CointelegraphCointelegraph

KiloEx exchange exploiter returns all stolen funds after $7.5M hack

阅读1分钟

A hacker behind the $7.5 million KiloEx exploit returned all the stolen funds four days after the attack.

Decentralized exchange (DEX) KiloEx had suspended platform operations after suffering the $7.5 million exploit, Cointelegraph reported on April 15.

In a surprising turn of events, the wallet address behind the exploit has returned all of the stolen cryptocurrency loot to the DEX. 

“#KiloEx exploiter -labeled addresses have returned ~$5.5M worth of cryptos to #KiloEx,” according to an April 18 X post from blockchain security platform PeckShieldAlert.

Minutes after the transfer occurred, KiloEx announced the full recovery of all the stolen funds, the exchange wrote in an April 18 X post.

The unexpected repayment occurred after KiloEx offered the hacker a $750,000 “white hat” bounty — 10% of the stolen amount — if they returned 90% of the looted assets.

The platform said it was working with law enforcement and cybersecurity firms, including Seal-911, SlowMist and Sherlock, to uncover more about the hacker’s activity and identity.

The initial attack may have been caused due to a “price oracle issue,” where the information used by a smart contract to determine the price of an asset is manipulated or inaccurate, leading to the exploit, PeckShield said in an April 14 X post.

KiloEx won’t pursue legal charges after asset recovery

Following the recovery of the funds, the platform will not be pursuing any legal charges against the attacker, KiloEx said:

“The legal process to formally close the case is now underway [...]. With all affected funds fully restored (leaving no victims), we are fulfilling our pledge to resolve this matter fairly and transparently.”

“In adherence to our agreement, we will award 10% of the recovered amount as a bounty to the white hat involved, recognizing their contribution to improving our platform’s security,” KiloEx added.

White hat hackers, also known as ethical hackers, look for infrastructure vulnerabilities to avoid future exploits.

The necessity of improved crypto security measures was highlighted on Feb. 21, when Bybit exchange lost over $1.4 billion, marking the largest hack in crypto history.