KyberSwap Loses $47 Million in Exploit Across Multiple Chains

KyberSwap Loses $47 Million in Exploit Across Multiple Chains

N
News Editor 01
2026-07-06 10:37:16
DeFi protocol KyberSwap suffered a $47 million exploit, draining funds from its Elastic Pools liquidity solution across Arbitrum, Optimism, Ethereum, Polygon, and Base. The attack involved flash loans and mathematical rounding errors. KNC token price plummeted.

去中心化交易所协议KyberSwap于今日遭遇重大安全事件,链上数据显示其Elastic Pools流动性解决方案中的约4700万美元资金被异常转移至单一钱包地址。此次攻击波及多条区块链,包括Arbitrum(2070万美元)Optimism(1500万美元)Ethereum(700万美元)Polygon(300万美元)以及Base(200万美元)。被盗资产涵盖多种形式的以太坊衍生代币(如包装代币和流动性质押代币)、Arbitrum(ARB)以及多种稳定币。

攻击手法疑似闪电贷与数学漏洞

此次事件首次由X平台用户Spreek披露,其发布的交易哈希显示资金正被持续抽走。链上数据分析师0xngmi(DefiLlama匿名员工)表示,这并非Kyber聚合器的授权问题,而是黑客直接攻击Kyber的流动性提供者(LP)池。目前KyberSwap的总锁仓价值(TVL)为7200万美元,但似乎未受影响。风投机构Cinneamhain Ventures的合伙人Adam Cochran进一步分析称,攻击利用了闪电贷与某种数学/舍入误差:每笔交易先从ETH余额开始,通过循环的铸造、赎回和兑换操作获利。

市场影响与代币价格暴跌

消息传出后,Kyber Network的原生代币Kyber Network Crystal(KNC)价格大幅下挫,跌幅一度超过15%。投资者对协议安全性产生严重担忧,抛售压力骤增。此次事件再次引发对DeFi协议安全性的广泛讨论,尤其是依赖复杂数学模型的集中流动性池产品。KyberSwap团队尚未发布官方声明,但社区正密切关注后续进展,包括黑客地址的动向以及团队是否计划采取补救措施。安全专家建议用户暂时避免与KyberSwap的Elastic Pools进行交互,并撤销相关合约授权以防范二次风险。

事件背景与启示

KyberSwap Elastic是一种允许流动性提供者选择自定义价格范围并自动复投收益的机制。此类设计虽能提升资本效率,但也增加了智能合约的复杂性和攻击面。本次攻击再次表明,闪电贷已成为DeFi攻击的常用工具,而细微的数学舍入问题足以导致数百万美元损失。截至发稿,被盗资金仍在黑客控制的地址中移动,尚未有追回迹象。KyberSwap事件是2023年DeFi领域又一起重大安全危机,提醒行业需持续加强审计与安全防护能力。

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.