• bitcoinBitcoin (BTC) $ 108,221.00
  • ethereumEthereum (ETH) $ 4,349.72
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.80
  • bnbBNB (BNB) $ 858.55
  • solanaSolana (SOL) $ 202.78
  • usd-coinUSDC (USDC) $ 0.999811
  • staked-etherLido Staked Ether (STETH) $ 4,338.70
  • tronTRON (TRX) $ 0.338867
  • dogecoinDogecoin (DOGE) $ 0.212252
  • cardanoCardano (ADA) $ 0.823151
  • wrapped-stethWrapped stETH (WSTETH) $ 5,246.49
  • chainlinkChainlink (LINK) $ 23.34
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,685.05
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 108,561.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • hyperliquidHyperliquid (HYPE) $ 44.41
  • wrapped-eethWrapped eETH (WEETH) $ 4,661.98
  • suiSui (SUI) $ 3.26
  • stellarStellar (XLM) $ 0.359453
  • bitcoin-cashBitcoin Cash (BCH) $ 530.16
  • avalanche-2Avalanche (AVAX) $ 23.49
  • hedera-hashgraphHedera (HBAR) $ 0.226734
  • wethWETH (WETH) $ 4,350.05
  • crypto-com-chainCronos (CRO) $ 0.278113
  • leo-tokenLEO Token (LEO) $ 9.48
  • litecoinLitecoin (LTC) $ 109.65
  • usdsUSDS (USDS) $ 0.999746
  • the-open-networkToncoin (TON) $ 3.07
  • shiba-inuShiba Inu (SHIB) $ 0.000012
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 108,241.00
  • whitebitWhiteBIT Coin (WBT) $ 42.21
  • uniswapUniswap (UNI) $ 9.61
  • polkadotPolkadot (DOT) $ 3.77
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.19
  • bitget-tokenBitget Token (BGB) $ 4.53
  • moneroMonero (XMR) $ 261.88
  • aaveAave (AAVE) $ 316.33
  • daiDai (DAI) $ 0.999921
  • ethenaEthena (ENA) $ 0.642649
  • pepePepe (PEPE) $ 0.000010
  • mantleMantle (MNT) $ 1.13
  • okbOKB (OKB) $ 169.07
  • ethereum-classicEthereum Classic (ETC) $ 20.87
  • bittensorBittensor (TAO) $ 319.09
  • nearNEAR Protocol (NEAR) $ 2.43
  • jito-staked-solJito Staked SOL (JITOSOL) $ 248.94
  • aptosAptos (APT) $ 4.26
  • ondo-financeOndo (ONDO) $ 0.903378
  • pi-networkPi Network (PI) $ 0.356551
  • usdt0USDT0 (USDT0) $ 1.00
  • binance-peg-wethBinance-Peg WETH (WETH) $ 4,351.68
  • internet-computerInternet Computer (ICP) $ 4.90
  • arbitrumArbitrum (ARB) $ 0.490642
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.241286
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • binance-staked-solBinance Staked SOL (BNSOL) $ 217.09
  • kaspaKaspa (KAS) $ 0.084751
  • cosmosCosmos Hub (ATOM) $ 4.47
  • vechainVeChain (VET) $ 0.024233
  • algorandAlgorand (ALGO) $ 0.235765
  • gatechain-tokenGate (GT) $ 17.02
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,949.10
  • susdssUSDS (SUSDS) $ 1.07
  • fasttokenFasttoken (FTN) $ 4.53
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.40
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.029328
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,561.05
  • story-2Story (IP) $ 6.00
  • worldcoin-wldWorldcoin (WLD) $ 0.906146
  • render-tokenRender (RENDER) $ 3.45
  • kucoin-sharesKuCoin (KCS) $ 13.83
  • sei-networkSei (SEI) $ 0.287372
  • bonkBonk (BONK) $ 0.000022
  • bfusdBFUSD (BFUSD) $ 0.999326
  • official-trumpOfficial Trump (TRUMP) $ 8.35
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,578.70
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.619670
  • black-phoenixBlack Phoenix (BPX) $ 1.10
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 44.50
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,693.95
  • jupiter-exchange-solanaJupiter (JUP) $ 0.509996
  • filecoinFilecoin (FIL) $ 2.26
  • flare-networksFlare (FLR) $ 0.021029
  • skySky (SKY) $ 0.064111
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 108,276.00
  • quant-networkQuant (QNT) $ 101.82
  • usdtbUSDtb (USDTB) $ 1.00
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 0.999908
  • fourFour (FORM) $ 3.61
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,592.85
  • hash-2Provenance Blockchain (HASH) $ 0.027839
  • xdce-crowd-saleXDC Network (XDC) $ 0.075560
  • falcon-financeFalcon USD (USDF) $ 0.999908
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,660.87
  • tether-goldTether Gold (XAUT) $ 3,453.40
  • injective-protocolInjective (INJ) $ 12.98
  • pyth-networkPyth Network (PYTH) $ 0.221047
  • nexoNEXO (NEXO) $ 1.24
  • optimismOptimism (OP) $ 0.695487
  • celestiaCelestia (TIA) $ 1.62
  • pump-funPump.fun (PUMP) $ 0.003455
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 230.45
  • wbnbWrapped BNB (WBNB) $ 858.64
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997478
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 108,568.00
  • blockstackStacks (STX) $ 0.620180
  • lido-daoLido DAO (LDO) $ 1.21
  • curve-dao-tokenCurve DAO (CRV) $ 0.759894
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999620
  • sonic-3Sonic (S) $ 0.314229
  • spx6900SPX6900 (SPX) $ 1.08
  • aerodrome-financeAerodrome Finance (AERO) $ 1.12
  • immutable-xImmutable (IMX) $ 0.516755
  • pax-goldPAX Gold (PAXG) $ 3,461.85
  • super-oethSuper OETH (SUPEROETH) $ 4,351.68
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.12
  • raydiumRaydium (RAY) $ 3.50
  • msolMarinade Staked SOL (MSOL) $ 267.69
  • saros-financeSaros (SAROS) $ 0.355713
  • the-graphThe Graph (GRT) $ 0.087838
  • conflux-tokenConflux (CFX) $ 0.179283
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 108,531.00
  • flokiFLOKI (FLOKI) $ 0.000093
  • memecoreMemeCore (M) $ 0.531715
  • kaiaKaia (KAIA) $ 0.147284
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.48
  • clbtcclBTC (CLBTC) $ 110,106.00
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 4,331.34
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 4,181.82
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 4,350.31
  • dogwifcoindogwifhat (WIF) $ 0.793489
  • pendlePendle (PENDLE) $ 4.64
  • theta-tokenTheta Network (THETA) $ 0.778297
  • vaultaVaulta (A) $ 0.489779
  • tezosTezos (XTZ) $ 0.734699
  • fartcoinFartcoin (FARTCOIN) $ 0.770627
  • iotaIOTA (IOTA) $ 0.192760
  • ethereum-name-serviceEthereum Name Service (ENS) $ 23.20
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.14
  • galaGALA (GALA) $ 0.016089
  • jito-governance-tokenJito (JTO) $ 1.98
  • ousgOUSG (OUSG) $ 112.39
  • ripple-usdRipple USD (RLUSD) $ 0.999616
  • jasmycoinJasmyCoin (JASMY) $ 0.014389
  • newton-projectAB (AB) $ 0.009144
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.997696
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.08
  • the-sandboxThe Sandbox (SAND) $ 0.274023
  • build-onBUILDon (B) $ 0.666391
  • morphoMorpho (MORPHO) $ 2.00
  • loaded-lionsLoaded Lions (LION) $ 0.021625
  • zcashZcash (ZEC) $ 40.37
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 4,351.54
  • stader-ethxStader ETHx (ETHX) $ 4,566.90
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,666.22
  • bittorrentBitTorrent (BTT) $ 0.00000065
  • flowFlow (FLOW) $ 0.398754
  • tbtctBTC (TBTC) $ 108,062.00
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,780.57
  • swethSwell Ethereum (SWETH) $ 4,703.49
  • usual-usdUsual USD (USD0) $ 0.998120
  • beldexBeldex (BDX) $ 0.076355
  • global-dollarGlobal Dollar (USDG) $ 0.999790
  • walrus-2Walrus (WAL) $ 0.384609
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.212213
  • decentralandDecentraland (MANA) $ 0.282522
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 108,231.00
  • vision-3Vision (VSN) $ 0.166116
  • bitcoin-svBitcoin SV (BSV) $ 26.05
  • syrupMaple Finance (SYRUP) $ 0.462928
  • ether-fiEther.fi (ETHFI) $ 1.08
  • frax-etherFrax Ether (FRXETH) $ 4,308.36
  • true-usdTrueUSD (TUSD) $ 0.997865
  • starknetStarknet (STRK) $ 0.126578
  • heliumHelium (HNT) $ 2.56
  • dydx-chaindYdX (DYDX) $ 0.610507
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 4,349.21
  • neoNEO (NEO) $ 6.66
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 107,792.00
  • based-brettBrett (BRETT) $ 0.047236
  • apenftAPENFT (NFT) $ 0.00000046
  • apecoinApeCoin (APE) $ 0.560682
  • usddUSDD (USDD) $ 1.00
  • bybit-staked-solBybit Staked SOL (BBSOL) $ 223.51
  • reserve-rights-tokenReserve Rights (RSR) $ 0.007423
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.999346
  • zksyncZKsync (ZK) $ 0.060469
  • sun-tokenSun Token (SUN) $ 0.022802
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999797
  • savings-daiSavings Dai (SDAI) $ 1.16
  • telcoinTelcoin (TEL) $ 0.004678
  • dexeDeXe (DEXE) $ 7.57
  • coredaoorgCore (CORE) $ 0.428045
  • bridged-usdc-polygon-pos-bridgeBridged USDC (Polygon PoS Bridge) (USDC.E) $ 0.999811
  • arweaveArweave (AR) $ 6.39
  • instadappFluid (FLUID) $ 6.12

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

0 14

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

The native token of Kinto, a compliance-focused Layer 2 network, crashed 90% on July 10 in under an hour after an attacker exploited its token minting mechanism and drained assets.

According to a July 11 X thread by Kinto co-founder Ramon Recuero, the incident appears to be tied to a broader vulnerability affecting thousands of contracts across DeFi built using the ERC1967Proxy standard, a common OpenZeppelin codebase that allows smart contracts to be upgraded without changing their address.

The vulnerability — first uncovered by blockchain security firm Venn Build alongside researchers from Dedaub, SEAL 911, and on-chain analyst pcaversaccio — revealed that thousands of contracts using the ERC1967Proxy standard were exposed to a novel exploit that let attackers insert malicious proxy admins while deceiving block explorers like Etherscan.

While the full list of affected projects remains unclear, Recuero noted that at least one — Berachain, a Layer 1 blockchain that had raised $100 million — was also exposed to the vulnerability but managed to prevent an attack in time.

Although a 36-hour “war room” effort helped secure many protocols before the vulnerability was widely exploited, Recuero said Kinto was not notified in time — even after other teams had been alerted — suggesting that the public disclosure of the vulnerability may have unintentionally triggered the attack on Kinto.

Recuero reiterated to The Defiant that the “Kinto network, assets and wallet are not affected and they are extremely safe,” adding that the Kinto smart contracts themselves were not breached. “This was a vulnerability in proxy contract ERC 1967 made worse by a bug in block explorers like Etherscan or Arbiscan,” he added.

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

Source: Arbiscan

By leveraging the backdoor, the attacker minted 110,000 K tokens and later used them to drain the Morpho Vault and a Uniswap v4 pool. Additional tokens were minted on demand, with funds bridged and swapped across protocols in what Recuero described as a “straightforward” attack.

“I know this is a really hard time for all of you. I am really sorry this has happened. No matter the circumstances, it is all my fault and I take responsibility. Me and the team will do anything in our power to come back from this,” Recuero wrote.

‘All Signs Point to Lazarus’

Amid the attack, Kinto’s native token K collapsed by 90% in under an hour, crashing from $7.69 to just $0.50 and wiping out nearly $13 million in market value in a matter of minutes, per data from CoinGecko.

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

Kinto Chart

Per Recuero, the team is working with authorities in the Cayman Islands and security groups, including ZeroShadow and Venn Build, to track the attacker. Speaking with The Defiant, Recuero said that “all signs point to Lazarus,” a North Korean state-sponsored hacking group that was also responsible for the $1.5 billion Bybit hack earlier this year.

If recovery efforts are successful, Kinto plans to roll back token balances to a snapshot block taken before the exploit, restore the Morpho vault and Uniswap liquidity, as well as relist K on centralized exchanges at the pre-hack price of $7.48 by July 31.

Recuero emphasized that the core Kinto network — including the wallet, bridge, and UI — remains unaffected. Following the hack, critics on social media panned Kinto’s reliance on the OpenZeppelin ERC1967Proxy pattern without fully auditing it for all possible vulnerabilities.

A user under the alias @SemiDeFi argued that the “sloppy proxy setup” left the door open to exploitation, effectively holding Kinto responsible for the breach.

In response, Recuero told The Defiant that “the vulnerable proxy contracts were audited by 30 different auditors, part of the OpenZeppelin foundational contract library and had been used for 10 years until now.”

Founded in 2023 by Ramon Recuero, Víctor Sánchez, and Alan Keegan, Kinto is a compliance‑focused Layer 2 network built on Ethereum’s Arbitrum Nitro stack, featuring native KYC/AML enforcement.

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

Kinto TVS

According to data from L2Beat, Kinto held over $80 million in total secured value as of December 2024, but that figure has since declined, dropping to $16 million as of July 10.

In February 2025, Brevan Howard Digital’s Abu Dhabi arm deployed $20 million in assets on Kinto to participate in its institutional-grade DeFi ecosystem.

Source

Leave A Reply

Your email address will not be published.