Cryptocurrency [loss] $2M+

Tweet by Spreekaway

2023-03-10 [vendor] Kyber bug [chain] ethereum
Primary Source ↗
Financial Loss $2.0M (1,970,000 USD)
Blockchain(s) Ethereum

Incident Details

Someone tried to swap around 2.03 million 3CRV tokens (priced at around $1.97 million) for stablecoins using the KyberSwap decentralized exchange protocol. However, due to an apparent flaw in which the protocol routed the trade through a project with very little liquidity. The trade suffered from massive slippage, and was frontrun by an MEV bot. The MEV bot made off with a nice $34,400, and the trader wound up with only five cents in the Tether stablecoin.Kyber seemed to acknowledge that the issue was on their end, tweeting that “We have been in touch with him and are investigating the issue. We will provide an update soon.”

Total loss estimated at $1,970,000.

Technical Details

Initial Attack Vector
MEV / sandwich attack
Vendor / Product
Kyber bug

Timeline

  1. 2023-03-10 Breach occurred
  2. 2023-03-10 Publicly disclosed