KlaySwap Hack
What happened
On February 3, 2022, users of KLAYswap, a DEX on Klaytn built by Ozys, lost about $1.9 million (roughly 2.2 billion KRW) after attackers used a BGP hijack to serve a malicious copy of the Kakao JavaScript SDK that the KLAYswap site loaded from developers.kakao.com. KLAYswap stated that neither its own front-end code nor its smart contracts were at fault.
From 11:31 KST, swaps, deposits and withdrawals made through the tampered page approved or sent users' tokens to an attacker-controlled contract. KLAYswap counted 407 abnormal transactions across 325 wallets, and security firm S2W traced the last one to 18:01 KST. The attacker swapped the loot into bridged tokens and moved it out through Orbit Bridge to the FixedFloat exchange; Orbit restricted its Klaytn minter and rejected part of the swaps, so S2W estimates only about $0.9 million was actually cashed out. KLAYswap paused the service, removed the Kakao SDK, built a page for revoking malicious approvals and announced a compensation plan.
How it happened
- The attacker deployed a theft "factory" contract
0x3f315f2bfa8452febbc08a9e3a7fdf8872f9527con January 7, 2022 from account0x648cafad991e88bfe6beb626dbeda15bd349073c, after months of test transactions. - From 10:04 KST on February 3, routes for more-specific prefixes covering the two IPs of
developers.kakao.com(for example211.249.221.0/24and121.53.104.0/24) were announced from AS9457, pulling that traffic to the attacker's server. - With traffic diverted, the attacker passed ZeroSSL's HTTP domain validation and obtained a valid TLS certificate for
developers.kakao.comat about 11:28 KST. - Requests for
kakao.min.jscarrying a KLAYswap referer reportedly received a modified bundle built from an old KLAYswap front end. It rewrote transaction requests so that user actions approved tokens to the theft contract or transferred them directly. - The theft contract then pulled approved tokens into
0xdfcb0861d3cb75bb09975dce98c4e152823c1a0b(first victim transfer in block 82005544). The attacker swapped the proceeds to KETH, KUSDT, KXRP and other bridged tokens and sent them through Orbit Bridge to FixedFloat.
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.