← Radar

Incident case file

Sign in to watch

KITE Foundation Token Attack — Detected and Contained

Incident date 2026-08-05Last updated Aug 14, 2026

4 views

ContainedEthereumDetected & contained attackCluster: KITE-CONT-2026-08

Estimated loss

$0

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Ledger

Attacker

MISSING — not publicly disclosed.

Funds moved to

N/A — per the official KITE Foundation statement, no tokens were lost at any point during the incident.

Linked

KITE Foundation operates payment infrastructure for the emerging 'AI Agent economy,' with native token KITE. Automated security monitoring flagged unusual KITE token transfer activity on Ethereum mainnet, triggering an immediate incident response that suspended all KITE token transfers and cross-chain bridge functions before any tokens could be successfully extracted by the attacker.

Chronology

1 beat
  1. August 6, 2026: KITE Foundation's automated security monitoring system flags unusual, unauthorized transfer activity involving the KITE token on Ethereum mainnet. The team initiates an immediate incident response, suspending all KITE token transfers and associated cross-chain bridge functionality as an emergency precautionary measure. Per the official statement published by @KiteAIFDN: 'We detected an attack targeting the Kite (KITE) token. It was identified and contained immediately, and no tokens were lost. In the interest of transparency, here is what happened: Our security monitoring flagged unusual KITE token transfer activity on Ethereum mainnet.' Despite the fully successful containment and confirmed zero token loss, market reaction to the disclosure is nonetheless negative — the KITE token's price declines by approximately 3.7% (moving from roughly $0.104 down into the low $0.10x range) in the immediate aftermath of the public announcement, reflecting general investor sensitivity to security-incident news regardless of the ultimately contained outcome. Any tokens flagged or frozen as part of the response are confirmed to remain excluded from re-entering secondary trading markets. No attacker identity or specific underlying technical vulnerability details have been publicly disclosed as of the close of the reporting window, consistent with a fully and rapidly contained incident where the team's evident priority was swift operational response over immediate exhaustive public technical disclosure.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)