Bitcoin.com News
Powered by

Kasplex KRC-20 Indexer Signature Bypass Drains Two Token Pools

This weekend, an attacker pulled 186.4 million ZEAL and 54.4 billion NACHO from a Kaspa KRC-20 bridge wallet without possessing its private key, then recycled the tokens through layer two (L2) networks and sold them into liquidity pools. The strange part is that Kaspa itself wasn’t hacked. Five valid transactions fooled an off-chain indexer into recognizing transfers that nobody had actually signed, leaving bridged tokens unbacked and some pools stripped of as much as 99.6% of their KAS-side value.

WRITTEN BY
SHARE
Kasplex KRC-20 Indexer Signature Bypass Drains Two Token Pools

Key Takeaways

  • An attacker moved 54.4 billion NACHO without holding the bridge wallet’s private key.
  • Zealous Swap pools lost 94% to 99.6% of their KAS-side value after the forged transfers.
  • Igra paused key exits as KRC-20 operators prepare to patch and reindex the system.

Five Transactions, No Private Key

A private key is supposed to be the line between owning crypto and merely knowing where it sits. On Sept. 20, somebody found a way around that assumption for KRC-20 tokens without breaking Kaspa’s base chain at all.

The attacker moved 186,425,259 ZEAL and 54,397,983,246 NACHO from a bridge custody address, even though they didn’t control its private key. Those tokens were then sent back to the same custody address as ordinary bridge deposits, minted on Igra Labs’ EVM layer and Kasplex L2, and dumped into Zealous Swap liquidity pools.

By the time the dust settled, the attacker’s L2 ZEAL and NACHO balances were empty, while affected pools had lost between 94% and 99.6% of their KAS-side value. Here’s the catch: Kaspa’s layer one (L1) did exactly what it was supposed to do.

An Empty Signature That Still Passed

KRC-20 token ownership isn’t enforced directly by Kaspa consensus. Token instructions ride inside Kaspa transactions, while an off-chain Kasplex indexer reads those instructions and determines who owns what. Normally, a KRC-20 transfer contains a public key, token instructions, and a valid signature. The attacker kept that familiar structure but supplied an empty signature and added an OP_NOT after OP_ENDIF.

X screenshot
Image source: X

An empty signature causes OP_CHECKSIG to return false rather than kill the transaction outright. The extra OP_NOT flipped that result back to true, leaving Kaspa with a valid transaction. Nothing had gone off the rails at the consensus layer. The indexer was another story. It recognized the KRC-20 envelope but didn’t require the script to match the canonical format exactly. It consequently credited the forged transfer as legitimate. Kasplex’s own API even returned opAccept: 1 on the first forged ZEAL transaction.

Anyone Could Build the Forgery

The nastiest twist was that the attacker didn’t need to discover some hidden credential. A standard Kaspa address exposes the public key needed to construct the forged KRC-20 operation. That means moving the tokens to another address doesn’t solve the underlying problem. Until the indexer is patched and its history reindexed, the same flaw can theoretically be used against KRC-20 balances elsewhere.

Five transactions forged the ZEAL and NACHO transfers. Nine tiny one-unit withdrawals, by contrast, were genuinely signed by custody and appear to have been probes testing whether the exit route worked. Interestingly, the legitimate transactions were the tiny ones. The custody wallet held roughly 50 other KRC-20 tokens. The attacker chose two.

The Tokens Are Still There, but the Backing Isn’t

On Sunday morning, Igra said the custody wallet’s entire ZEAL and NACHO holdings were taken, leaving 97,651,212 ZEAL and 42,570,879,908 NACHO on the Layer 2 networks without full L1 backing. Another 4.5 billion NACHO remained with the attacker on L1.

Igra paused iKAS exits to Kaspa L1 and Hyperlane transfers, while users were warned against bridging KRC-20 tokens, buying ZEAL or NACHO on L2 decentralized exchanges (DEXs), or adding liquidity to affected pools. Native KAS, Kaspa consensus and Igra assets that weren’t bridged KRC-20 tokens were described as unaffected.

Fixing the software alone won’t clean up the mess. Zealous Swap says operators need to patch the indexer and reindex its history, rejecting empty signatures, malformed tags and scripts that continue beyond OP_ENDIF. Nacho the Kat, meanwhile, says the community intends to move toward KCC-20, a standard designed to put token rules into scripts enforced by the network itself.

The issue follows a slew of exploits, bugs, hacks, and data breaches over the last few weeks. On Saturday, Lightning Network custodial and non-custodial infrastructure provider Blink Wallet disclosed that a “few dozen” custodial accounts were drained. Cybersecurity company DCENT saw DCENT App Wallets siphoned this week as well. The timing comes as cybersecurity attacks have amplified, and some suspect AI is assisting this wave of exploiters.