KyberSwap’s $46 Million Hack: The Most Complex Smart Contract Exploit
Ambient Exchange founder Doug Colkitt described KyberSwap’s recent hack as the most complex and carefully engineered smart contract exploit he has ever seen. Colkitt outlined the intricacies of the attack in a detailed Twitter thread, shedding light on the methods used by the attacker.
The Exploitation of KyberSwap’s Concentrated Liquidity
Colkitt explained how the attacker manipulated KyberSwap’s concentrated liquidity feature to deceive the contract into believing it had more liquidity than it actually did. By exploiting this flaw, the attacker created an opportunity to drain the pool successfully.
The attacker executed two swaps, manipulating the liquidity environment to sell wstETH for ETH at a low price and then buy wstETH from the pool at a higher price. This resulted in the attacker receiving more money than initially paid, leading to an infinite money glitch.
Unraveling the Attack: Anomalies and Manipulation
Colkitt further investigated the attack and discovered anomalies related to KyberSwap’s handling of liquidity at tick boundaries. The attacker skillfully manipulated calculations and prevented certain functions from being invoked during specific swaps, tricking the pool into double-counting liquidity.
Other Dexes Not at Risk
Colkitt clarified that this exploit is specific to KyberSwap’s implementation of concentrated liquidity and does not pose a risk to other reputable decentralized exchanges like Ambient or Uniswap. However, KyberSwap forks may be vulnerable to similar attacks.
Hot Take: KyberSwap Exploited in $46 Million Attack Due to ‘Infinite Money Glitch’
KyberSwap fell victim to a highly sophisticated smart contract exploit that allowed the attacker to drain $46 million from the platform. By manipulating KyberSwap’s concentrated liquidity feature, the attacker deceived the contract and generated an infinite money glitch. The exploit involved carefully executed swaps and manipulation of liquidity calculations. While other decentralized exchanges implementing concentrated liquidity are not at risk, KyberSwap and its forks may be vulnerable to similar attacks. This incident highlights the importance of robust security measures in the crypto industry.