A security exploit on the Kaspa blockchain's KRC-20 token standard allowed an attacker to move approximately 186 million ZEAL and 54.4 billion NACHO tokens without possessing the bridge wallet's private key by exploiting a signature verification flaw in an off-chain indexer, draining liquidity pools. Security researcher Shai Wyborski claims he had warned the Kasplex team about exactly this type of trust vulnerability before mainnet launch but was ignored, defunded, and attacked by community members.