
Kasplex KRC-20 Indexer Exploit Drains Two Token Pools
An attacker withdrew 186.4 million ZEAL and 54.4 billion NACHO from a Kaspa KRC-20 bridge wallet without possessing its private key, according to a security alert. The tokens were subsequently routed through layer-2 networks and sold into liquidity pools.
Off-Chain Indexer Exploited
The incident did not involve a compromise of the Kaspa blockchain itself. Instead, the attacker reportedly used five valid transactions to deceive an off-chain indexer responsible for processing and verifying activity related to the Kasplex KRC-20 bridge.
By bypassing the indexer’s signature checks, the attacker was able to make unauthorized withdrawals from the bridge wallet. The flaw appears to have affected the indexer’s interpretation of valid on-chain transactions rather than Kaspa’s underlying consensus or cryptographic security.
Tokens Moved Through Layer-2 Networks
After withdrawing the assets, the attacker recycled the ZEAL and NACHO tokens through layer-2 networks before selling them into liquidity pools. This activity placed pressure on the affected markets and reduced the assets held by the associated pools.
KRC-20 is a token standard used on the Kaspa network. Bridges and indexers supporting such assets typically track transactions off-chain and use that information to coordinate deposits, withdrawals and token movements across networks.
Security Implications
The incident highlights the risks associated with off-chain infrastructure, even when the underlying blockchain remains operational and uncompromised. A vulnerability in an indexer or bridge verification system can enable unauthorized asset transfers if transaction validation is not handled correctly.
The affected wallets, pools and total financial impact were not specified in the available information.