KyberSwap Elastic Hack
What happened
KyberSwap Elastic was exploited across several EVM networks on November 22, 2023. A carefully sized, flash-loan-funded swap sequence triggered a rounding flaw in its concentrated-liquidity swap logic, letting the attacker corrupt tick and liquidity state before extracting assets.
In SwapMath, the incremental-liquidity calculation rounded in the wrong direction. That could make the computed next square-root price cross a tick boundary even though the swap branch concluded that no crossing occurred. The resulting mismatch between price, current tick, and base liquidity allowed a reverse swap to receive more assets than the pool should have released.
Case & protocol details
Attack Timeline
The attacker first moved a pool price outside active base liquidity, then added and partially removed liquidity to create a precise state. A swap amount just below the tick-crossing threshold made the pool calculate a final price beyond the boundary while treating the tick as un-crossed. Because the liquidity update did not run, the next reverse swap used inconsistent state and double-counted liquidity, producing an inflated token output.
Security review history
- ChainSecurity Report
Evidence & learning
Proof of concept
1 availableSources and on-chain records
- report Report twitter.com
- analysis Twitter/X Alert twitter.com
- analysis Website reference blocksec.com
- analysis Website reference app.blocksec.com
- analysis Website reference twitter.com
- analysis Website reference coindesk.com
- analysis KyberSwap Elastic Exploit Post Mortem and User Support with 100% Coverage via the Treasury Grant Program blog.kyberswap.com
- analysis Yet Another Tragedy of Precision Loss: An In-Depth Analysis of the KyberSwap Incident blocksec.com
- analysis A Deep Dive Into the KyberSwap Hack slowmist.medium.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.