Security Incident Overview
A significant security incident unfolded over the weekend when an attacker executed a complex operation involving the theft of 186.4 million ZEAL and 54.4 billion NACHO tokens from a bridge wallet associated with the Kaspa KRC-20 network. Intriguingly, this operation did not breach the core security of the Kaspa system itself. Instead, it exploited vulnerabilities in an off-chain indexer, enabling the attacker to initiate five legitimate-looking transactions that neither required valid signatures nor any real blockchain manipulation.
Method of Attack
The malicious actor successfully withdrew the tokens using methods that avoided detection by the standard verification processes. After facilitating transfers from a custody address to mint new tokens on Igra Labs’ EVM layer and Kasplex Layer 2 (L2), the attacker deposited these tokens into various liquidity pools. The impact was staggering, as numerous pools suffered catastrophic losses of between 94% and 99.6% of their KAS-side value while the attacker ultimately depleted their own L2 balances of ZEAL and NACHO.
Understanding Token Ownership
To understand the unfolding chaos, one must recognize that ownership of KRC-20 tokens does not rely solely on direct consensus within the Kaspa network. Instead, the delineation of token ownership operates through off-chain processes conducted by the Kasplex indexer, which relies on specific formats in token transactions. Typical KRC-20 transactions involve public keys, token instructions, and valid signatures. The perpetrator cleverly manipulated this structure by submitting an empty signature and adding a specific command that coerced the system into accepting the transactions as valid rather than rejecting them.
Concerns and Implications
In a curious twist, it became apparent that the attacker did not have to breach any secured credentials or exploit sophisticated hacking techniques. Any standard Kaspa address discloses the necessary public key, allowing the attacker to seed their forgery. This raises substantial concerns about the integrity of KRC-20 tokens, as the flaw may extend into other balances, putting the entire KRC-20 ecosystem at risk until the indexer’s processes are corrected.
Details of the Breach
The origin of this breach can be traced to five fraudulent transactions and a handful of genuine one-unit withdrawals that appeared to be tests to ensure the exploit was viable. The custody wallet previously held other KRC-20 tokens, yet the attacker only targeted ZEAL and NACHO. Following the incident, Igra announced that only 97,651,212 ZEAL and approximately 42.5 billion NACHO remained as uncollateralized assets across L2 networks, with an additional 4.5 billion NACHO still retained by the attacker on Layer 1.
Response and Future Actions
In response to the grave situation, Igra has temporarily suspended iKAS withdrawals to Kaspa Layer 1 and Hyperlane transactions, advising users to refrain from bridging KRC-20 tokens or trading on decentralized exchanges involving these tokens. Fortunately, native KAS and other Igra assets that are not derived from bridged KRC-20 tokens were confirmed to be secure.
Addressing this vulnerability will require more than just a software patch; the Zealous Swap platform has emphasized the need to enhance the indexer, ensuring the rejection of invalid signatures and other problematic scripts. Meanwhile, the community is advocating for an upgrade to a new KCC-20 standard, intended to strengthen token rules and facilitate network-enforced governance.
Broader Context
This incident is part of a larger pattern of increasing vulnerabilities in cryptocurrency systems, following a series of hacks and exploits that have plagued various platforms recently. Observers have speculated that the rising sophistication of cyberattacks could be related to advancements in artificial intelligence which may be aiding malicious actors.
In addition to this event, Blink Wallet, a platform for Lightning Network payments, revealed recently that several custodial accounts had been compromised, further highlighting the urgent need for enhanced security measures across all crypto-related infrastructures.