KiloEX stolen $7.5 million: the market capitalization is not enough to pay, and the decentralized trust crisis erupts again?

By ChandlerZ, Foresight News
On April 15, the perpetual contract DEX KiloEx announced that its treasury had been attacked, and the situation has now been contained. KiloEX platform functionality has been suspended, and the team is working with security partners to track the flow of funds and is planning to launch a reward program. KiloEX is analyzing attack paths and affected assets while collaborating with ecosystem partners to try to recover funds. The full report will be released soon.
According to on-chain data, KiloEx addresses were stolen and lost around $7.4 million, including $3.3 million on the Base network, $3.1 million on the OpBnB network, and $1 million on the BNB Chain.
According to the market, KILO fell by more than 33% in 24 hours, the lowest price hit 0.033 USDT, and is currently reported at 0.0346 USDT.

According to Cyvers Alerts monitoring, the root cause of this hacking attack may be an access control flaw in price oracles.

Simply put, oracles were supposed to have a trusted actor update price information, but due to a lack of necessary permission restrictions, attackers were able to bypass the verification mechanism and arbitrarily tamper with asset prices to manipulate contract logic.
A preliminary analysis of one of the attack deals by PaiDun shows that this is a price prediction issue. Using this vulnerability, the attackers set the initial price of ETHUSD at 100 when opening a position, then immediately closed the position at an inflated ETHUSD price of 10,000. This transaction alone made a profit of about $3.12 million.
What is KiloEX?
KiloEX is a decentralized perpetual DEX that focuses on risk management, capital efficiency optimization, and ecosystem integration of LST tokens. KiloEX participated in BNB Chain's recent airdrop alliance campaign and the Renew Paradigm campaign on Manta Pacific to obtain stablecoin earnings by staking STONE. Additionally, KiloEX plans to launch hybrid treasury and hybrid margin trading features.
KiloEX itself is a Perp DEX with oractor-based pricing similar to GMX, and its core innovations are:
Stable coin neutral LP with built-in hedging
Copy Trading
The token economy side draws on today's advanced mechanisms
In terms of funding, KiloEX received investment from Binance Labs and was incubated during the sixth season of its MVB. Additionally, it has received investments from Foresight Ventures, Crescendo Ventures, Manta Network, 7UP DAO, Poolz Finance, GTS Ventures, and some angel investors.
KiloEX completed an exclusive TGE on Binance Wallet on March 27, attracting more than 70,000 users to participate in the launch, and the subscription amount exceeded 300 times.

According to data from its official website, KiloEX's total trading volume is $3.764 billion, and the current TVL is $33.84 million. According to DeFilLama data, the average daily trading volume of KiloEX is about 100 million US dollars, and the 7-day trading volume is about 500 million US dollars.
Trust crisis and community questioning revealed by security incidents
Although the project party immediately suspended the platform's functions and cooperated with security agencies to track the flow of funds, the actual loss of this attack was almost the same as its current market value of 7.3 million US dollars, and its fully diluted valuation was only about 34.49 million US dollars. The theft of large sums of money in a project of this size has undoubtedly dealt a heavy blow to users' confidence. What is even more worrisome is that up to now, the KiloEx team has not released any detailed statements about user compensation mechanisms, recovery plans, or team funding response plans, making the line between “hacker attacks” and “whether the project party is responsible” increasingly blurred.
On social platforms, many community members expressed strong dissatisfaction, believing that KiloEx lacked a clear commitment to protecting users' interests at a critical moment. On social platforms, some users accuse the project party of “running away from a bear market”, “high-profile fundraising and low-key aftercare,” etc., and are concerned about platform governance and financial transparency issues. The rapid shift in market sentiment also caused the KILO token to drop sharply by more than 30% in the short term.
Although the KiloEX incident is still in the early stages of incident handling, it has revealed the core contradiction of a new round of decentralized protocol “sustainability tests”: safety is not an ex post facto response after the project is launched, but rather a responsibility setting in the early stages of the architecture. In particular, KiloEX was incubated by Binance Labs and participated in airdrop alliance activities, and the foundation of trust between its core user base and platform is based on the perception of “official endorsement”. If the project party fails to come up with a clear plan of responsibility, regardless of whether the funds are recovered or not, the market's confidence in its “safety and control” will be fundamentally weakened, and may even affect the reputation of its ecological collaboration network.
Structural challenges due to frequent security incidents: not just KiloEX
At the same time, recent frequent negative security-related incidents have been revealed in the Web3 sector, further exacerbating the crisis of trust in the industry. Shortly after KiloEx was hacked, Odin.fun co-founder Bob Bodily also tweeted yesterday that his account is suspected to have been hacked, and the incident is still being processed. Earlier, some users reported that their linked account assets had been emptied and suspected to have been stolen. The extension of hacking attacks from project contracts to the founder's personal assets also shows that current attackers are no longer limited to technical vulnerabilities, but instead carry out systematic attacks through multi-dimensional permissions, social engineering, and even operational vulnerabilities. This places higher level of security governance requirements on the project party.
What is particularly alarming is that currently some small to medium DEXs use on-chain oracles for pricing, but there are still obvious shortcomings in access control, permission verification, and abnormal behavior warning. From the perspective of the Web3 industry as a whole, issues such as no compensation mechanisms, unbalanced allocation of authority, and a vacuum in token governance power are gradually becoming red line indicators in the community's next-generation investment evaluation logic. In the past, the market often paid more attention to product design and token return models, but with frequent security incidents and the tightening of regulatory scales, whether a project can establish a full-chain mechanism of “pre-protection+ in-case freeze+ post-payment” will become a core variable in whether users and capital will continue to support it.



