Data leak [loss] $2M+

"KlaySwap crypto users lose funds after BGP hijack"

2022-02-03 [vendor] KLAYswap
Primary Source ↗
Financial Loss $1.9M (1,900,000 USD)

Incident Details

Some sophisticated hackers managed a BGP hijack on the servers powering KakaoTalk, a marketing and customer service application used by the South Korean KLAYswap cryptocurrency exchange. The hijacking enabled the hackers to serve malicious JavaScript that allowed hackers to intercept funds as a user initiated a transaction. Over a two-hour period, the hackers stole cryptocurrency totaling ₩2.2 million (about $1.9 million) from 325 customer wallets. The exchange acknowledged the hack the same day, and promised to compensate affected users.

Total loss estimated at $1,900,000.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
KLAYswap

Timeline

  1. 2022-02-03 Breach occurred
  2. 2022-02-03 Publicly disclosed