{"id":87478,"date":"2023-11-24T14:42:07","date_gmt":"2023-11-24T12:42:07","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=87478"},"modified":"2025-09-13T12:04:22","modified_gmt":"2025-09-13T09:04:22","slug":"kyberswap-offers-hacker-a-90-payout-to-return-most-of-the-funds","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/kyberswap-offers-hacker-a-90-payout-to-return-most-of-the-funds\/","title":{"rendered":"KyberSwap offers hacker a 90% payout to return most of the funds"},"content":{"rendered":"<p>The KyberSwap <a href=\"https:\/\/forklog.com\/en\/news\/what-is-a-dao-decentralised-autonomous-organisation\">decentralized autonomous organization<\/a> (DAO) that runs the DEX KyberSwap reached out to the hacker with an offer to return most of the funds in exchange for a reward.<\/p>\n<figure class=\\\"wp-block-image size-full\\\"><img decoding=\\\"async\\\" src=\\\"https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2023-11-24-v-12.45.51.webp\\\" alt=\\\"Snimok-ekrana-2023-11-24-v-12.45.51\\\" class=\\\"wp-image-220805\\\"\/><figcaption class=\\\"wp-element-caption\\\">Data: <a href=\\\"https:\/\/etherscan.io\/idm?addresses=0x8180a5ca4e3b94045e05a9313777955f7518d757,0x50275e0b7261559ce1644014d4b78d4aa63be836&#038;type=1\\\">Etherscan<\/a>.<\/figcaption><\/figure>\n<blockquote class=\\\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\\\">\n<p>&#8220;You have carried out one of the most sophisticated hacks. [&#8230;] A reward on the table equivalent to 10% of the users&#8217; funds withdrawn by you,&#8221; the message said.<\/p>\n<\/blockquote>\n<p>The DAO&#8217;s representatives set a deadline for the attacker \u2014 90% of the assets must be returned by 06:00 UTC on 25 November.<\/p>\n<p>The breach of the Elastic Pools liquidity pool, in which the hacker withdrew about $47 million from the protocol, <a href=\"https:\/\/forklog.com\/en\/news\/hacker-drains-kyberswap-elastic-pools-of-about-47-million\">became known<\/a> on November 23. He left a message in the transaction indicating his intent to begin negotiations &#8220;in a few hours&#8221;.<\/p>\n<p>According to Ambient founder Doug Colkitt, the attacker used &#8220;a complex and carefully crafted smart-contract exploit.&#8221;<\/p>\n<blockquote class=\\\"twitter-tweet\\\">\n<p lang=\\\"en\\\" dir=\\\"ltr\\\">2\/ First thing to note is this exploit is specific to Kyber&#8217;s implementation of concentrated liquidity<\/p>\n<p>There&#8217;s no reason to believe that other reputable concentrated liquidity dexes, like Ambient or Uniswap, are at risk from this exploit. (Though Kyber forks obviously are)<\/p>\n<p>\u2014 Doug Colkitt (@0xdoug) <a href=\\\"https:\/\/twitter.com\/0xdoug\/status\/1727613542252024187?ref_src=twsrc%5Etfw\\\">November 23, 2023<\/a><\/p><\/blockquote>\n<p> <script async src=\\\"https:\/\/platform.twitter.com\/widgets.js\\\" charset=\\\"utf-8\\\"><\/script><\/p>\n<p>Besoin experts <a href=\"https:\/\/forklog.com\/en\/news\/hacker-siphons-off-25-million-from-kronos-research-platform\">estimated<\/a> the exchange&#8217;s losses at about $48 million in various assets, &#8220;primarily including 16,217 ETH, 3,987,332 ARB, 591,441 OP and 1,111,926 DAI&#8221;.<\/p>\n<p><a href=\"https:\/\/forklog.com\/en\/news\/analysts-estimate-losses-from-htx-and-heco-bridge-hack-at-110-million\">On 22 November Justin Sun <\/a> reported a hacker attack on HTX&#8217;s hot wallet and <a href=\"https:\/\/forklog.com\/en\/news\/what-are-cross-chain-bridges\">cross-chain bridge<\/a> Heco Bridge. Experts estimate the damage at over $110 million.<\/p>\n<p><a href=\"https:\/\/forklog.com\/en\/news\/poloniex-hack-losses-top-100-million\">Previously, Poloniex was hacked<\/a>. Then Sun announced &#8220;successful identification and freezing of part of the assets linked to the hacker&#8217;s addresses&#8221;. He gave the latter a week to return the stolen funds for a reward of 5% of the amount, which amounted to about $6.25 million.<\/p>\n<p>A few days later, Tron founder <a href=\"https:\/\/forklog.com\/en\/news\/justin-sun-raises-bounty-for-poloniex-hacker-to-10-million\">increased the reward<\/a> for the hacker to $10 million.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The KyberSwap DAO asked the hacker to return most of the funds in exchange for a reward.<\/p>\n","protected":false},"author":1,"featured_media":87479,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[44,1416],"class_list":["post-87478","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybercrime","tag-kyber-network"],"aioseo_notices":[],"amp_enabled":true,"views":"20","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/87478","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=87478"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/87478\/revisions"}],"predecessor-version":[{"id":87480,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/87478\/revisions\/87480"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/87479"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=87478"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=87478"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=87478"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}