An analysis of the recent $46 million exploit that drained decentralized exchange KyberSwap has revealed remarkably sophisticated manipulation of the platform’s concentrated liquidity protocols.
According to Ambient Finance founder Doug Colkitt, who led the investigation, the attack relied on complicated calculations to create an “infinite money error.”
1/ I’ve completed a preliminary look at the Kyber exploit and think I now have a pretty good understanding of what happened.
This is by far the most complex and carefully crafted smart contract exploit I have ever seen…
— Doug Colkitt (@0xdoug) November 23, 2023
By subtly tricking KyberSwap’s smart contracts that power liquidity pools, the attacker bypassed controls that would have updated pool liquidity values when price limits were exceeded. This enabled double counting of existing liquidity while tricking contracts into overpaying on transactions – netting the extractor over $46 million in profits across multiple pools.
Also read: City of Lugano adds Polygon to its crypto payment app
Colkitt points out that the attack focused on the manner of KyberSwap’s special concentrated liquidity implementation. Therefore, other well-known platforms such as Uniswap and Ambient Finance remain protected from this specific vulnerability. Nevertheless, the exploit shows amazing precision and creativity.
The KyberSwap hack took a multi-stage approach using quick loans
In Colkitt’s analysis, transactions followed a multi-tiered approach that used quick loans to manipulate prices and liquidity. After the attacker drained the ETH/wstETH pool, he minted a small amount of liquidity within a certain price range where no other liquidity existed. This created a “clean canvas” for fine-tuned manipulation.
Two swaps then took place around this tightly controlled price, with no other liquidity available. The first swap moved the price just above the limit of the attacker’s liquidity range.
Also Read: JPMorgan Says Binance’s $4.3 Billion Settlement Overturns Cloud Over Crypto
On the second swap, the price moved back within the range, resulting in the liquidity value being updated correctly. However, because the first swap failed to remove liquidity when the threshold was exceeded, the second swap essentially counted liquidity twice. This allowed the attacker to withdraw more money than he deposited, draining the pool.
According to Colkitt, the quantity calculations used to predict whether price limits would be exceeded were slightly different from the pricing formulas.
Also Read: No Reason to Stop a Spot Bitcoin ETF, Says SEC Commissioner
By constructing exchange amounts with uncanny precision, the attacker was able to bypass border checks. In some cases, the differences amounted to as little as a 0.000000001% error rate, highlighting the complexity of the attack.
Colkitt points out that additional verification of whether swap steps remain within expected limits could have prevented the attack. Fortunately, implementing this fix to patch exploited smart contracts proves to be straightforward.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.