KyberSwap Elastic Hack
Incident Overview
KyberSwap DEX suffers a $45 million loss in cross-chain flash loan price manipulation attack.
On November 23, 2023, KyberSwap, a cross-chain DEX, was exploited in a flash loan attack that manipulated prices and ticks, leading to an approximate loss of $45 million across several chains. The attacker used a flash loan to deplete pools with low liquidity by executing swaps and strategic position changes. Multiple swap steps and cross-tick operations were initiated to induce double liquidity counting, effectively draining the pools. The attacker also sent an on-chain message, stating that negotiations would start once they were fully rested.
Losses across chains:
- Ethereum
- 7,624,223 USD worth of WETH, KNC, USDC, and more
- Arbitrum
- 20,378,076 USD worth of WETH, ARB, WBTC, DAI, and more
- Polygon
- 1,196,359 USD worth of WETH, WMATIC, WBTC, and more
- Base
- 325,085 USD worth WETH
- Optimism
- 15,738,093 USD worth of wstETH, cbETH, WETH, OP, and more
- Avalanche
- 23,592 USD worth of USDC and AVAX
Ethereum:
- Attacker: https://etherscan.io/address/0x50275E0B…3BE836
- Malicious Transaction: https://etherscan.io/tx/0x485e08dc…92f0f3
- On-chain Message: https://etherscan.io/tx/0x7a891258…4dc40a
Arbitrum:
- Funds Holders:
https://arbiscan.io/address/0xc9b826ba…0b50c6
https://arbiscan.io/address/0x84E66f86…F7Adb4
https://arbiscan.io/address/0x98d69d3e…0b88d3
- Malicious Transaction: https://arbiscan.io/tx/0x567f0ba7…b11c5b
- Bridging Transaction: https://arbiscan.io/tx/0x8a7fc196…0789e4
Avalanche:
- Funds Holders: https://snowtrace.io/address/0xc9b826ba…0b50c6
- Malicious Transaction: https://snowtrace.io/tx/0x96d90b23…bf9714
Optimism:
- Funds Holders: https://optimistic.etherscan.io/address/0xc9b826ba…0b50c6
- Malicious Transaction: https://optimistic.etherscan.io/tx/0x7f325cf1…c5c874
Polygon:
- Funds Holders: https://polygonscan.com/address/0xc9b826ba…0b50c6
- Malicious Transaction: https://polygonscan.com/tx/0xb58c8146…df8b0c
Base:
- Funds Holders: https://basescan.org/address/0xc9b826ba…0b50c6
- Malicious Transaction: https://basescan.org/tx/0x0a2957e7…27f9f7
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to KyberSwap Elastic, these are the critical security checks that could have prevented this incident (November 2023).
- Verify all logic paths related to Flashloan Swap Logic Exploit / Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Audit Report 1 Report
Related Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Proof-of-Concept Exploits
On-Chain Evidence & References
Sources & References
Learn to Prevent the Next KyberSwap Elastic
The KyberSwap Elastic hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.