KICKICO Hack
What happened
In July 2018 an attacker got hold of the private key KICKICO used to administer the KickCoin (KICK) token contract on Ethereum, and stole over 70 million KICK, valued at about $7.7 million at the time. With owner rights, the attacker did not need to transfer tokens out of victims' wallets. Instead it burned KICK from holders' addresses and minted matching amounts to addresses it controlled. KICKICO said total supply stayed the same, so its monitoring for sudden supply changes was not triggered. KICKICO learned of the theft when victims complained, including one who said about $800,000 of KICK had disappeared.
KICKICO put the hack at 26 July 2018, 09:04 UTC, and spoke of about 40 affected addresses. An independent on-chain analysis found the burn-and-mint transactions ran from about 20:43 to 22:19 UTC on 25 July. It found the attacker handed contract ownership back to the Bancor converter afterwards to cover its tracks. Its final tally was 24 destroy() calls removing 62,229,697.14 KICK from victims and 26 issue() calls minting 68,278,606.99 KICK to the attacker, so supply actually grew by about 6.05 million KICK. KICKICO regained control by replacing the compromised key with a cold-storage key, then used the same owner functions to burn the attacker-minted tokens. It promised to return all tokens, and the analysis traces refunds to victims in August and September 2018.
How it happened
- The attacker obtained the private key of the account that controlled the KickCoin token contract (
0x5031...6451in the on-chain analysis). - Using that key, it called the owner-only
destroy()function to burn KICK from a victim's address, thenissue()to mint a matching amount to an address it controlled, repeating this for each victim. - KICKICO said the burns and mints offset each other, so its supply-based monitoring did not flag the theft. An on-chain tally later found 68,278,606.99 KICK issued against 62,229,697.14 KICK destroyed, so supply did not stay exactly flat. The attacker then returned contract ownership to the Bancor converter.
- After victims reported missing tokens, KICKICO swapped the compromised key for a cold-storage key, burned the attacker-minted KICK and began refunding holders.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.