A decentralized exchange targeted in a multi-million-dollar exploit has recovered its losses just days after the incident, thanks to an unexpected twist involving the hacker themselves.
KiloEx, a decentralized trading platform, confirmed on April 18 that it had received back the full $7.5 million drained in a recent attack. The surprise return of funds came four days after the breach, which had forced the platform to suspend operations temporarily.
The attacker’s sudden change of heart appears to have been triggered by KiloEx’s public offer of a 10% white-hat bounty—roughly $750,000—on the condition that 90% of the stolen assets were returned. Within days, wallets linked to the breach began transferring millions back to KiloEx, as confirmed by blockchain security firm PeckShield.
The platform had been working with cybersecurity partners including Sherlock, SlowMist, and Seal-911, as well as law enforcement, in efforts to track down the source of the attack. Early investigations pointed to a manipulated price oracle—a known vulnerability in decentralized finance—which may have enabled the exploit.
Despite the initial alarm, the swift resolution has allowed KiloEx to reassure users that no funds were lost. The platform has now begun closing the case, stating that it will not pursue legal action and will honor its bounty commitment.
KiloEx described the incident as a wake-up call and said it would continue enhancing its smart contract infrastructure. “With no victims and full restitution, we consider this matter settled. We’ll reward the white hat and keep working to make our platform more secure.”
A new breed of cyber-attack is sweeping through crypto media, exploiting site pop-ups and wallet-connect prompts instead of smart-contract bugs.
CoinMarketCap, one of the most widely used crypto data tracking platforms, is reportedly facing a front-end security breach, with multiple users encountering a suspicious prompt to verify their wallets.
Russia’s attempt to formalize its crypto mining sector is falling short, with most miners opting to remain off the books despite new regulations.
A well-known investor at crypto VC firm Hypersphere has fallen victim to an elaborate phishing attack that wiped out a substantial portion of his personal savings.