← Radar

Incident case file

Sign in to watch

KiloEx — Permissionless Price Oracle Manipulation

Incident date April 14, 2026

1 views

ResolvedBaseopBNBBNB ChainOracle manipulationCluster: KLX-ORC-2026-04

Estimated loss

$7.5M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Attacker: 0x00fac92881556a90fdb19eae9f23640b95b4bcbd (funded via Tornado Cash pre-attack)

Funds moved to: $3.3M on Base + $3.1M on opBNB + $1M on BNB Chain = ~$7.5M total. Routed via zkBridge + Meson cross-chain. On 18 April 2026: KiloEx dropped legal actions, attacker accepted the 10% bounty ($750K), 90% of funds returned (~$6.75M).
Single attacker wallet 0x00fac9…b4bcbd. KiloEx coordinates with BNB Chain, Manta Network, Seal-911, SlowMist, Sherlock to trace and negotiate.

Timeline: On 13 April 2026, KiloEx announced an 'exclusive partnership' with Dubai-based Web3 venture capitalist firm DWF Labs (BlockchainReporter / Cointelegraph) 'to accelerate innovation and growth in decentralized trading'. On 14 April 2026 at ~19:30 UTC, Cyvers Alerts detected the multi-chain exploit. Root cause (Chaofan Shou, Fuzzland + PeckShield): access control flaw on the price oracle — 'anyone can change Kilo's price oracle; they check that the caller is a trusted forwarder, but not the forwarded caller'. The attacker executed ETH/USD positions with initial price 100, immediately closed at price 10,000, netting $3.12M per transaction. Total: ~$7.5M split across 3 chains. Funds routed via zkBridge + Meson. KiloEx paused the platform immediately. On 15 April, KiloEx offered 10% of the loot (allow attacker to retain $750K) if 90% returned, or identity disclosure + legal action. On 18 April, KiloEx dropped legal actions and confirmed whitehat bug bounty payment. On 21 April, KiloEx published SlowMist post-mortem. On 24 April, compensation plan announced for traders, Hybrid Vault stakers (+10% APY bonus), VIP users (+1 tier, 30 days protection). Vulnerability patched, platform resumed. 'Very simple' vulnerability (Chaofan Shou) — trusted forwarder validated but not forwarded caller.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)