CryptoReal
CASE FILE — Jul 15, 2025

Kinto's $K Token Craters After Hidden Proxy Backdoor Exploit

Kinto, a compliance-focused DeFi protocol built by Ramon Recuero, saw its native $K token crippled after an attacker exploited a flaw in the token's proxy contract. The breach allowed 110,000 counterfeit $K tokens to be minted and dumped, draining roughly $1.55 million in liquidity from Uniswap and Morpho pools and erasing nearly 95% of the token's value.

Kinto's leadership has attributed the breach to a "sophisticated," even state-actor-level adversary exploiting outdated OpenZeppelin proxy code, rather than any flaw in its own contract design or in the allocations held by insiders.

Notably, this isn't the first time a project led by Recuero has absorbed a costly loss tied to an external event — his earlier venture, Babylon Finance, also suffered a major hit traced to a third-party hack.

Background

Recuero had positioned Kinto as infrastructure meant to bring regulated, institutional-grade finance onto Ethereum. The $K token, deployed on Arbitrum, launched with exchange listings and institutional backers, giving it the trappings of established, legitimate infrastructure.

That image cracked on July 10, when a hidden flaw in the token's upgradeable proxy contract was used to mint 110,000 unauthorized $K tokens. The attacker emptied every pool holding liquidity, sending the token's price from $7.68 down to $0.50 in under 24 hours, according to CoinGecko figures.

Kinto's first public statement was thin on specifics: "Kinto community. We are looking into the situation ourselves and with third parties (Hypernative, Seal 911) - as soon as we have a clear picture of what has happened we will make an announcement."

How the exploit worked

Recuero later explained: "Today, we got hacked by a state actor. They upgraded the implementation of the K token on Arbitrum and used it to mint fake K tokens that they dumped immediately."

Whatever one makes of the "state actor" framing, the underlying mechanism was real. Researcher pcaversaccio identified a hidden backdoor embedded in the ERC-1967 proxy pattern used by the $K contract — a widely deployed but, in this instance, vulnerable proxy standard that let the attacker mint tokens without triggering any obvious red flags on-chain.

Sums referenced in this case file

Venn Network researchers say they had been tracking the underlying vulnerability for months across a large number of exposed contracts. Alongside Venn, teams from Dedaub and SEAL 911 reportedly reached out privately to affected projects to help patch the flaw before it could be exploited. Some protocols reconfigured their contracts in time; others withdrew funds pre-emptively. Kinto was not among those that acted in time.

By Recuero's own account, the vulnerability was disclosed to the team on July 9 at 20:17 UTC; the attack hit on July 10 at 08:40 UTC — roughly twelve hours later.

One detail stands out in the forensic record: the attacker minted precisely 110,000 $K tokens, not a round figure picked at random but one that closely tracked the pools' available liquidity — suggesting either unusual restraint on the attacker's part or a precise read on how much value could actually be extracted.

A familiar name

This isn't Recuero's first brush with a protocol-crippling loss. In 2021 he launched Babylon Finance, which promised community-run, professionally structured investment strategies for retail users — essentially crowd-managed hedge funds on-chain. The project peaked near a $200 million fully diluted valuation before collapsing roughly 99.95% to about $100,000 by 2022.

Part of that decline traced back to April 2022, when the Rari protocol was hacked, wiping out $3.4 million spread across several Babylon investment pools. Although Babylon itself hadn't been breached, Recuero chose to reimburse affected users out of his own resources after Rari initially pledged, then abandoned, a full-reimbursement plan. Users were made whole, plus an additional 2% to offset fees, and $100,000 was distributed to holders of Babylon's "heart" token who hadn't suffered direct losses. "Although the damage to Babylon is done and irreparable," Recuero wrote at the time, "we are extremely happy that our users will recover all the losses from this hack."

Kinto launched in 2024 as something of a successor — smart wallets and compliance tooling in place of Babylon's investment strategies, but carrying the same institutional backing, the same reform-minded pitch, and the same founder.

The recovery pitch

Three days after the exploit, Recuero announced a recovery fund: "We're raising a recovery fund. Bootstrapping fresh liquidity isn't free. If you believe in Kinto's mission - safer, compliant DeFi - consider helping."

Unlike his response to the Rari incident, this time the ask took the shape of a community fundraiser rather than a personally funded reimbursement. The stated plan involves snapshotting all balances as they stood before the hack, issuing a new $K token on Arbitrum reflecting those balances, and raising funds to cover the roughly $1.4 million lost from Uniswap liquidity and Morpho vault balances. Affected users would be made whole only if Recuero succeeds in raising sufficient capital from "partners and existing investors."

Kinto's team subsequently published a full technical post-mortem detailing the exploit's mechanics, though questions about timing and who ultimately benefited from the attack remain open.

Whether the hidden proxy backdoor, the state-actor framing, or the timing so soon after a private vulnerability disclosure amounts to bad luck, a genuine external attack, or something else entirely is still unresolved. What is established is the technical exploit itself, the $1.55 million drained, the roughly 95% price collapse, and a promised "$K v2" token meant to restore both liquidity and trust.

ArbitrumDefiKinto
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.