• bitcoinBitcoin (BTC) $ 117,373.00
  • ethereumEthereum (ETH) $ 3,080.26
  • xrpXRP (XRP) $ 2.93
  • tetherTether (USDT) $ 0.999749
  • bnbBNB (BNB) $ 686.54
  • solanaSolana (SOL) $ 161.76
  • usd-coinUSDC (USDC) $ 0.999884
  • dogecoinDogecoin (DOGE) $ 0.197154
  • tronTRON (TRX) $ 0.300549
  • staked-etherLido Staked Ether (STETH) $ 3,082.04
  • cardanoCardano (ADA) $ 0.740757
  • hyperliquidHyperliquid (HYPE) $ 47.68
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 117,259.00
  • stellarStellar (XLM) $ 0.454018
  • suiSui (SUI) $ 4.04
  • wrapped-stethWrapped stETH (WSTETH) $ 3,729.89
  • chainlinkChainlink (LINK) $ 16.02
  • hedera-hashgraphHedera (HBAR) $ 0.233885
  • bitcoin-cashBitcoin Cash (BCH) $ 493.78
  • avalanche-2Avalanche (AVAX) $ 21.63
  • wrapped-eethWrapped eETH (WEETH) $ 3,310.71
  • leo-tokenLEO Token (LEO) $ 9.03
  • shiba-inuShiba Inu (SHIB) $ 0.000014
  • wethWETH (WETH) $ 3,086.86
  • the-open-networkToncoin (TON) $ 3.03
  • litecoinLitecoin (LTC) $ 95.26
  • usdsUSDS (USDS) $ 0.999859
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999966
  • whitebitWhiteBIT Coin (WBT) $ 44.60
  • moneroMonero (XMR) $ 337.96
  • polkadotPolkadot (DOT) $ 4.06
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 117,319.00
  • uniswapUniswap (UNI) $ 9.22
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • pepePepe (PEPE) $ 0.000013
  • bitget-tokenBitget Token (BGB) $ 4.50
  • aaveAave (AAVE) $ 324.79
  • bittensorBittensor (TAO) $ 434.12
  • daiDai (DAI) $ 0.999835
  • pi-networkPi Network (PI) $ 0.447039
  • crypto-com-chainCronos (CRO) $ 0.108981
  • aptosAptos (APT) $ 5.03
  • nearNEAR Protocol (NEAR) $ 2.64
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
  • internet-computerInternet Computer (ICP) $ 5.54
  • ondo-financeOndo (ONDO) $ 0.934649
  • ethereum-classicEthereum Classic (ETC) $ 18.60
  • okbOKB (OKB) $ 47.25
  • jito-staked-solJito Staked SOL (JITOSOL) $ 197.39
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • algorandAlgorand (ALGO) $ 0.284771
  • mantleMantle (MNT) $ 0.709871
  • bonkBonk (BONK) $ 0.000030
  • kaspaKaspa (KAS) $ 0.086797
  • ethenaEthena (ENA) $ 0.357158
  • sei-networkSei (SEI) $ 0.382604
  • usd1-wlfiUSD1 (USD1) $ 0.999583
  • vechainVeChain (VET) $ 0.024930
  • cosmosCosmos Hub (ATOM) $ 4.66
  • pump-funPump.fun (PUMP) $ 0.005958
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.033658
  • arbitrumArbitrum (ARB) $ 0.425748
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.229074
  • render-tokenRender (RENDER) $ 3.89
  • fasttokenFasttoken (FTN) $ 4.50
  • susdssUSDS (SUSDS) $ 1.06
  • official-trumpOfficial Trump (TRUMP) $ 9.37
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,087.19
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.714807
  • worldcoin-wldWorldcoin (WLD) $ 1.07
  • gatechain-tokenGate (GT) $ 15.49
  • filecoinFilecoin (FIL) $ 2.60
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 116,861.00
  • skySky (SKY) $ 0.077372
  • binance-staked-solBinance Staked SOL (BNSOL) $ 172.07
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.74
  • jupiter-exchange-solanaJupiter (JUP) $ 0.505977
  • spx6900SPX6900 (SPX) $ 1.59
  • kucoin-sharesKuCoin (KCS) $ 11.56
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,237.77
  • usdtbUSDtb (USDTB) $ 0.999745
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997457
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,517.73
  • celestiaCelestia (TIA) $ 1.97
  • usdt0USDT0 (USDT0) $ 0.998897
  • nexoNEXO (NEXO) $ 1.31
  • story-2Story (IP) $ 4.35
  • injective-protocolInjective (INJ) $ 13.04
  • fartcoinFartcoin (FARTCOIN) $ 1.25
  • blockstackStacks (STX) $ 0.799286
  • flare-networksFlare (FLR) $ 0.017345
  • optimismOptimism (OP) $ 0.687655
  • xdce-crowd-saleXDC Network (XDC) $ 0.074255
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,295.51
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,243.70
  • sonic-3Sonic (S) $ 0.354757
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 117,379.00
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 0.999786
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.65
  • dogwifcoindogwifhat (WIF) $ 1.05
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,251.44
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,332.26
  • immutable-xImmutable (IMX) $ 0.538218
  • curve-dao-tokenCurve DAO (CRV) $ 0.742164
  • the-graphThe Graph (GRT) $ 0.101724
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 1.00
  • flokiFLOKI (FLOKI) $ 0.000099
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 117,480.00
  • pax-goldPAX Gold (PAXG) $ 3,335.43
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.11
  • clbtcclBTC (CLBTC) $ 119,258.00
  • wbnbWrapped BNB (WBNB) $ 686.94
  • kaiaKaia (KAIA) $ 0.151951
  • iotaIOTA (IOTA) $ 0.223637
  • vaultaVaulta (A) $ 0.551005
  • paypal-usdPayPal USD (PYUSD) $ 0.999437
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 182.08
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.41
  • tether-goldTether Gold (XAUT) $ 3,326.72
  • theta-tokenTheta Network (THETA) $ 0.814786
  • msolMarinade Staked SOL (MSOL) $ 212.10
  • galaGALA (GALA) $ 0.017583
  • jasmycoinJasmyCoin (JASMY) $ 0.016332
  • lido-daoLido DAO (LDO) $ 0.880780
  • raydiumRaydium (RAY) $ 2.94
  • ethereum-name-serviceEthereum Name Service (ENS) $ 23.19
  • the-sandboxThe Sandbox (SAND) $ 0.311022
  • tokenize-xchangeTokenize Xchange (TKX) $ 9.37
  • saros-financeSaros (SAROS) $ 0.275292
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.75
  • aerodrome-financeAerodrome Finance (AERO) $ 0.841391
  • ousgOUSG (OUSG) $ 111.80
  • zcashZcash (ZEC) $ 43.37
  • memecoreMemeCore (M) $ 0.425628
  • pyth-networkPyth Network (PYTH) $ 0.121094
  • super-oethSuper OETH (SUPEROETH) $ 3,084.69
  • tezosTezos (XTZ) $ 0.649125
  • bittorrentBitTorrent (BTT) $ 0.00000069
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.997888
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,302.12
  • jito-governance-tokenJito (JTO) $ 1.89
  • pendlePendle (PENDLE) $ 4.01
  • falcon-financeFalcon USD (USDF) $ 0.999671
  • chain-2Onyxcoin (XCN) $ 0.018886
  • walrus-2Walrus (WAL) $ 0.466815
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,189.49
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • mog-coinMog Coin (MOG) $ 0.000002
  • flowFlow (FLOW) $ 0.391442
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,088.29
  • morphoMorpho (MORPHO) $ 1.94
  • telcoinTelcoin (TEL) $ 0.006719
  • tbtctBTC (TBTC) $ 117,308.00
  • wrapped-hypeWrapped HYPE (WHYPE) $ 47.72
  • decentralandDecentraland (MANA) $ 0.314253
  • newton-projectAB (AB) $ 0.008642
  • usual-usdUsual USD (USD0) $ 0.997562
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 115,031.00
  • heliumHelium (HNT) $ 3.09
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 117,379.00
  • coredaoorgCore (CORE) $ 0.543515
  • based-brettBrett (BRETT) $ 0.054691
  • thorchainTHORChain (RUNE) $ 1.54
  • staked-hypeStaked HYPE (STHYPE) $ 47.72
  • bitcoin-svBitcoin SV (BSV) $ 26.59
  • conflux-tokenConflux (CFX) $ 0.103587
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,087.28
  • apecoinApeCoin (APE) $ 0.650379
  • ripple-usdRipple USD (RLUSD) $ 0.999720
  • starknetStarknet (STRK) $ 0.143271
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.197713
  • usddUSDD (USDD) $ 0.999719
  • beldexBeldex (BDX) $ 0.069825
  • build-onBUILDon (B) $ 0.498587
  • syrupMaple Finance (SYRUP) $ 0.459633
  • true-usdTrueUSD (TUSD) $ 0.997574
  • venomVenom (VENOM) $ 0.232327
  • arweaveArweave (AR) $ 7.44
  • reserve-rights-tokenReserve Rights (RSR) $ 0.008258
  • deepDeepBook (DEEP) $ 0.193108
  • stader-ethxStader ETHx (ETHX) $ 3,280.97
  • dydx-chaindYdX (DYDX) $ 0.630841
  • 1inch1inch (1INCH) $ 0.336751
  • kavaKava (KAVA) $ 0.426151
  • compound-governance-tokenCompound (COMP) $ 48.41
  • neoNEO (NEO) $ 6.42
  • aioz-networkAIOZ Network (AIOZ) $ 0.379423
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,404.03
  • ether-fiEther.fi (ETHFI) $ 1.19
  • apenftAPENFT (NFT) $ 0.00000045
  • elrond-erd-2MultiversX (EGLD) $ 15.52
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.40
  • dexeDeXe (DEXE) $ 7.43
  • zksyncZKsync (ZK) $ 0.059156
  • ecasheCash (XEC) $ 0.000021
  • axie-infinityAxie Infinity (AXS) $ 2.52
  • hashnote-usycCircle USYC (USYC) $ 1.09
  • dog-go-to-the-moon-runeDog (Bitcoin) (DOG) $ 0.004120
  • swethSwell Ethereum (SWETH) $ 3,380.90
  • ether-fi-staked-btcEther.fi Staked BTC (EBTC) $ 118,812.00

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

0 2

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

The native token of Kinto, a compliance-focused Layer 2 network, crashed 90% on July 10 in under an hour after an attacker exploited its token minting mechanism and drained assets.

According to a July 11 X thread by Kinto co-founder Ramon Recuero, the incident appears to be tied to a broader vulnerability affecting thousands of contracts across DeFi built using the ERC1967Proxy standard, a common OpenZeppelin codebase that allows smart contracts to be upgraded without changing their address.

The vulnerability — first uncovered by blockchain security firm Venn Build alongside researchers from Dedaub, SEAL 911, and on-chain analyst pcaversaccio — revealed that thousands of contracts using the ERC1967Proxy standard were exposed to a novel exploit that let attackers insert malicious proxy admins while deceiving block explorers like Etherscan.

While the full list of affected projects remains unclear, Recuero noted that at least one — Berachain, a Layer 1 blockchain that had raised $100 million — was also exposed to the vulnerability but managed to prevent an attack in time.

Although a 36-hour “war room” effort helped secure many protocols before the vulnerability was widely exploited, Recuero said Kinto was not notified in time — even after other teams had been alerted — suggesting that the public disclosure of the vulnerability may have unintentionally triggered the attack on Kinto.

Recuero reiterated to The Defiant that the “Kinto network, assets and wallet are not affected and they are extremely safe,” adding that the Kinto smart contracts themselves were not breached. “This was a vulnerability in proxy contract ERC 1967 made worse by a bug in block explorers like Etherscan or Arbiscan,” he added.

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

Source: Arbiscan

By leveraging the backdoor, the attacker minted 110,000 K tokens and later used them to drain the Morpho Vault and a Uniswap v4 pool. Additional tokens were minted on demand, with funds bridged and swapped across protocols in what Recuero described as a “straightforward” attack.

“I know this is a really hard time for all of you. I am really sorry this has happened. No matter the circumstances, it is all my fault and I take responsibility. Me and the team will do anything in our power to come back from this,” Recuero wrote.

‘All Signs Point to Lazarus’

Amid the attack, Kinto’s native token K collapsed by 90% in under an hour, crashing from $7.69 to just $0.50 and wiping out nearly $13 million in market value in a matter of minutes, per data from CoinGecko.

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

Kinto Chart

Per Recuero, the team is working with authorities in the Cayman Islands and security groups, including ZeroShadow and Venn Build, to track the attacker. Speaking with The Defiant, Recuero said that “all signs point to Lazarus,” a North Korean state-sponsored hacking group that was also responsible for the $1.5 billion Bybit hack earlier this year.

If recovery efforts are successful, Kinto plans to roll back token balances to a snapshot block taken before the exploit, restore the Morpho vault and Uniswap liquidity, as well as relist K on centralized exchanges at the pre-hack price of $7.48 by July 31.

Recuero emphasized that the core Kinto network — including the wallet, bridge, and UI — remains unaffected. Following the hack, critics on social media panned Kinto’s reliance on the OpenZeppelin ERC1967Proxy pattern without fully auditing it for all possible vulnerabilities.

A user under the alias @SemiDeFi argued that the “sloppy proxy setup” left the door open to exploitation, effectively holding Kinto responsible for the breach.

In response, Recuero told The Defiant that “the vulnerable proxy contracts were audited by 30 different auditors, part of the OpenZeppelin foundational contract library and had been used for 10 years until now.”

Founded in 2023 by Ramon Recuero, Víctor Sánchez, and Alan Keegan, Kinto is a compliance‑focused Layer 2 network built on Ethereum’s Arbitrum Nitro stack, featuring native KYC/AML enforcement.

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

Kinto TVS

According to data from L2Beat, Kinto held over $80 million in total secured value as of December 2024, but that figure has since declined, dropping to $16 million as of July 10.

In February 2025, Brevan Howard Digital’s Abu Dhabi arm deployed $20 million in assets on Kinto to participate in its institutional-grade DeFi ecosystem.

Source

Leave A Reply

Your email address will not be published.