KiloEx · 44

KiloEX launches a unified 90% strong flat line mechanism to provide the industry's latest settlement point for highly leveraged transactions

Comparatively, in the recent incident where nearly 120,000 people were out of positions due to sharp fluctuations in Bitcoin, the KiloEx platform observed a counterintuitive phenomenon: over 70% of liquidations came from multiple orders, and most were not due to the end of the trend, but were knocked out by short-term price shocks. This reveals the core contradiction of high-leverage trading: the real source of risk is often not misjudgment of direction, but rather that risk control models do not provide sufficient buffer space for market noise. In this case, the decentralized derivatives trading platform KiloEX officially launched its core risk control mechanism to unify the 90% strong flat line. This mechanism breaks industry practice, does not strengthen points ahead of time as leverage multiples increase, and insists on providing a fixed loss threshold of -90% for all positions. According to comparison, under 100x leverage, KiloEX users have a strong flat buffer of -90%, the living space far exceeds the -50% design of a mainstream platform, and the resistance to fluctuation is nearly doubled. This move aims to address the core pain point of highly leveraged traders being liquidated prematurely due to instantaneous market fluctuations from the bottom of risk control.

270d ago

KiloEX announced the total destruction of over 13.41 million KILO tokens

According to Twitter, KiloEx, a decentralized derivatives trading platform invested by YZI Labs (formerly Binance Labs), recently carried out another token burn through the xKilo attribution mechanism. The total number of kilos destroyed has reached 13,418,836 kilos. Of these, the xKilo ownership mechanism destroyed a total of 4,809,594 tokens, and 8,609,242 unclaimed tokens were destroyed by airdrop. KiloEX directly transforms user redemption choices into deflationary forces through a custom attribution and destruction mechanism: when users redeem xKilo early, the unredeemed portion is automatically destroyed. At the same time, users can get an annualized return of up to 31.65% by staking xKilo. The platform now supports multi-asset trading such as contracts, spot, US stocks, and foreign exchange, focusing on CEX-level trading experience and low fees, injecting new competitive vitality into the decentralized derivatives circuit.

310d ago
Produced by Slow Mist | Blockchain Security and Anti-Money Laundering Report for the 1st Half of 2025

Produced by Slow Mist | Blockchain Security and Anti-Money Laundering Report for the 1st Half of 2025

Due to space limitations, this article lists only the key content of the analysis report. The full content can be downloaded at the following link. Chinese: https://www.slowmist.com/report/SlowMist-first-half-of-the-2025-report(CN).pdf英文:https://www.slowmist.com/report/SlowMist-first-half-of-the-2025-report(EN).pdf一、前言2025 In the first half of the year, while the blockchain industry developed rapidly, It also continues to be pressured by increasingly complex security threats and compliance challenges. On the one hand, hacker attacks continue to be active. APT organizations' attack methods tend to be modular and systematic, and phishing and social worker attacks are rampant, causing major asset losses and a crisis of user trust. On the other hand, global regulations are evolving at an accelerated pace, and governments and international organizations have frequently introduced new regulations on anti-money laundering, sanctions, and investor protection. It is worth noting that stablecoins are gradually evolving into a key infrastructure connecting traditional finance with on-chain finance, and the world's major financial institutions and leading crypto platforms are speeding up their stablecoin strategic layout. In addition to this, the money transfer model for black production continues to evolve, on-chain tracking technology and intelligence collaboration mechanisms also continue to evolve, regulators are cooperating more closely with leading platforms, and cases of fund freezing and recovery have increased markedly, forming a stronger deterrent to on-chain crime and illegal funds. As a pioneer in blockchain security, SlowMist (SlowMist) continues to be deeply involved in threat intelligence, attack monitoring, traceability, and compliance support. In this context, this report focuses on major security events in the first half of 2025, global regulatory developments, and on-chain anti-money laundering trends. It is hoped that this report will provide timely, systematic, and insightful safety compliance references for industry practitioners, safety researchers, and compliance officers to enhance their ability to identify, respond and predict risks. 2. Blockchain Security Situation Security Incident Review In the first half of 2025, the blockchain sector still faced serious security challenges. According to incomplete statistics from the SlowMist (SlowMist) blockchain hacked event archive (SlowMist Hacked), 121 security incidents occurred in the first half of the year, causing losses of approximately US$2.373 billion. Compared to the first half of 2024 (total 223 cases, loss of approximately US$1.43 billion), although the number of incidents decreased, the overall amount of losses increased by about 65.94% year over year. Note: The data in this report is based on the token price at the time of the incident. Actual losses should be higher than the statistical results due to factors such as currency price fluctuations, some undisclosed events, and losses of ordinary users not included in the statistics. (https://hacked.slowmist.io/)1. From an ecological perspective, Ethereum is still the hardest hit area for attacks, with related losses of approximately US$38.59 million. Next was Solana, which lost around $5.8 million, and BSC, which lost around $5.49 million. 2. In terms of project types, DeFi is the type most commonly attacked. There were 92 DeFi-type security incidents in the first half of 2025, accounting for 76.03% of the total number of incidents (121), with losses as high as US$470 million. Compared with the first half of 2024 (158 cases in total, losses of about US$659 million), losses decreased by 28.67% year over year. Next, there were 11 incidents involving exchange platforms, but the amount of losses was as high as US$1,883 million. Among them, Bybit was the most severely attacked, and a single incident caused a loss of approximately US$1.46 billion. 3. Judging from the scale of losses, there were 2 incidents in the first half of the year that lost more than 100 million US dollars, and the top ten attacks totaled 2,018 billion US dollars. 4. Judging from the cause of the attack, the number of security incidents caused by hacked accounts was the highest, reaching 42. Next, there were 35 security incidents due to contract flaws. In addition to directly attacking projects or agreements, fraudulent “tricks” surrounding ordinary users are also rapidly evolving. This section highlights a few typical or new types of fraud worth focusing on in the first half of 2025. 1. Phishing attacks such as EIP-7702 take advantage of changes in the delegation mechanism brought about by EIP-7702 — the user's EOA address can be authorized to a contract, making it have the characteristics of this contract...

416d ago慢雾科技#Slow Mist Technology

KiloEX transaction fee adjusted from 0.07% to 0.05%

In comparison, KiloEx posted an article on the X platform stating that it will implement a transaction fee adjustment for all users from 0.07% to 0.05%. The adjustment will take effect at 12:10 (UTC) on May 12, 2025. This rate will initially provide a 2-month trial period to evaluate the enhanced features of the platform.

467d ago
Monthly Update | Web3 security incidents cost around $26.4 million in total

Monthly Update | Web3 security incidents cost around $26.4 million in total

Overview In April 2025, the total cost of Web3 security incidents was approximately $26.4 million. Among them, according to statistics from the Slow Mist Blockchain Hacked Archive (https://hacked.slowmist.io), there were 18 hacked incidents, resulting in losses of about US$21.11 million, and US$17.89 million being frozen or returned. The causes of the incident involved contract breaches, social engineering, internal fraud, and private key leaks. Furthermore, according to Web3 anti-fraud platform Scam Sniffer, there were 7,565 victims of phishing incidents this month, with losses amounting to $5.29 million. (https://dune.com/scam-sniffer/april-2025-scam-sniffer-scam-report)安全大事件KiloEx2025 On April 15, 2004, KiloEx, a decentralized perpetual contract trading platform, was attacked, causing losses of approximately $8.44 million. After the incident occurred, SlowMist (SlowMist) immediately intervened in the analysis and issued a safety reminder. Fortunately, thanks to the active response of the project party and the collaboration of various parties such as SlowMist (SlowMist), all stolen assets were successfully recovered over a period of 3.5 days, and the incident was successfully resolved. According to KiloEx's analysis report, the attack stemmed from a flaw in the contract permission verification mechanism. The TrustedForwarder contract inherits OpenZeppelin's MinimalForwarderUpgradeable contract, where the execute method is not overridden in TrustedForwarder and is a method that can be accessed without permission. Attackers use this vulnerability to directly call OpenZeppelin's minimalForwarderUpgradeable primitive execute method. The request content of the execute method is to call the delegateExecutePositions function. In the delegateExecutePositions method, only msg.sender == trustedForwarder was verified, and it did not verify whether the actual initiator is a keeper, so the attackers bypass permission verification. The attackers first use a very low price to open a position in a transaction, and then close the position at a higher price. This completes the attack. (On April 26, https://x.com/SlowMist_Team/status/1911991384254402737)Loopscale2025, Loopscale, a modular DeFi lending marketplace built on Solana, was attacked, resulting in the theft of around 5.7 million USDC and 1200 SOL, or about 12% of the platform's total capital. The root cause of this attack has been confirmed. Loopscale has isolated issues with the RateX-based collateral pricing mechanism. On April 29, according to Loopscale's official Twitter account, after successful negotiations, all 5,726,725 USDC and 1,211 SOL stolen on April 26 have been returned, and users' deposits have not been lost. (https://x.com/LoopscaleLabs/status/1917212052029931624)ZKsync据 Incident analysis report published by zkSync (https://zksync.mirror.xyz/W5vPDZqEqf2NuwQ5x7SyFnIxqqpE1szAFD69iaaBFnI),4 On January 13, a hacked administrator account was minted for zkSync 2024 Remaining tokens that have not yet been claimed in the ZK token Merkle distribution agreement that was airdropped on June 17. The attackers successfully took control of 111,881,122 ZK tokens (the market capitalization was around $5 million at the time). This time...

478d ago慢雾科技#Slow Mist Technology

The DeFi platform was hacked in April and lost 92 million US dollars, and the cumulative losses this year have exceeded 1.7 billion US dollars

According to the Immunefi report, the April 2025 crypto hacking incident caused the DeFi platform to lose $92 million, up 124% from $41 million in March. Among them, the open source platform UPCX was attacked by over $70 million, the biggest incident of the month; kiloEX was attacked by hackers and lost 7.5 million US dollars, and the hacker subsequently returned all funds. The report stated that all attacks in April targeted DeFi platforms, and centralized exchanges did not report any security incidents. By the end of April, the cumulative losses from crypto hacking attacks in 2025 had reached $1.7 billion, more than the total amount of $1.49 billion for the full year of 2024. Immunefi founder Mitchell Amador said that state-sponsored hacking groups posed a major threat, and recommended that the agreement adopt a “zero trust” architecture to strengthen security protection.

479d ago

KiloEX announced a restart, and the platform has returned to normal operation

According to official news, the decentralized derivatives trading platform KiloEx announced today that it has completed security audits and system repairs, and that the platform has now officially resumed operation. Previously, KiloEX suspended its service due to a hacker attack, and the team then quickly initiated an emergency response mechanism, cooperated with a third-party security agency to launch an investigation, and recover all funds. Officials said that in the future, they will continue to strengthen security construction, further strengthen the platform security protection system, and ensure users' asset safety and transaction experience. In addition, KiloEX has announced solutions for affected users, which will fully reimburse traders affected by this incident for new position losses, and will begin a 30-day 10% additional yield pledge bonus campaign and the first transaction bonus campaign after the platform is restarted.

485d ago

KiloEX announced a compensation plan for hacking incidents. Traders and staking users will receive compensation and revenue bonuses

In comparison, according to KiloEx, the platform will introduce differentiated compensation measures for affected users in response to the security incident between 18:27 and 19:40 UTC on April 14. Traders will receive full compensation due to reduced profits or increased losses during the downtime period. It is recommended to close positions as soon as the platform is restored; Hybrid Vault guarantees that users' principal and earnings are not lost, and can participate in a 10% annualized additional income campaign from April 24 to May 24; VIP users will receive a level +1 reward and a 30-day VIP protection period.

485d ago
SlowMist (SlowMist) helps KiloEX recover all stolen funds, incident review

SlowMist (SlowMist) helps KiloEX recover all stolen funds, incident review

2025 年 4 月 15 日,去中心化永续合约交易平台 KiloEx 遭遇黑客攻击,造成约 844 万美元的损失。事件发生后,慢雾(SlowMist) 第一时间介入分析,并发布安全提醒。幸运的是,在项目方的积极应对和慢雾(SlowMist) 等多方协作下,历时 3.5 天,最终成功追回了全部被盗资产,事件得以圆满解决。(https://x.com/SlowMist_Team/status/1911991384254402737)事件回顾漏洞原因分析据 KiloEx 的分析报告,此次攻击源于合约权限验证机制的缺陷。TrustedForwarder 合约继承了 OpenZeppelin 的 MinimalForwarderUpgradeable 合约,其中 execute 方法没有在 TrustedForwarder 进行 override,是一个不需要权限就可以访问的方法。 攻击者利用这一漏洞,直接调用 OpenZeppelin 的 MinimalForwarderUpgradeable 原始 execute 方法。execute 方法的请求内容是调用 delegateExecutePositions 这个 function,在 delegateExecutePositions 方法中只验证了 msg.sender == trustedForwarder,并没有验证真正的发起者是否是 keeper,从而攻击者绕开了权限验证,攻击者在一笔交易中首先使用极低的价格开仓,再以较高的价格的平仓,从而完成攻击。攻击时间线此次攻击链上痕迹清晰,关键时间节点如下:Apr-13-2025 23:31:59 UTC黑客地址 0x00faC92881556A90FdB19eAe9F23640B95B4bcBd 从 Tornado Cash 提款 1 ETH 作为启动资金。(https://etherscan.io/tx/0xa0fa4ab8ded0c07085d244e1981919b440f78b609e1cf8d7f8ee32d358dfdf46)Apr-13-2025 23:39:11 ~ Apr-14-2025 01:21:36 UTC黑客使用多个 DeFi Protocol 和 Bridge 将从 Tornado Cash 提款的 ETH 拆分转移到 opBNB、Base、BSC、Taiko、B2、Manta 链,作为后续部署攻击合约的 Gas fee。(https://dashboard.misttrack.io/address/ETH/0x00faC92881556A90FdB19eAe9F23640B95B4bcBd)Apr-14-2025 18:27:43 ~ 19:36:49 UTC黑客在 opBNB、Base、BSC、Taiko、B2、Manta 链部署攻击合约。(https://opbnbscan.com/tx/0x657ab20a838043e36ab372a122804e07dbeca522b989899e27dee54b4c3f2971)Apr-14-2025 18:52:27 ~ 19:40:49 UTC黑客在 opBNB、Base、BSC、Taiko、B2、Manta 链调用攻击合约发起攻击。(https://opbnbscan.com/tx/0x79eb28ae21698733048e2dae9f9fe3d913396dc9d93a0e30d659df6065127964)应急响应事件发生后,依托于慢...

486d ago慢雾科技#Slow Mist Technology