KiloEx to Compensate Users After $7 Million Exploit
Key Takeaways
- Compensation will be calculated only up to the point when the platform resumes operations
- KiloEx says users who had open positions during the suspension will be reimbursed for the difference in increased losses or decreased profits caused by the exploit.
KiloEx, a decentralized exchange (DEX), has announced a compensation plan following a security breach earlier this month that led to $7 million in losses. The platform suspended operations on April 14 after containing the exploit, which was attributed to a vulnerability in its price oracle mechanism.
According to a statement from KiloEx, users who had open positions during the suspension will be reimbursed for the difference in increased losses or decreased profits caused by the exploit. Compensation will be calculated only up to the point when the platform resumes operations. Users are advised to close their positions as soon as possible after the platform is back online.
The attack was linked to a permissionless function on the platform that allowed the attacker to make unauthorized transactions. KiloEx’s internal review revealed that the attacker was able to open a trading position at an artificially low price and close it at a higher price, generating a profit not backed by market activity.
Blockchain security firm PeckShield reported that the attacker likely exploited a price oracle vulnerability and used a wallet funded by crypto mixing service- Tornado Cash.
KiloEx confirmed that it has worked with blockchain security firm SlowMist to recover approximately $8.44 million. The exchange has completed a full security audit and said operations will only resume once the upgraded systems are confirmed secure.
The compensation plan covers traders, Hybrid Vault stakers, and VIP users affected by the exploit. The exchange said, “Compensation will only be calculated up to the point the platform resumes,” emphasizing that impacted users should act promptly once services are restored.
Following the announcement, KILO, the platform’s native token, fell by over 5%. The token’s decline reflects concerns within the market about the safety of decentralized platforms following repeated exploit incidents in the sector.
KiloEx has not specified a timeline for resuming services but stated that operations will continue only after all necessary security measures have been verified. The exchange plans to provide further updates through its official channels.