ChainBleedv0.1 · open intel
← back to feed·FRONTEND2022-09-02 · 3y ago
Incident · SLOWMIST

Kyber Network

Malicious Code Injection Attack
Estimated loss
$265.0K
VERDICT —OUT OF SCOPE
Root cause is a frontend / UI hijack — users authorized the malicious transaction from a compromised site or DNS. On-chain contract was not the failure surface; pre-deployment audit cannot catch this class.
▰ METHOD
FRONTEND
FRONTEND
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

Decentralized liquidity protocol Kyber Network disclosed on Twitter that its users lost $265,000 in funds due to a front-end exploit. The vulnerability stems from malicious Google Tag Manager code in the KyberSwap website, where attackers target whale wallets and gain permission to transfer user funds by inserting fake approvals. Attack method (per SlowMist): Malicious Code Injection Attack. Reported loss: $ 265,000.

Primary source
https://cointelegraph.com/news/kyber-network-offers-bounty-following-265k-hack-of-decentralized-exchange
Sourced from
slowmist
Technical record
chain
protocol
Kyber Network
bug_class
frontend
date_occurred
2022-09-02
loss_usd
$265,000
source_id
sm:kyber-network::2022-09-02
Related — same bug class· frontend
2026-04-14
1mo ago
CowSwap
Supply-chain attack
frontend
$1.20M
OUT OF SCOPE
2025-12-12
6mo ago
ETH
ZEROBASE
Frontend Attack
frontend
$123.0K
OUT OF SCOPE
2025-06-23
11mo ago
CoinTelegraph
Frontend Attack
frontend
OUT OF SCOPE
2025-06-21
11mo ago
CoinMarketCap
Frontend Attack
frontend
$21.6K
OUT OF SCOPE
2024-08-20
1y ago
SOL
Parcl
Frontend Attack
frontend
OUT OF SCOPE
2023-09-19
2y ago
ETH
Balancer V2
Frontend Attack
frontend
$238.0K
OUT OF SCOPE
ChainBleed — live web3 threat intelligence