• bitcoinBitcoin (BTC) $ 111,915.00
  • ethereumEthereum (ETH) $ 3,998.16
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 1,200.24
  • xrpXRP (XRP) $ 2.47
  • solanaSolana (SOL) $ 196.18
  • usd-coinUSDC (USDC) $ 0.999900
  • staked-etherLido Staked Ether (STETH) $ 3,995.37
  • dogecoinDogecoin (DOGE) $ 0.199869
  • tronTRON (TRX) $ 0.311987
  • cardanoCardano (ADA) $ 0.682276
  • wrapped-stethWrapped stETH (WSTETH) $ 4,859.27
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 111,712.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,299.26
  • chainlinkChainlink (LINK) $ 18.65
  • figure-helocFigure Heloc (FIGR_HELOC) $ 0.998454
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • wrapped-eethWrapped eETH (WEETH) $ 4,308.71
  • stellarStellar (XLM) $ 0.329683
  • hyperliquidHyperliquid (HYPE) $ 38.71
  • bitcoin-cashBitcoin Cash (BCH) $ 522.81
  • suiSui (SUI) $ 2.73
  • avalanche-2Avalanche (AVAX) $ 22.40
  • wethWETH (WETH) $ 3,995.28
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • leo-tokenLEO Token (LEO) $ 9.67
  • usdsUSDS (USDS) $ 1.00
  • hedera-hashgraphHedera (HBAR) $ 0.181306
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 111,845.00
  • usdt0USDT0 (USDT0) $ 1.00
  • litecoinLitecoin (LTC) $ 94.32
  • shiba-inuShiba Inu (SHIB) $ 0.000010
  • mantleMantle (MNT) $ 1.88
  • whitebitWhiteBIT Coin (WBT) $ 42.20
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • the-open-networkToncoin (TON) $ 2.22
  • moneroMonero (XMR) $ 305.23
  • crypto-com-chainCronos (CRO) $ 0.159084
  • polkadotPolkadot (DOT) $ 3.15
  • daiDai (DAI) $ 0.999864
  • bittensorBittensor (TAO) $ 411.78
  • uniswapUniswap (UNI) $ 6.62
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.139110
  • okbOKB (OKB) $ 178.52
  • aaveAave (AAVE) $ 243.71
  • zcashZcash (ZEC) $ 224.31
  • memecoreMemeCore (M) $ 2.07
  • bitget-tokenBitget Token (BGB) $ 4.80
  • pepePepe (PEPE) $ 0.000007
  • ethenaEthena (ENA) $ 0.426297
  • nearNEAR Protocol (NEAR) $ 2.43
  • jito-staked-solJito Staked SOL (JITOSOL) $ 242.50
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • usd1-wlfiUSD1 (USD1) $ 0.999934
  • aster-2Aster (ASTER) $ 1.35
  • susdssUSDS (SUSDS) $ 1.07
  • aptosAptos (APT) $ 3.65
  • c1usdCurrency One USD (C1USD) $ 1.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999729
  • ethereum-classicEthereum Classic (ETC) $ 16.39
  • ondo-financeOndo (ONDO) $ 0.767448
  • binance-peg-wethBinance-Peg WETH (WETH) $ 4,000.14
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.51
  • story-2Story (IP) $ 6.51
  • falcon-financeFalcon USD (USDF) $ 0.997467
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.196642
  • worldcoin-wldWorldcoin (WLD) $ 0.930025
  • gatechain-tokenGate (GT) $ 16.39
  • binance-staked-solBinance Staked SOL (BNSOL) $ 210.86
  • htx-daoHTX DAO (HTX) $ 0.000002
  • kucoin-sharesKuCoin (KCS) $ 14.29
  • internet-computerInternet Computer (ICP) $ 3.45
  • usdtbUSDtb (USDTB) $ 1.00
  • arbitrumArbitrum (ARB) $ 0.332623
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,561.06
  • pi-networkPi Network (PI) $ 0.213189
  • hash-2Provenance Blockchain (HASH) $ 0.035200
  • algorandAlgorand (ALGO) $ 0.196556
  • bfusdBFUSD (BFUSD) $ 1.00
  • wbnbWrapped BNB (WBNB) $ 1,200.80
  • cosmosCosmos Hub (ATOM) $ 3.38
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,213.56
  • kaspaKaspa (KAS) $ 0.059350
  • vechainVeChain (VET) $ 0.018516
  • tether-goldTether Gold (XAUT) $ 4,146.71
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,262.21
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 38.86
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.024108
  • chainopera-aiChainOpera AI (COAI) $ 7.37
  • flare-networksFlare (FLR) $ 0.018945
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,315.81
  • render-tokenRender (RENDER) $ 2.77
  • skySky (SKY) $ 0.060972
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 111,843.00
  • sei-networkSei (SEI) $ 0.217525
  • pump-funPump.fun (PUMP) $ 0.003758
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,235.25
  • pax-goldPAX Gold (PAXG) $ 4,158.78
  • official-trumpOfficial Trump (TRUMP) $ 6.24
  • nexoNEXO (NEXO) $ 1.20
  • bonkBonk (BONK) $ 0.000015
  • pancakeswap-tokenPancakeSwap (CAKE) $ 3.40
  • jupiter-exchange-solanaJupiter (JUP) $ 0.367058
  • syrupusdcSyrup USDC (SYRUPUSDC) $ 1.13
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 1.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 111,801.00
  • filecoinFilecoin (FIL) $ 1.60
  • immutable-xImmutable (IMX) $ 0.561645
  • spx6900SPX6900 (SPX) $ 1.16
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997651
  • xdce-crowd-saleXDC Network (XDC) $ 0.059398
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,299.75
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 224.18
  • morphoMorpho (MORPHO) $ 1.80
  • celestiaCelestia (TIA) $ 1.11
  • injective-protocolInjective (INJ) $ 9.22
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 111,806.00
  • solmevSolMev (SN116) $ 2,398.72
  • doublezeroDoubleZero (2Z) $ 0.256661
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.340160
  • fasttokenFasttoken (FTN) $ 2.01
  • clbtcclBTC (CLBTC) $ 112,704.00
  • optimismOptimism (OP) $ 0.474316
  • ripple-usdRipple USD (RLUSD) $ 0.999940
  • lido-daoLido DAO (LDO) $ 0.930467
  • msolMarinade Staked SOL (MSOL) $ 261.12
  • blockstackStacks (STX) $ 0.454114
  • curve-dao-tokenCurve DAO (CRV) $ 0.563553
  • aerodrome-financeAerodrome Finance (AERO) $ 0.878653
  • ousgOUSG (OUSG) $ 112.92
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,823.09
  • global-dollarGlobal Dollar (USDG) $ 0.999916
  • plasmaPlasma (XPL) $ 0.413143
  • sonic-3Sonic (S) $ 0.194982
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,995.74
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.85
  • the-graphThe Graph (GRT) $ 0.067337
  • pyth-networkPyth Network (PYTH) $ 0.119453
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.09
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998485
  • flokiFLOKI (FLOKI) $ 0.000071
  • saros-financeSaros (SAROS) $ 0.256315
  • havvenSynthetix (SNX) $ 1.96
  • tbtctBTC (TBTC) $ 111,358.00
  • kaiaKaia (KAIA) $ 0.111359
  • aethirAethir (ATH) $ 0.045534
  • tezosTezos (XTZ) $ 0.606000
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,993.26
  • myx-financeMYX Finance (MYX) $ 3.27
  • newton-projectAB (AB) $ 0.007564
  • gtethGTETH (GTETH) $ 3,996.64
  • stader-ethxStader ETHx (ETHX) $ 4,277.91
  • ether-fiEther.fi (ETHFI) $ 1.18
  • pendlePendle (PENDLE) $ 3.53
  • usdaiUSDai (USDAI) $ 1.03
  • iotaIOTA (IOTA) $ 0.145824
  • beldexBeldex (BDX) $ 0.078499
  • conflux-tokenConflux (CFX) $ 0.113468
  • dashDash (DASH) $ 44.71
  • usual-usdUsual USD (USD0) $ 0.998446
  • dogwifcoindogwifhat (WIF) $ 0.551264
  • theta-tokenTheta Network (THETA) $ 0.547773
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.31
  • ethereum-name-serviceEthereum Name Service (ENS) $ 16.34
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,393.44
  • galaGALA (GALA) $ 0.011539
  • swethSwell Ethereum (SWETH) $ 4,390.31
  • starknetStarknet (STRK) $ 0.122768
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 111,882.00
  • the-sandboxThe Sandbox (SAND) $ 0.216659
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,302.87
  • rna-2RNA (SN117) $ 4,708.96
  • raydiumRaydium (RAY) $ 1.94
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.789194
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.200310
  • swissborgSwissBorg (BORG) $ 0.520664
  • bittorrentBitTorrent (BTT) $ 0.00000052
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • jasmycoinJasmyCoin (JASMY) $ 0.010444
  • decentralandDecentraland (MANA) $ 0.261508
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.30
  • true-usdTrueUSD (TUSD) $ 0.999655
  • astherus-staked-bnbAster Staked BNB (ASBNB) $ 1,263.12
  • vaultaVaulta (A) $ 0.304571
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.10
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,300.86
  • usddUSDD (USDD) $ 1.00
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999900
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 1.00
  • ai-companionsAI Companions (AIC) $ 0.466094
  • flowFlow (FLOW) $ 0.286373
  • sun-tokenSun Token (SUN) $ 0.024070
  • syrupMaple Finance (SYRUP) $ 0.412787
  • zero-gravity0G (0G) $ 2.13
  • bitcoin-svBitcoin SV (BSV) $ 22.21
  • jito-governance-tokenJito (JTO) $ 1.12
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,993.96
  • frax-etherFrax Ether (FRXETH) $ 3,955.66
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 27.48
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,997.42

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

0 25

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

The native token of Kinto, a compliance-focused Layer 2 network, crashed 90% on July 10 in under an hour after an attacker exploited its token minting mechanism and drained assets.

According to a July 11 X thread by Kinto co-founder Ramon Recuero, the incident appears to be tied to a broader vulnerability affecting thousands of contracts across DeFi built using the ERC1967Proxy standard, a common OpenZeppelin codebase that allows smart contracts to be upgraded without changing their address.

The vulnerability — first uncovered by blockchain security firm Venn Build alongside researchers from Dedaub, SEAL 911, and on-chain analyst pcaversaccio — revealed that thousands of contracts using the ERC1967Proxy standard were exposed to a novel exploit that let attackers insert malicious proxy admins while deceiving block explorers like Etherscan.

While the full list of affected projects remains unclear, Recuero noted that at least one — Berachain, a Layer 1 blockchain that had raised $100 million — was also exposed to the vulnerability but managed to prevent an attack in time.

Although a 36-hour “war room” effort helped secure many protocols before the vulnerability was widely exploited, Recuero said Kinto was not notified in time — even after other teams had been alerted — suggesting that the public disclosure of the vulnerability may have unintentionally triggered the attack on Kinto.

Recuero reiterated to The Defiant that the “Kinto network, assets and wallet are not affected and they are extremely safe,” adding that the Kinto smart contracts themselves were not breached. “This was a vulnerability in proxy contract ERC 1967 made worse by a bug in block explorers like Etherscan or Arbiscan,” he added.

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

Source: Arbiscan

By leveraging the backdoor, the attacker minted 110,000 K tokens and later used them to drain the Morpho Vault and a Uniswap v4 pool. Additional tokens were minted on demand, with funds bridged and swapped across protocols in what Recuero described as a “straightforward” attack.

“I know this is a really hard time for all of you. I am really sorry this has happened. No matter the circumstances, it is all my fault and I take responsibility. Me and the team will do anything in our power to come back from this,” Recuero wrote.

‘All Signs Point to Lazarus’

Amid the attack, Kinto’s native token K collapsed by 90% in under an hour, crashing from $7.69 to just $0.50 and wiping out nearly $13 million in market value in a matter of minutes, per data from CoinGecko.

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

Kinto Chart

Per Recuero, the team is working with authorities in the Cayman Islands and security groups, including ZeroShadow and Venn Build, to track the attacker. Speaking with The Defiant, Recuero said that “all signs point to Lazarus,” a North Korean state-sponsored hacking group that was also responsible for the $1.5 billion Bybit hack earlier this year.

If recovery efforts are successful, Kinto plans to roll back token balances to a snapshot block taken before the exploit, restore the Morpho vault and Uniswap liquidity, as well as relist K on centralized exchanges at the pre-hack price of $7.48 by July 31.

Recuero emphasized that the core Kinto network — including the wallet, bridge, and UI — remains unaffected. Following the hack, critics on social media panned Kinto’s reliance on the OpenZeppelin ERC1967Proxy pattern without fully auditing it for all possible vulnerabilities.

A user under the alias @SemiDeFi argued that the “sloppy proxy setup” left the door open to exploitation, effectively holding Kinto responsible for the breach.

In response, Recuero told The Defiant that “the vulnerable proxy contracts were audited by 30 different auditors, part of the OpenZeppelin foundational contract library and had been used for 10 years until now.”

Founded in 2023 by Ramon Recuero, Víctor Sánchez, and Alan Keegan, Kinto is a compliance‑focused Layer 2 network built on Ethereum’s Arbitrum Nitro stack, featuring native KYC/AML enforcement.

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

Kinto TVS

According to data from L2Beat, Kinto held over $80 million in total secured value as of December 2024, but that figure has since declined, dropping to $16 million as of July 10.

In February 2025, Brevan Howard Digital’s Abu Dhabi arm deployed $20 million in assets on Kinto to participate in its institutional-grade DeFi ecosystem.

Source

Leave A Reply

Your email address will not be published.