$4M ‘exit scam’ suspected as Kokomo Finance flies off radar, token plunges

0

[ad_1]

Optimism-based lending protocol Kokomo Finance has been suspected of a $4 million “exit scam” that has seen user funds plucked out from the platform via a smart contract loophole.

Blockchain security firm CertiK alerted its followers to the “exit scam” in a March 26 Twitter post, noting that the Kokomo Finance (KOKO) token has plummeted 95% in value in a matter of minutes.

CertiK also noted that Kokomo Finance removed all social media accounts immediately following the alleged rug pull too.

Kokomo Finance has either deactivated or deleted its Twitter account. Source: Twitter

CertiK said the deployer of KOKO attacked the smart contract code of a wrapped Bitcoin token, cBTC, by resetting the reward speed and pausing the borrow function.

After that, an address beginning with “0x5a2d..” approved the new cBTC smart contract to spend over 7000 Sonne Wrapped Bitcoin (So-WBTC).

The attacker then called another command to swap the So-WBTC to the 0x5a2d address, which produced a $4 million profit, according to the security firm.

Changes to the smart contract code of the KOKO began at about 9 am UTC on March 26. Source: Optimistic Etherscan

A CertiK spokesperson told Cointelegraph that it was the largest “incident” that they’ve detected on Optimism.

Kokomo Finance is an open-source and non-custodial lending protocol on Optimism, where investors could trade for wBTC, Ether (ETH), Tether (USDT), USD Coin (USDC) and DAI.

Kokomo Finance rose up the ranks quickly in recent days, with blockchain data platforms like CoinGecko and DefiLlama officially tracking it shortly after Kokomo Finance went live on Optimism on March 25.

The price of Kokomo Finance token, KOKO fell over 97% at about 4:10pm UTC time on March 26. Source: CoinGecko

Recent screenshots reveal that more than $2 million was locked into Kokomo Finance prior to it falling more than 97%.

Over 72% of the total value locked in the Kokomo Finance protocol came in the form of wrapped Bitcoin, according to data from DefiLlama.

Cointelegraph attempted to access all social media and blog websites listed on Kokomo Finance’s Linktree page, however, all of these links now lead to some form of an error page, suggesting the page has been removed.

Related: 7 DeFi protocol hacks in Feb see $21 million in funds stolen: DefiLlama

Cointelegraph came across Kokomo Finance’s smart contract audit, which was reviewed and shared by 0xGuard earlier in March.

While most aspects of the audit were passed, “typographical errors” were found and the owner of the KOKO token was found to have a one-time ability to 45% of the maximum supply to an arbitrary address.

Kokomo did not pass all aspects of its smart contract audit, which was reviewed by 0xGuard in March. Source: GitHub

Cointelegraph reached out to 0xGuard for comment but did not receive an immediate response.

Magazine: Should crypto projects ever negotiate with hackers? Probably



[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 62,398.00
ethereum
Ethereum (ETH) $ 1,629.63
tether
Tether (USDT) $ 0.999519
bnb
BNB (BNB) $ 590.87
usd-coin
USDC (USDC) $ 0.999699
xrp
XRP (XRP) $ 1.14
solana
Solana (SOL) $ 64.73
tron
TRON (TRX) $ 0.328960
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05
hyperliquid
Hyperliquid (HYPE) $ 58.85
dogecoin
Dogecoin (DOGE) $ 0.084562
usds
USDS (USDS) $ 0.999660
leo-token
LEO Token (LEO) $ 9.58
rain
Rain (RAIN) $ 0.013416
stellar
Stellar (XLM) $ 0.205435
wrapped-steth
Wrapped stETH (WSTETH) $ 2,779.67
zcash
Zcash (ZEC) $ 393.42
canton-network
Canton (CC) $ 0.167307
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 76,243.00
cardano
Cardano (ADA) $ 0.164582
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
monero
Monero (XMR) $ 306.49
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 2,466.93
chainlink
Chainlink (LINK) $ 7.75
whitebit
WhiteBIT Coin (WBT) $ 44.59
usd1-wlfi
USD1 (USD1) $ 0.999614
wrapped-eeth
Wrapped eETH (WEETH) $ 2,465.31
the-open-network
Toncoin (TON) $ 1.71
susds
sUSDS (SUSDS) $ 1.08
bitcoin-cash
Bitcoin Cash (BCH) $ 225.80
ethena-usde
Ethena USDe (USDE) $ 0.999280
dai
Dai (DAI) $ 0.999623
memecore
MemeCore (M) $ 3.22
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 76,366.00
lab
LAB (LAB) $ 13.07
hedera-hashgraph
Hedera (HBAR) $ 0.081756
litecoin
Litecoin (LTC) $ 42.19
weth
WETH (WETH) $ 2,268.37
sui
Sui (SUI) $ 0.754334
avalanche-2
Avalanche (AVAX) $ 6.75
paypal-usd
PayPal USD (PYUSD) $ 0.999796
usdt0
USDT0 (USDT0) $ 0.998824
hashnote-usyc
Circle USYC (USYC) $ 1.13
shiba-inu
Shiba Inu (SHIB) $ 0.000005
crypto-com-chain
Cronos (CRO) $ 0.060099
tether-gold
Tether Gold (XAUT) $ 4,305.72
global-dollar
Global Dollar (USDG) $ 1.00
near
NEAR Protocol (NEAR) $ 1.90
blackrock-usd-institutional-digital-liquidity-fund
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
Shares