# bridge exploit — X 热门讨论 (2026-09-22 03:17 UTC)
## @ScapeSquad (s c a p e . 𐤊) · 09-21 23:34 · ♥26 ↻4 💬4 🚨 $KAS KRC20 index exploit update:
Exploiter wants 1M Kaspa released, while another 0.97M is stuck.
The attacker used the Igra exit bridge which is a manual process. When processed, the iKAS immediately burns with instructions for the Igra team to release $KAS to a certain address on the L1. Igra hasn't released yet and doesn't intend to.
Hence, 1M iKAS of the 1.97M exploited iKAS is currently contained and trapped to be recoverable. The remaining 0.97M iKAS is being transferred to other existing wallets, perhaps out of desperation, because there is no way out of Igra. Their exit is blocked, unlike on Kasplex, which is where the exploiter was able to transfer 141.6k wKAS to $KAS.
The exploiter's response to Igra: > 引用 @ScapeSquad: 🚨 $KAS KRC20 index attacker chose criminal prosecution by transferring iKAS funds to existing wallets rather than the designated return.
• Unauthorized use of a computer (s. 342.1): It's an offence to fraudulently and without colour of right obtain computer services or data, or use a computer system to commit another offence. "Without colour of right" is roughly "without an honest belief you had a legal entitlement," and "the system let me" doesn't give you that.
• Mischief in relation to computer data (s. 430(1.1)): Covers interfering with the lawful use of data or a system.
• Theft and fraud (ss. 322, 380): Taking funds by exploiting a system in a way its operators didn't intend can be charged as plain theft or fraud, no "hacking" statute required. Fraud in particular covers deceit or "other fraudulent means," which courts read broadly.
• Laundering (s. 462.31): Moving the proceeds afterward is its own offence, and a serious one.
Let the games begin... 🔥 https://x.com/ScapeSquad/status/2102179737569276392