# "smart contract" (exploit OR hacked OR drained) — X 热门讨论 (2026-09-21 09:08 UTC)

## @Kaspa_KAT (K.A.T.) · 09-21 03:55 · ♥20 ↻8 💬1 We independently checked the transactions in this report and fully agree with @ZealousSwap's findings. KAT Bridge behaved as designed: for KRC-20 it treats the @Kasplex indexer as the source of truth, and it minted on EVM only after that indexer reported a successful deposit. Routes are paused at the smart-contract level while we wait for a meaningful updates from @kasplex. The Vault signers keys, Relayers keys, Onboarder keys, and SC Admins keys were never accessed, the smart contracts were not hacked; the source of truth upstream (kasplex indexer) allowed forged transactions to remove liquidity from the vault without any valid signature.

We also audited the full KAT Bridge KRC-20 history. None of those mints used an empty-sig / OP_NOT / KASPLEX forge. The only transactions we found with that pattern are the ones in the ZealousSwap report ( vault outflows, not bridge mints or releases). Due to the structure of the possible forgeries we'll need to continue this research when a KRC20 indexer is available because not all possible forgery txn shapes require showing relation to the Bridge vault address on a kaspa explorer but they will in the indexer's oplist txn history.

Out of caution, KRC-721 bridge is paused as well. We have no evidence it was affected or targeted.

@ZealousSwap's incident report - https://t.co/4STCTQDMbg > 引用 @ZealousSwap: 🚨 KRC 20 Indexer Signature Bypass: Incident Report

We have completed our analysis of the KRC 20 incident that affected ZEAL and other bridged assets.

Importantly, our investigation found no exploit in ZealousSwap, Igra, or Kaspa L1. All three operated as intended. The vulnerability was in the Kasplex KRC 20 indexer.

The report covers the signature bypass, how unauthorized KRC 20 balances were created, how they were bridged to L2, and the resulting impact on liquidity.

Full incident report in the reply. https://x.com/Kaspa_KAT/status/2101882941723062362

## @SUSHlR0LL (Sushi) · 09-20 22:45 · ♥21 ↻1 💬14 CS2 Scammers found a way to make people drain their own inventory without sending them a phishing link.

They uploaded YouTube tutorials showing people how to build an AI CS2 skins trading bot with Claude.

People followed the tutorial themselves.

Copied the code.

Deployed the smart contract themselves.

Funded it from their own wallets.

And approved every transaction themselves.

Except the “CS2 trading bot” had no trading logic.

It was built to send their inventory straight to the scammers.

224 inventories lost $862,000 when it was stolen.

The median victim lost $3,840

Some victims even got an error after getting drained telling them to deposit another 50% to fix the bot.

They literally got people to build, fund and approve their own inventory drainer. https://x.com/SUSHlR0LL/status/2101804848454967706