhere.

The wallet behind the attack has some questionable associations, yet the same address later signaled a willingness to negotiate — after, in its own words, getting some rest.

Theories about the attacker's identity and motive vary: a burned-out grey hat who, inspired by a previous near-miss involving a related but less sophisticated vulnerability, finally cashed in after more than six months of work; or, alternatively, someone simply bluffing about talks. (Tracking credit goes to 0xdoug and BlockSec.)

01Mechanics of the exploit

The attack began shortly before 11 PM UTC the night before, striking KyberSwap Elastic's concentrated-liquidity pools directly.

Per 0xdoug's breakdown of the exploit, the attacker used flash loans to shift asset prices into segments of each pool's liquidity curve that held no actual liquidity. A series of extremely precise swaps executed inside that empty range then triggered a precision/rounding error in Kyber's code.

That shows just how carefully engineered this exploit was. The check failed by <0.00000000001%

A fuller technical walkthrough from 0xdoug is available here.

Sums referenced in this case file

BlockSec's post-mortem attributed the root cause to "tick manipulation and double liquidity counting":

In summary, the attackers borrowed a flash loan and drained the pools with low liquidity. By executing swaps and altering positions, they manipulated the current prices and ticks of the victimized pools. Ultimately, the attacker triggered multiple swap steps and cross tick operations, resulting in double liquidity counting and consequently draining the pools.

Two addresses anchor the exploit, both active across Arbitrum, Optimism, Ethereum, Polygon, Base and Avalanche: 0x50275e0b7261559ce1644014d4b78d4aa63be836 carried out execution, while a second address — also present on Arbitrum, Optimism, Ethereum, Polygon, Base and Avalanche0xc9b826bad20872eb29f9b1d8af4befe8460b50c6, held the stolen assets across every affected chain.

An example transaction on Ethereum: 0x485e08dc…. BlockSec's MetaSleuth tool mapped the full attack sequence, while EigenPhi separately compiled a list of every transaction involved.

The attacker additionally funded a wallet on Scroll, though no attack was ever carried out there.

Following the money trail: initial capital originated from Tornado Cash on Ethereum, moved through an intermediary address, which then supplied the Arbitrum, Optimism, Base, and unused Scroll wallets. The Polygon and Avalanche wallets, by contrast, were funded through FixedFloat.

Notably, according to KyberSwap's own documentation, the current version of Elastic had already been audited by ChainSecurity and reviewed through a Sherlock audit contest.

02Commentary, clues, and a possible identity

Throughout the exploit, the attacker left a trail of commentary embedded directly in transaction event logs, including lines like "Step 2, finding liquidity required," "Is it enough?," and "Raping Now."

In a move that could be either misdirection or a deliberate signature, the attacker sent 1,000 ETH on Arbitrum to a wallet linked to the $16M Indexed Finance hack from October 2021.

That gesture plausibly fits the pattern of the Indexed Finance attacker, Andean Medjedovic, who has a documented history of drawing attention to himself. The timing is also suggestive: it follows a recent, thwarted governance attack on Indexed Finance's abandoned treasury, whose fallout is still unfolding and whose initial attempt has been tentatively linked to Lazarus.

Even so, despite Lazarus being blamed for a string of recent hacks, this particular incident doesn't fit the mold. Openly planted on-chain jokes and staged misdirection aren't typically how the group operates — Lazarus tends not to bother with red herrings, instead relying on sprawling webs of transactions designed to exhaust or mislead investigators through sheer complexity. Nor is negotiation something Lazarus is known to offer.

03An olive branch, or another taunt

Whoever is ultimately responsible, the attacker's own words suggest the situation may not be a total loss. Shortly after completing the exploit, the following message was posted on-chain from the attacker's address:

Dear Kyberswap Developers, Employees, DAO members and LPs,

Negotiations will start in a few hours when I am fully rested.

Thank you.

Whether that message points toward a resolution for KyberSwap and its liquidity providers, or is simply another taunt aimed at the community, remains to be seen.

KyberSwap
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.