T
iTokenly

Kinto hack — July 2025

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJuly 10, 2025
Target typeToken contract
Loss$1,550,000Price at time of incident
MethodAccess control flawCPIMP ('Clandestine Proxy In the Middle of Proxy'). Kinto's $K ERC1967 token proxy on Arbitrum had been deployed without being initialised in the same transaction, letting an attacker front-run initialisation and write a malicious implementation into a storage slot. That implementation forwarded most calls to the legitimate logic, restored itself after each transaction and spoofed the slots block explorers read, staying dormant until activated to mint unlimited $K.
ChainsArbitrum
Attributed toLazarus GroupSuspected
OutcomeProject shut down

What happened

Kinto was an Ethereum layer-2 project whose $K token also traded as an ERC-20 on Arbitrum. That token's proxy was one of hundreds compromised by what researchers named the CPIMP attack, short for Clandestine Proxy In the Middle of Proxy. Where a proxy is deployed but not initialised in the same transaction, an attacker can front-run the initialisation and write its own implementation into a storage slot, then have that implementation forward most calls to the legitimate logic while restoring itself after each transaction and spoofing the slots block explorers read. The backdoor stays dormant and invisible until it is used.

David Benchimol of Venn found the vulnerability on 8 July 2025 and alerted Dedaub; a war room with SEAL 911 and the researcher pcaversaccio mitigated most exposed contracts and, by Dedaub's account, protected tens of millions of dollars. Kinto's contract was not among those saved. Public disclosure went out on 9 July 2025, and the attacker activated the Kinto backdoor the following day, minting about 110,000 counterfeit $K and selling them, draining a Uniswap v4 pool and a Morpho Blue vault of 577 ETH, worth about $1.55 million at the time. The Block's headline rounded this to $1.6 million. The $K price fell roughly 90 to 95 percent.

Kinto stated that its layer-2 network, wallets and contracts were not themselves breached. Co-founder Ramon Recuero said all signs pointed to Lazarus; no supporting evidence was published and no government body has attributed the incident. Morpho depositors were left holding bad debt. Kinto failed to raise afterwards, announced its shutdown in September 2025, repaid Phoenix lenders about 76 percent of principal and Recuero committed personal funds toward partially reimbursing Morpho depositors.

Sources

  1. Kinto (Ramon Recuero)Primary · retrieved 2026-08-01
  2. The DefiantSecondary · retrieved 2026-08-01
  3. The BlockSecondary · retrieved 2026-08-01
  4. DedaubSecondary · retrieved 2026-08-01
  5. NethermindSecondary · retrieved 2026-08-01

Official post-mortem: https://medium.com/mamori-finance/%EF%B8%8F-post-mortem-k-proxy-hack-our-path-forward-c2c3809882c6

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Kinto hack — July 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/kinto
https://itokenly.com/hacks/kinto

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.