• bitcoinBitcoin (BTC) $ 119,345.00
  • ethereumEthereum (ETH) $ 3,412.66
  • xrpXRP (XRP) $ 3.36
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 715.42
  • solanaSolana (SOL) $ 173.38
  • usd-coinUSDC (USDC) $ 0.999807
  • dogecoinDogecoin (DOGE) $ 0.211657
  • staked-etherLido Staked Ether (STETH) $ 3,406.41
  • tronTRON (TRX) $ 0.316032
  • cardanoCardano (ADA) $ 0.800764
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 119,187.00
  • hyperliquidHyperliquid (HYPE) $ 45.42
  • stellarStellar (XLM) $ 0.468620
  • wrapped-stethWrapped stETH (WSTETH) $ 4,101.92
  • suiSui (SUI) $ 3.96
  • chainlinkChainlink (LINK) $ 17.03
  • hedera-hashgraphHedera (HBAR) $ 0.251909
  • bitcoin-cashBitcoin Cash (BCH) $ 492.35
  • avalanche-2Avalanche (AVAX) $ 22.53
  • wrapped-eethWrapped eETH (WEETH) $ 3,658.03
  • shiba-inuShiba Inu (SHIB) $ 0.000014
  • leo-tokenLEO Token (LEO) $ 8.94
  • wethWETH (WETH) $ 3,413.88
  • the-open-networkToncoin (TON) $ 3.15
  • litecoinLitecoin (LTC) $ 101.44
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998104
  • usdsUSDS (USDS) $ 0.999900
  • whitebitWhiteBIT Coin (WBT) $ 45.28
  • polkadotPolkadot (DOT) $ 4.14
  • moneroMonero (XMR) $ 333.50
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 119,336.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • pepePepe (PEPE) $ 0.000013
  • bitget-tokenBitget Token (BGB) $ 4.74
  • uniswapUniswap (UNI) $ 8.80
  • aaveAave (AAVE) $ 316.50
  • bittensorBittensor (TAO) $ 422.00
  • crypto-com-chainCronos (CRO) $ 0.113708
  • daiDai (DAI) $ 1.00
  • nearNEAR Protocol (NEAR) $ 2.76
  • aptosAptos (APT) $ 5.17
  • pi-networkPi Network (PI) $ 0.436419
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
  • ondo-financeOndo (ONDO) $ 1.02
  • ethereum-classicEthereum Classic (ETC) $ 19.86
  • internet-computerInternet Computer (ICP) $ 5.55
  • jito-staked-solJito Staked SOL (JITOSOL) $ 210.71
  • okbOKB (OKB) $ 46.86
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • bonkBonk (BONK) $ 0.000035
  • algorandAlgorand (ALGO) $ 0.301928
  • mantleMantle (MNT) $ 0.776160
  • kaspaKaspa (KAS) $ 0.091375
  • ethenaEthena (ENA) $ 0.368481
  • arbitrumArbitrum (ARB) $ 0.438003
  • usd1-wlfiUSD1 (USD1) $ 0.999126
  • vechainVeChain (VET) $ 0.025451
  • cosmosCosmos Hub (ATOM) $ 4.76
  • render-tokenRender (RENDER) $ 4.04
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.231647
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,402.53
  • sei-networkSei (SEI) $ 0.344679
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.757740
  • official-trumpOfficial Trump (TRUMP) $ 9.80
  • fasttokenFasttoken (FTN) $ 4.52
  • gatechain-tokenGate (GT) $ 15.91
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.030008
  • worldcoin-wldWorldcoin (WLD) $ 1.08
  • filecoinFilecoin (FIL) $ 2.66
  • susdssUSDS (SUSDS) $ 1.06
  • pump-funPump.fun (PUMP) $ 0.005081
  • spx6900SPX6900 (SPX) $ 1.87
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 119,168.00
  • binance-staked-solBinance Staked SOL (BNSOL) $ 184.19
  • skySky (SKY) $ 0.078409
  • quant-networkQuant (QNT) $ 112.14
  • jupiter-exchange-solanaJupiter (JUP) $ 0.537464
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,574.64
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,888.97
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.90
  • kucoin-sharesKuCoin (KCS) $ 11.82
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • fartcoinFartcoin (FARTCOIN) $ 1.46
  • usdtbUSDtb (USDTB) $ 0.999722
  • flare-networksFlare (FLR) $ 0.021028
  • usdt0USDT0 (USDT0) $ 1.00
  • curve-dao-tokenCurve DAO (CRV) $ 1.01
  • story-2Story (IP) $ 4.60
  • celestiaCelestia (TIA) $ 1.90
  • injective-protocolInjective (INJ) $ 13.86
  • nexoNEXO (NEXO) $ 1.33
  • blockstackStacks (STX) $ 0.818396
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,586.68
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,658.93
  • xdce-crowd-saleXDC Network (XDC) $ 0.077939
  • flokiFLOKI (FLOKI) $ 0.000128
  • optimismOptimism (OP) $ 0.701401
  • sonic-3Sonic (S) $ 0.371694
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,689.93
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.78
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 1.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,594.64
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 119,031.00
  • dogwifcoindogwifhat (WIF) $ 1.04
  • immutable-xImmutable (IMX) $ 0.541743
  • the-graphThe Graph (GRT) $ 0.103023
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.997984
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 119,054.00
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 195.12
  • pax-goldPAX Gold (PAXG) $ 3,344.05
  • wbnbWrapped BNB (WBNB) $ 713.90
  • clbtcclBTC (CLBTC) $ 120,184.00
  • kaiaKaia (KAIA) $ 0.158042
  • lido-daoLido DAO (LDO) $ 1.01
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.11
  • ethereum-name-serviceEthereum Name Service (ENS) $ 27.05
  • iotaIOTA (IOTA) $ 0.228654
  • tokenize-xchangeTokenize Xchange (TKX) $ 11.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.58
  • vaultaVaulta (A) $ 0.558452
  • msolMarinade Staked SOL (MSOL) $ 227.18
  • paypal-usdPayPal USD (PYUSD) $ 0.999866
  • theta-tokenTheta Network (THETA) $ 0.840947
  • tether-goldTether Gold (XAUT) $ 3,337.76
  • galaGALA (GALA) $ 0.018160
  • jasmycoinJasmyCoin (JASMY) $ 0.016846
  • the-sandboxThe Sandbox (SAND) $ 0.315513
  • aerodrome-financeAerodrome Finance (AERO) $ 0.893893
  • raydiumRaydium (RAY) $ 2.86
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,656.99
  • super-oethSuper OETH (SUPEROETH) $ 3,413.64
  • zcashZcash (ZEC) $ 44.95
  • pyth-networkPyth Network (PYTH) $ 0.125964
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,616.99
  • ousgOUSG (OUSG) $ 111.82
  • saros-financeSaros (SAROS) $ 0.263987
  • bittorrentBitTorrent (BTT) $ 0.00000070
  • tezosTezos (XTZ) $ 0.647086
  • pendlePendle (PENDLE) $ 4.12
  • jito-governance-tokenJito (JTO) $ 1.91
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998517
  • heliumHelium (HNT) $ 3.60
  • morphoMorpho (MORPHO) $ 2.05
  • tbtctBTC (TBTC) $ 118,914.00
  • falcon-financeFalcon USD (USDF) $ 0.999872
  • chain-2Onyxcoin (XCN) $ 0.018745
  • flowFlow (FLOW) $ 0.400281
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • mog-coinMog Coin (MOG) $ 0.000002
  • walrus-2Walrus (WAL) $ 0.449874
  • decentralandDecentraland (MANA) $ 0.317332
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,413.79
  • memecoreMemeCore (M) $ 0.357581
  • based-brettBrett (BRETT) $ 0.059792
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 118,982.00
  • newton-projectAB (AB) $ 0.008643
  • usual-usdUsual USD (USD0) $ 0.997575
  • thorchainTHORChain (RUNE) $ 1.63
  • bitcoin-svBitcoin SV (BSV) $ 28.75
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 119,313.00
  • usddUSDD (USDD) $ 1.00
  • telcoinTelcoin (TEL) $ 0.006104
  • coredaoorgCore (CORE) $ 0.554840
  • wrapped-hypeWrapped HYPE (WHYPE) $ 45.31
  • ether-fiEther.fi (ETHFI) $ 1.32
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.211193
  • reserve-rights-tokenReserve Rights (RSR) $ 0.009231
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,415.17
  • stader-ethxStader ETHx (ETHX) $ 3,660.63
  • apecoinApeCoin (APE) $ 0.665374
  • beldexBeldex (BDX) $ 0.073831
  • ripple-usdRipple USD (RLUSD) $ 0.999833
  • savings-daiSavings Dai (SDAI) $ 1.16
  • conflux-tokenConflux (CFX) $ 0.099025
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,765.42
  • deepDeepBook (DEEP) $ 0.200189
  • aioz-networkAIOZ Network (AIOZ) $ 0.415651
  • true-usdTrueUSD (TUSD) $ 0.999104
  • starknetStarknet (STRK) $ 0.136894
  • build-onBUILDon (B) $ 0.487118
  • dydx-chaindYdX (DYDX) $ 0.642338
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.51
  • arweaveArweave (AR) $ 7.24
  • neoNEO (NEO) $ 6.65
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,378.33
  • syrupMaple Finance (SYRUP) $ 0.434298
  • kavaKava (KAVA) $ 0.429081
  • elrond-erd-2MultiversX (EGLD) $ 16.24
  • venomVenom (VENOM) $ 0.221422
  • compound-governance-tokenCompound (COMP) $ 49.18
  • apenftAPENFT (NFT) $ 0.00000046
  • 1inch1inch (1INCH) $ 0.327114
  • swethSwell Ethereum (SWETH) $ 3,736.16
  • dexeDeXe (DEXE) $ 7.86
  • staked-hypeStaked HYPE (STHYPE) $ 45.14
  • wormholeWormhole (W) $ 0.093733
  • ecasheCash (XEC) $ 0.000022
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.75
  • zksyncZKsync (ZK) $ 0.059439

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

0 6

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

The native token of Kinto, a compliance-focused Layer 2 network, crashed 90% on July 10 in under an hour after an attacker exploited its token minting mechanism and drained assets.

According to a July 11 X thread by Kinto co-founder Ramon Recuero, the incident appears to be tied to a broader vulnerability affecting thousands of contracts across DeFi built using the ERC1967Proxy standard, a common OpenZeppelin codebase that allows smart contracts to be upgraded without changing their address.

The vulnerability — first uncovered by blockchain security firm Venn Build alongside researchers from Dedaub, SEAL 911, and on-chain analyst pcaversaccio — revealed that thousands of contracts using the ERC1967Proxy standard were exposed to a novel exploit that let attackers insert malicious proxy admins while deceiving block explorers like Etherscan.

While the full list of affected projects remains unclear, Recuero noted that at least one — Berachain, a Layer 1 blockchain that had raised $100 million — was also exposed to the vulnerability but managed to prevent an attack in time.

Although a 36-hour “war room” effort helped secure many protocols before the vulnerability was widely exploited, Recuero said Kinto was not notified in time — even after other teams had been alerted — suggesting that the public disclosure of the vulnerability may have unintentionally triggered the attack on Kinto.

Recuero reiterated to The Defiant that the “Kinto network, assets and wallet are not affected and they are extremely safe,” adding that the Kinto smart contracts themselves were not breached. “This was a vulnerability in proxy contract ERC 1967 made worse by a bug in block explorers like Etherscan or Arbiscan,” he added.

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

Source: Arbiscan

By leveraging the backdoor, the attacker minted 110,000 K tokens and later used them to drain the Morpho Vault and a Uniswap v4 pool. Additional tokens were minted on demand, with funds bridged and swapped across protocols in what Recuero described as a “straightforward” attack.

“I know this is a really hard time for all of you. I am really sorry this has happened. No matter the circumstances, it is all my fault and I take responsibility. Me and the team will do anything in our power to come back from this,” Recuero wrote.

‘All Signs Point to Lazarus’

Amid the attack, Kinto’s native token K collapsed by 90% in under an hour, crashing from $7.69 to just $0.50 and wiping out nearly $13 million in market value in a matter of minutes, per data from CoinGecko.

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

Kinto Chart

Per Recuero, the team is working with authorities in the Cayman Islands and security groups, including ZeroShadow and Venn Build, to track the attacker. Speaking with The Defiant, Recuero said that “all signs point to Lazarus,” a North Korean state-sponsored hacking group that was also responsible for the $1.5 billion Bybit hack earlier this year.

If recovery efforts are successful, Kinto plans to roll back token balances to a snapshot block taken before the exploit, restore the Morpho vault and Uniswap liquidity, as well as relist K on centralized exchanges at the pre-hack price of $7.48 by July 31.

Recuero emphasized that the core Kinto network — including the wallet, bridge, and UI — remains unaffected. Following the hack, critics on social media panned Kinto’s reliance on the OpenZeppelin ERC1967Proxy pattern without fully auditing it for all possible vulnerabilities.

A user under the alias @SemiDeFi argued that the “sloppy proxy setup” left the door open to exploitation, effectively holding Kinto responsible for the breach.

In response, Recuero told The Defiant that “the vulnerable proxy contracts were audited by 30 different auditors, part of the OpenZeppelin foundational contract library and had been used for 10 years until now.”

Founded in 2023 by Ramon Recuero, Víctor Sánchez, and Alan Keegan, Kinto is a compliance‑focused Layer 2 network built on Ethereum’s Arbitrum Nitro stack, featuring native KYC/AML enforcement.

Kinto Token Tanks 90% as Backdoor Disclosure Lets Attacker Mint 110,000 Tokens and Drain Liquidity Pools

Kinto TVS

According to data from L2Beat, Kinto held over $80 million in total secured value as of December 2024, but that figure has since declined, dropping to $16 million as of July 10.

In February 2025, Brevan Howard Digital’s Abu Dhabi arm deployed $20 million in assets on Kinto to participate in its institutional-grade DeFi ecosystem.

Source

Leave A Reply

Your email address will not be published.