KiloEx Hack

Approximate loss $8.4M
Opbnb Base BNB Chain Taiko B2 Manta
Missing keeper authorization

What happened

On April 14, 2025 UTC, KiloEx was exploited through missing keeper authorization in its forwarding path. SlowMist later estimated the loss at $8.44 million and reported all stolen assets returned after a 10% bounty agreement.

Technical root cause

TrustedForwarder exposed the inherited execute method without the required authorization check. Downstream position execution trusted the forwarder without authenticating the initiating keeper.

How it happened

  1. The attacker deployed and executed attack contracts on opBNB, Base, BNB Smart Chain, Taiko, B2 and Manta.
  2. The inherited execute method forwarded requests to delegateExecutePositions(), which checked the forwarder but not the original caller's keeper authorization.
  3. The attacker opened a position at an artificially low price and closed it at a higher price within one transaction.
  4. SlowMist reported that the assets were returned to KiloEx Safe wallets after about 3.5 days.

Protocol details

Classification Protocol Logic / Exchange (DEX) / Oracle Manipulation
Protocol Type Derivatives
Implementation language Solidity
Protocol links Website @KiloEx_perp

Market Context at Time of Hack

Token Price at Hack $0.0488
Market Cap at Hack $10.3M
Reported loss / token market cap 81.56%
Token Categories
DeFi Derivatives DEX BNB Chain Ecosystem Binance Alpha Binance Wallet IDO Binance Ecosystem Perp dex coins

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.