Kasplex KRC-20 signature bypass exploit leads to significant liquidity pool losses
An attacker exploited a signature verification vulnerability in the Kasplex KRC-20 off-chain indexer to transfer 186 million ZEAL and 54.398 billion NACHO without holding the bridge wallet private keys. By forging five transactions, the attacker minted tokens via Igra Labs EVM layer and Kasplex L2 before selling them on Zealous Swap. The KAS-side value of the affected liquidity pools dropped by 94% to 99.6%. Igra has suspended iKAS withdrawals to Kaspa L1 and Hyperlane transfers, advising users to avoid bridging KRC-20 tokens or adding liquidity to affected pools. Kaspa L1 consensus and non-bridged Igra assets remain unaffected.
Summaries are written by AI from the original article. Not investment advice.