T
iTokenly

KiloEx hack — April 2025

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeDecentralised exchange
Loss$7,500,000Published estimates range $7,000,000 to $7,500,000Price at time of incident
Recovered$6,750,000
MethodAccess control flawKiloEx's TrustedForwarder contract inherited OpenZeppelin's MinimalForwarderUpgradeable but did not override the execute method, leaving it permissionless. Calling execute let the attacker reach delegateExecutePositions, which checked only that the caller was the trusted forwarder and not that an authorised keeper had supplied the price, so positions could be opened at an arbitrary low price and closed at an arbitrary high price inside a single transaction across six chains.
ChainsBase, BNB Chain, Other
OutcomeFunds returned

What happened

KiloEx, a multi-chain perpetual futures exchange, was drained on 14 April 2025. Its own post-mortem places the attack transactions between 18:52:27 and 19:40:49 UTC, with preparation on 13 and 14 April, and names the attacker address, funded from Tornado Cash. Early reporting described the incident as price-oracle manipulation and many accounts still label it that way, but KiloEx's post-mortem identifies an access-control failure. Its TrustedForwarder contract inherited OpenZeppelin's MinimalForwarderUpgradeable and failed to override the execute method, leaving it callable by anyone. Through that opening the attacker reached delegateExecutePositions, which verified only that the call came from the trusted forwarder, not that an authorised keeper had supplied the price. That allowed positions to be opened at an arbitrarily low price and closed at an arbitrarily high one within a single transaction. The pattern was repeated on opBNB, Base, BSC, Taiko, B2 and Manta. Figures differ. KiloEx confirmed a $7.5 million loss and suspended the platform; CoinDesk reported the total as about $7 million and described one transaction in which the attacker netted $3.12 million. KiloEx offered a 10 percent white-hat bounty, about $750,000, for return of the remainder and said it would withdraw legal action against the attacker. The attacker accepted. By 18 April KiloEx said it had recovered all of the hacked funds, with the attacker keeping the bounty, and it published a plan compensating traders whose positions were affected during the suspension and paying stakers an additional 10 percent APY.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Attacker addresses

  • 0x00faC92881556A90FdB19eAe9F23640B95B4bcBd

Sources

  1. KiloExPrimary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. CoinDeskSecondary · retrieved 2026-08-01
  4. CointelegraphSecondary · retrieved 2026-08-01

Official post-mortem: https://medium.com/@KiloEx/kiloex-security-incident-root-cause-analysis-post-mortem-3d899caac08c

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "KiloEx hack — April 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/kiloex
https://itokenly.com/hacks/kiloex

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.