KiiChain Security Incident: What Happened and What Comes Next

KiiChain Security Incident: How the Staking Exploit Unfolded KiiChain Security Incident published its full incident report, and it fills in a lot of the picture that was missing when the network first went dark. In short, someone found a way to trick the chain's staking system into thinking they had far more money than they actually did and then quietly walked off with roughly 148 million KII across 18 separate rounds before the team caught on and pulled the plug. The good news buried in all of this is that most of the damage is still fixable. Here's how it played out, told plainly and in order. The Short Version On 22 August 2026, an attacker found a weak spot in how KiiChain's system tracks balances between its Cosmos side and its Ethereum-style (EVM) side. Source: KiiChainio on X They exploited it 18 times, hitting a different wallet each time, before the KiiChain team spotted the unusual activity and froze the entire chain at block 9,355,723—22:50:58 UTC. That halt is what stopped things from getting worse. The team has since figured out exactly how the attack worked, tested a fix, and confirmed it closes the gap. And importantly, this wasn't a bug KiiChain's own developers wrote—it lives inside a piece of shared code called the Cosmos-EVM module, used by several different blockchains. That's also why two other chains, Mantra and TAC, got hit by nearly the identical trick that same week. Source: Document of KiiChain Security Incident How the Attacker Actually Pulled It Off This is the clever—and frustrating—part. Normally, there's no way to exploit this bug from a regular wallet, because the system simply won't let you "delegate" (stake) more money than you actually have. So the attacker had to build a workaround: They calculated, in advance, what address a new smart contract would be deployed to Before deploying anything, they turned that future address into a special "vesting" account Then they deployed their exploit contract onto that same address, so the contract inherited the vesting account's status From there, they delegated one wei (a tiny fraction of a token) more than the contract could actually afford That tiny overreach triggered an underflow—basically, the system's math broke and wrapped around to a nonsensical, enormous number instead of throwing an error They then chained two more bugs on top of that to pull real funds from victim wallets onto their own contract One reassuring detail: this couldn't be used to print money out of thin air. Every single drain was capped at whatever the victim's real balance actually was.
عنوان اصلی (انگلیسی): KiiChain Security Incident: What Happened and What Comes Next
مشاهدهی خبر کامل در منبع ↗ بازگشت به Hyperlaneاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.