KiloEx Hack
What happened
On April 14, 2025 UTC, KiloEx was exploited through missing keeper authorization in its forwarding path. SlowMist later estimated the loss at $8.44 million and reported all stolen assets returned after a 10% bounty agreement.
TrustedForwarder exposed the inherited execute method without the required authorization check. Downstream position execution trusted the forwarder without authenticating the initiating keeper.
How it happened
- The attacker deployed and executed attack contracts on opBNB, Base, BNB Smart Chain, Taiko, B2 and Manta.
- The inherited
executemethod forwarded requests todelegateExecutePositions(), which checked the forwarder but not the original caller's keeper authorization. - The attacker opened a position at an artificially low price and closed it at a higher price within one transaction.
- SlowMist reported that the assets were returned to KiloEx Safe wallets after about 3.5 days.
Protocol details
Security review history
- SlowMist View report
Evidence
- report @shoucccc incident report x.com
- report @SlowMist_Team incident report x.com
- report @BeosinAlert incident report x.com
- report @KiloEx_perp incident report x.com
- analysis DeFiLlama defillama.com
- analysis SlowMist Assists KiloEx in Recovering All Stolen Funds — Incident Recap slowmist.medium.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.