Kujira Hack

TOTAL LOST $260K
Low Other

Summarize with AI

Affected Chain 2023 Incident surface
Recovered - No recovery reported
All-Time Rank #1196 By amount stolen
Protocol Type Exploit/Other Target category

Incident Overview

Kujira Network was exploited, resulting in more than 236,000 $USD worth of $USK being created.

Kujira Network is a layer-1 ecosystem. $USK is the stablecoin of the ecosystem. The attacker exploited a previously unknown vulnerability and minted $USK to buy their own $ETH back from themselves at an unusually expensive rate. This exploit caused $230,000 of bad debt to be accrued by this contract.

In the USK Margin contract instead of providing collateral and minting $USK, users provide $USK, and the contract is permitted to mint $USK and then swap the total amount for the collateral asset.

A bug in the USK Margin contract meant it considered $ETH to be worth significantly more than the market rate when opening a new position, allowing the exploiter to place limit orders for their own $ETH at a little less than 10,000 $USK each. They then opened large margin positions, which minted $USK, and bought their own $ETH back from themselves, at nearly 6x the market rate.

This $USK was then sold for $USDC and extracted from the network. The attacker sold a total of 58 $ETH, and the USK Margin contract has a total debt of 335,000 $USK, equating to roughly $236,000 $USD.

In order to guarantee that $USK is fully collateralized - the Kujira Team has placed a single limit order on the USDC-USK pair for 245,000 $USDC at a price of 1.01. This meant absorbing any excess supply from the market, offsetting the effects of the attack.

USK Margin contract:

https://finder.kujira.app/kaiyo-1/contract/kujira1m4ves3ymz5hyrj3war3t7uxu9ewt8rwpunja87960n0gre3a5pzspgry4g

Incident Report

Protocol / Project Kujira
Date of Incident
Attack Technique Other
Classification Stablecoin
Primary Source View Post-Mortem

Protocol Information

Protocol Type Exploit/Other
Affected Token USK
Official Website kujira.app
Protocol Twitter/X @TeamKujira
Team Anonymous
Source Code Unverified

Market Context at Time of Hack

Token Categories
Cosmos Ecosystem Ethereum Ecosystem Arbitrum Ecosystem Osmosis Ecosystem

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of other and Solidity and EVM internals
Capital Required Seed capital to cover gas and initial position setup
On-Chain Access Ability to interact with smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in Kujira's contract logic - root cause: stablecoin
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Likely — with a thorough Other audit checklist and test coverage

If you're auditing a protocol with similar architecture to Kujira, these are the critical security checks that could have prevented this incident (February 2023).

  • Verify all logic paths related to Other are guarded by proper access controls and input validation
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Sources & References

Learn to Prevent the Next Kujira

The Kujira hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial