T
iTokenly

Kokomo Finance hack — March 2023

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMarch 27, 2023
Target typeLending protocol
Loss$4,000,000Published estimates range $4,000,000 to $5,500,000Price at time of incident
MethodRug pull or exit scamProject deployer swapped the upgradeable cBTC market implementation for a malicious contract it had deployed shortly before, altered reward parameters via _setRewardSpeed and paused borrowing, then used the new implementation to call method 0x804edaad and move 7,010 Sonne Wrapped Bitcoin from an address that had approved the cBTC contract to an operator-controlled address, which redeemed them for about 141.7 WBTC; a separate one-time owner privilege on the KOKO token to mint 45% of maximum supply to an arbitrary address accounted for a smaller part of the take.
ChainsOptimism
Audited beforehand0xGuard
Attributed toKokomo Finance deployer / project operatorsSuspected
OutcomeProject shut down

What happened

Kokomo Finance was a Compound-style lending protocol that launched on Optimism on 25 March 2023 and gathered roughly $2 million in total value locked within two days. On 26 March 2023 the project's deployer address replaced the implementation behind the protocol's wrapped-bitcoin market (cBTC) with a contract it had deployed shortly before, changed reward parameters through _setRewardSpeed and paused borrowing. The malicious implementation then allowed a call to method 0x804edaad that moved 7,010 Sonne Wrapped Bitcoin — held by an address that had approved the cBTC contract to spend them — to an address the operators controlled, where they were redeemed for about 141.7 WBTC. The KOKO token fell about 95% within minutes, and the website, Twitter, GitHub and Medium accounts were deleted the same day.

Published figures differ. Cointelegraph, QuillAudits and Beosin each put the 26 March take at about $4 million, consistent with the on-chain redemption of roughly 141.7 WBTC at that day's price. CertiK, which first traced the transactions, described the loss as about $4.5 million in user funds. Beosin later said the same operators took a further $1.5 million on 31 March by modifying the deployment contract, which would bring the total to about $5.5 million.

No charges, indictment or admission has been reported, so the identification of the deployer as the culprit rests on the analyses published by CertiK, QuillAudits and Beosin rather than on any legal finding. The contracts had been reviewed days before launch by the auditor 0xGuard, whose report noted that the owner of the KOKO token had a one-time ability to mint 45% of the maximum supply to an arbitrary address. Cointelegraph reported that the exploiters used this method as well, but that the vast majority of the loss came from the cBTC implementation swap. The protocol never resumed operation.

Sources

  1. CertiKSecondary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. QuillAuditsSecondary · retrieved 2026-08-01
  4. ChainCatcher (reporting Beosin Alert)Secondary · retrieved 2026-08-01
  5. CoinGeekSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Kokomo Finance hack — March 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/kokomo-finance
https://itokenly.com/hacks/kokomo-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.