Kokomo Finance hack — March 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | March 27, 2023 |
| Target type | Lending protocol |
| Loss | $4,000,000Published estimates range $4,000,000 to $5,500,000Price at time of incident |
| Method | Rug pull or exit scamProject deployer swapped the upgradeable cBTC market implementation for a malicious contract it had deployed shortly before, altered reward parameters via _setRewardSpeed and paused borrowing, then used the new implementation to call method 0x804edaad and move 7,010 Sonne Wrapped Bitcoin from an address that had approved the cBTC contract to an operator-controlled address, which redeemed them for about 141.7 WBTC; a separate one-time owner privilege on the KOKO token to mint 45% of maximum supply to an arbitrary address accounted for a smaller part of the take. |
| Chains | Optimism |
| Audited beforehand | 0xGuard |
| Attributed to | Kokomo Finance deployer / project operatorsSuspected |
| Outcome | Project shut down |
What happened
Kokomo Finance was a Compound-style lending protocol that launched on Optimism on 25 March 2023 and gathered roughly $2 million in total value locked within two days. On 26 March 2023 the project's deployer address replaced the implementation behind the protocol's wrapped-bitcoin market (cBTC) with a contract it had deployed shortly before, changed reward parameters through _setRewardSpeed and paused borrowing. The malicious implementation then allowed a call to method 0x804edaad that moved 7,010 Sonne Wrapped Bitcoin — held by an address that had approved the cBTC contract to spend them — to an address the operators controlled, where they were redeemed for about 141.7 WBTC. The KOKO token fell about 95% within minutes, and the website, Twitter, GitHub and Medium accounts were deleted the same day.
Published figures differ. Cointelegraph, QuillAudits and Beosin each put the 26 March take at about $4 million, consistent with the on-chain redemption of roughly 141.7 WBTC at that day's price. CertiK, which first traced the transactions, described the loss as about $4.5 million in user funds. Beosin later said the same operators took a further $1.5 million on 31 March by modifying the deployment contract, which would bring the total to about $5.5 million.
No charges, indictment or admission has been reported, so the identification of the deployer as the culprit rests on the analyses published by CertiK, QuillAudits and Beosin rather than on any legal finding. The contracts had been reviewed days before launch by the auditor 0xGuard, whose report noted that the owner of the KOKO token had a one-time ability to mint 45% of the maximum supply to an arbitrary address. Cointelegraph reported that the exploiters used this method as well, but that the vast majority of the loss came from the cBTC implementation swap. The protocol never resumed operation.
Sources
- CertiKSecondary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
- QuillAuditsSecondary · retrieved 2026-08-01
- ChainCatcher (reporting Beosin Alert)Secondary · retrieved 2026-08-01
- CoinGeekSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Kokomo Finance hack — March 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/kokomo-financehttps://itokenly.com/hacks/kokomo-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.