Kipseli Hack

Reported loss $72K
Base
Output Token Validation

What happened

On April 22, 2026, Kipseli Router on Base was exploited for approximately $72,350 after an attacker swapped 0.04 WETH for about 0.926 cbBTC using an unsupported route.

Technical root cause

The router did not verify that the output token matched the quote token before using a USDC-only quoter's return value as the output-token transfer amount.

How it happened

The router used a USDC-denominated quote as the raw amount to transfer for a different output token. The unsupported WETH-to-cbBTC path therefore received a USDC-scaled value in cbBTC units.

Protocol details

Classification Input Validation
Protocol Type DEX
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.