KiloEx hack — April 2025
Incident facts
| Date of incident | |
|---|---|
| Target type | Decentralised exchange |
| Loss | $7,500,000Published estimates range $7,000,000 to $7,500,000Price at time of incident |
| Recovered | $6,750,000 |
| Method | Access control flawKiloEx's TrustedForwarder contract inherited OpenZeppelin's MinimalForwarderUpgradeable but did not override the execute method, leaving it permissionless. Calling execute let the attacker reach delegateExecutePositions, which checked only that the caller was the trusted forwarder and not that an authorised keeper had supplied the price, so positions could be opened at an arbitrary low price and closed at an arbitrary high price inside a single transaction across six chains. |
| Chains | Base, BNB Chain, Other |
| Outcome | Funds returned |
What happened
KiloEx, a multi-chain perpetual futures exchange, was drained on 14 April 2025. Its own post-mortem places the attack transactions between 18:52:27 and 19:40:49 UTC, with preparation on 13 and 14 April, and names the attacker address, funded from Tornado Cash. Early reporting described the incident as price-oracle manipulation and many accounts still label it that way, but KiloEx's post-mortem identifies an access-control failure. Its TrustedForwarder contract inherited OpenZeppelin's MinimalForwarderUpgradeable and failed to override the execute method, leaving it callable by anyone. Through that opening the attacker reached delegateExecutePositions, which verified only that the call came from the trusted forwarder, not that an authorised keeper had supplied the price. That allowed positions to be opened at an arbitrarily low price and closed at an arbitrarily high one within a single transaction. The pattern was repeated on opBNB, Base, BSC, Taiko, B2 and Manta. Figures differ. KiloEx confirmed a $7.5 million loss and suspended the platform; CoinDesk reported the total as about $7 million and described one transaction in which the attacker netted $3.12 million. KiloEx offered a 10 percent white-hat bounty, about $750,000, for return of the remainder and said it would withdraw legal action against the attacker. The attacker accepted. By 18 April KiloEx said it had recovered all of the hacked funds, with the attacker keeping the bounty, and it published a plan compensating traders whose positions were affected during the suspension and paying stakers an additional 10 percent APY.
On-chain references
Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.
Attacker addresses
- 0x00faC92881556A90FdB19eAe9F23640B95B4bcBd
Sources
- KiloExPrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/@KiloEx/kiloex-security-incident-root-cause-analysis-post-mortem-3d899caac08c
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "KiloEx hack — April 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/kiloexhttps://itokenly.com/hacks/kiloexPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.