KiloEx Hacker Returns Entire $7.5M Four Days After Exploit
In a surprising turn of events, the hacker behind the $7.5 million exploit of decentralized exchange KiloEx has returned the entire sum just four days after the initial attack. On April 14, KiloEx suspended its perpetual...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
In a surprising turn of events, the hacker behind the $7.5 million exploit of decentralized exchange KiloEx has returned the entire sum just four days after the initial attack.
On April 14, KiloEx suspended its perpetual futures trading platform following a severe security breach that resulted in attackers draining $7.5 million worth of cryptocurrency assets across the Base, opBNB, and BNB Chain networks.
The exploit was traced to a flaw in KiloEx’s price oracle system, which allowed the attacker to manipulate the ETH/USD price feed.
This enabled the attacker to open positions at absurdly low prices and close them at vastly inflated values, profiting millions in single transactions.
Approximately $3.3 million was drained from Base, $3.1 million from opBNB, and $1 million from BSC.
The breach prompted an immediate shutdown of the platform and an urgent call to arms.
KiloEx mobilized a broad coalition of cybersecurity experts and blockchain partners, including SlowMist, BlockSec, SEAL 911, Manta Network, BNB Chain, and many others.
They began forensic investigations to trace the stolen funds and identify the attacker.
In the days following the attack, PeckShield identified associated wallet addresses, and on-chain activity showed that portions of the funds, approximately $5.5 million, were being returned, suggesting that negotiations were underway.
#PeckShieldAlert #KiloEx exploiter -labeled addresses have returned ~$5.5M worth of cryptos to #KiloEx pic.twitter.com/snvitWs7ia
— PeckShieldAlert (@PeckShieldAlert) April 18, 2025 The Ultimatum That Changed the CourseKiloEx’s swift response and aggressive public strategy likely played a crucial role in the resolution.
Just hours after confirming the exploit, the platform issued a stern ultimatum to the attacker via X (formerly Twitter), presenting a choice: return 90% of the funds within 72 hours and receive a 10% white-hat bounty, or face relentless legal and forensic pursuit.
The DEX revealed that it had already identified blockchain addresses linked to the attacker and placed them under constant surveillance.
These could be frozen at any moment, KiloEx warned, as they were actively working with exchanges and security partners.
The hacker was offered safe passage if they complied, and KiloEx pledged not to pursue further legal action.
Should they fail to respond, the matter would escalate into a full-blown criminal case, backed by law enforcement, cybersecurity firms, and international exchange networks.
Apparently, the attacker decided the risk wasn’t worth the reward.
By April 18, the full $7.5 million had been returned. KiloEx issued a statement expressing relief and gratitude, confirming that the matter was resolved.
Dear Community,
We are pleased to announce that we have successful recovery of all stolen funds related to the recent security incident. This outcome underscores our commitment to protecting user assets and fostering a secure ecosystem.
1. Case Resolution Progress
– The legal…
They also upheld their offer and awarded the attacker a 10% white-hat bounty of $750,000, thereby turning an exploiter into a contributor in a gesture of ethical closure.
Recurring Oracle Exploits and White Hat ResolutionsThe KiloEx saga is the latest in a growing pattern of DeFi platforms falling victim to oracle-based price manipulation exploits.
These attacks target the very system that delivers real-world data to smart contracts, and their manipulation can have devastating consequences.
Similarly to this KiloEx incident, on October 25 last year, a hacker returned $6.1 million to a U.S. government wallet after initially stealing over $20 million in various cryptocurrencies.
$6.1M in stolen crypto is back in a US government wallet. What’s the significance of this recovery? @OnchainLens dives into the details.#CryptoHack #BlockchainSecurityhttps://t.co/p8JOmwUq4p
— Cryptonews.com (@cryptonews) October 25, 2024That breach, although different in scale and nature, similarly concluded with the attacker voluntarily returning assets, likely under external pressure.
In the case of KiloEx, the collaborative response from blockchain partners, law enforcement, and cybersecurity professionals helped ensure a swift outcome.
The platform publicly acknowledged a long list of contributors, including SlowMist, SEAL 911, Binance, Sherlock, and dozens of others.
With user funds fully restored, KiloEx now turns its attention to rebuilding community trust.
The platform has pledged transparency and will share updates on the legal withdrawal process as it winds down the incident.
Legal proceedings are being finalized with the support of judicial authorities and third-party experts.
The post KiloEx Hacker Returns Entire $7.5M Four Days After Exploit appeared first on Cryptonews.
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CryptonewsRelated market context
CZ Warns Bitcoin Holders After $70 Million Wallet Exploit: 'Nothing Is 100%'
The Binance founder urged holders to spread funds across multiple wallets as Galaxy Research put the toll from the Coldcard exploi...
Binance’s CZ warns users to split funds after $70M Coldcard exploit
The Coldcard exploit highlights the critical need for diversified security strategies in crypto storage, balancing complexity with...
Binance founder CZ calls for wallet diversification after $70 million Coldcard exploit
Binance founder Changpeng Zhao says hardware wallets can still have bugs and suggests spreading funds across multiple wallets afte...
Coldcard Firmware Flaw Lets Attacker Drain 594 Bitcoin From Users
An attacker swept roughly 594 bitcoin, worth about $38 million, out of around 500 separate wallets between 01:31 and 01:56 UTC on...
Lite Strategy Funds $5.4M Buyback With Litecoin Sales And Covered Calls
Lite Strategy has repurchased 4.9 million shares for $5.4 million, using Litecoin treasury activity and covered-call premiums to f...
Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen
Bitcoin Magazine Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen The popular Bitcoin hardware wallet...