Kinto released a review report on the K attack incident, planning to migrate contracts and restore user assets.

TechubNews

Techub News reports that Ramon Recuero, the founder of the Arbitrum ecosystem modular trading platform Kinto, has released a detailed recap report on the K Token hacking incident. The attack originated from a hidden backdoor vulnerability in the ERC-1967 Proxy standard, which allowed the attacker to bypass blockchain explorer detection, upgrade the K proxy contract on Arbitrum, and mint unlimited tokens. Subsequently, approximately 1.55 million dollars in liquidity was extracted from Uniswap V4 and Morpho Blue.

Kinto stated that the vulnerability exists in the widely used OpenZeppelin Proxy template, which was not written by the Kinto team. The Kinto L2 network, wallet SDK, and abstract infrastructure are not affected, and users’ other assets on Kinto are also unaffected. The project team will take the following remedial measures, including deploying new K contracts: launching a reinforced new contract on Arbitrum; asset recovery: taking a snapshot of on-chain and CEX exchange addresses at the block before the attack (356170028) to restore all Token balances; restarting Liquidity: conducting small-scale financing to inject new liquidity into the Uniswap pool and restoring CEX trading at pre-attack prices; Morpho compensation plan: providing borrowers with a 90-day repayment period, and the team will cover the remaining gap; speculator compensation mechanism: providing a proportionate distribution of new K compensation windows for users who purchased before the announcement after the attack.

View Original
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Comment
0/400
GateUser-6898469bvip
· 2025-07-14 07:33
Steadfast HODL💎
View OriginalReply0
NZAIRvip
· 2025-07-14 03:42
Speculator fairness window — one week after trading resumes, wallets that bought the dip before our first announcement will receive new $K pro-rata. Details TBD.
Reply0
NZAIRvip
· 2025-07-14 03:42
Detailed timeline (UTC) Wed · 9 Jul 2025 · 20:17 — First public disclosure of the proxy-slot back-door by @deeberiroz. Thu · 10 Jul 2025 · 08:40 — Attacker upgrades the Arbitrum $K proxy, mints unlimited tokens, and drains Uniswap & Morpho (~ $1.55 M). See the Tenderly trace and the attacker’s tx list. Thu · 10 Jul 2025 · 09:50 — Kinto issues its first public alert.
Reply0
GateUser-31bde388vip
· 2025-07-14 03:14
What is recovery trading?
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)