OceanAltOceanAlt

Security incident · 2022-09-01

KyberSwap Classic

According to the public DefiLlama incident dataset, KyberSwap Classic (Polygon) suffered a security incident on 2022-09-01, with about $265K reported lost.

Date2022-09-01
Reported loss$265K
ChainPolygon
Target typeDeFi Protocol
Technique classFrontend & Infrastructure
TechniqueCDN Compromise
Bridge incidentNo
Within 2022#127 by loss that year, 0.0% of all reported losses that year

How this kind of attack works

The website, domain or hosting was hijacked, and users signed transactions that sent funds to the attacker from a page that looked normal.

Would a pre-payment check have helped

Partly applies

When a frontend or domain is hijacked the payee address is freshly generated and on no list, but the hijacked host is often already in public phishing feeds, so endpoint screening catches part of this class.

Other incidents with the same technique

Sources

This page restates public reports and is not OceanAlt's judgment of any party. To report an error, email business@oceanalt.com; we review within 48 hours.

← Back to incidents