KyberSwap Elastic Hack

TOTAL LOST $48.7M
High Arithmetic Overflow & Underflow Attacks Arbitrum Base Ethereum Optimism Polygon

What happened

KyberSwap Elastic was exploited across several EVM networks on November 22, 2023. A carefully sized, flash-loan-funded swap sequence triggered a rounding flaw in its concentrated-liquidity swap logic, letting the attacker corrupt tick and liquidity state before extracting assets.

Technical Root Cause

In SwapMath, the incremental-liquidity calculation rounded in the wrong direction. That could make the computed next square-root price cross a tick boundary even though the swap branch concluded that no crossing occurred. The resulting mismatch between price, current tick, and base liquidity allowed a reverse swap to receive more assets than the pool should have released.

Case & protocol details

Classification Protocol Logic / Exchange (DEX) / Arithmetic & Precision
Protocol Type DEX
Smart Contract Language Solidity
Official Website kyberswap.com/
Protocol Twitter/X @KyberNetwork

Attack Timeline

The attacker first moved a pool price outside active base liquidity, then added and partially removed liquidity to create a precise state. A swap amount just below the tick-crossing threshold made the pool calculate a final price beyond the boundary while treating the tick as un-crossed. Because the liquidity update did not run, the next reverse swap used inconsistent state and double-counted liquidity, producing an inflated token output.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.