T
iTokenly

Kame Aggregator hack — September 2025

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedSeptember 12, 2025
Target typeDecentralised exchange
Loss$1,000,000Published estimates range $1,000,000 to $1,300,000Price at time of incident
MethodAccess control flawThe AggregationRouter's swap() function executed an arbitrary call to a caller-supplied executor address with caller-supplied calldata, with no validation of either. The attacker set the executor to a malicious Multicall contract and used it to call transferFrom on tokens that users had approved to the router, so funds were pulled directly from user wallets that had granted unlimited allowances rather than from a protocol treasury.
ChainsOther
OutcomePartially recovered

What happened

Kame Aggregator, a decentralised exchange aggregator on the Sei network, was exploited in September 2025 through a flaw in its AggregationRouter. The router's swap() function executed an arbitrary call to an address and calldata supplied by the caller, with no validation performed on either. An attacker set the executor to a contract they controlled and had it call transferFrom on tokens that users had approved to the router. Funds were therefore taken out of individual wallets that had granted unlimited allowances to the vulnerable contract, not out of a protocol treasury. Verichains, which published the only detailed technical write-up, identified the attacker address, dated the incident 12 September 2025 and put the loss at approximately $1 million. Blockonomi also reported 'over $1 million' but dated the drain to 13 September. Halborn's monthly review put it at $1.3 million. No audited total was ever published, so this record carries $1 million as the headline with $1.3 million as the upper bound, and treats the date as approximate. Kame told users to revoke approvals to the affected contracts and to keep approvals disabled until security checks were finalised. It later confirmed that 185 ETH had been returned to a recovery wallet after the team negotiated directly with the attacker, saying "we have successfully communicated with hackers and they accepted our offer to transfer funds back". Kame said it was gathering information on all affected wallets and that a compensation plan would be shared once the investigation was complete. Blockonomi reported that most of the stolen assets remained unaccounted for. No individual or group has been named as responsible.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Attacker addresses

  • 0x14bb98581ac1f1a43fd148db7d7d793308dc4d80
  • 0x3A42B17f0D25de388BF0b08ffd860cdBDDdfB110

Sources

  1. VerichainsSecondary · retrieved 2026-08-01
  2. BlockonomiSecondary · retrieved 2026-08-01
  3. CryptopolitanSecondary · retrieved 2026-08-01
  4. HalbornSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Kame Aggregator hack — September 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/kame-aggregator
https://itokenly.com/hacks/kame-aggregator

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.