An attacker removed 186,425,259 ZEAL and 54,397,983,246 NACHO from a Kaspa KRC-20 bridge wallet without controlling its private key, exposing a weakness in the off-chain Kasplex indexer.
The tokens were routed through layer two (L2) networks, minted on Igra Labs’ EVM layer and Kasplex L2, and then sold into Zealous Swap liquidity pools. Between 94% and 99.6% of the affected pools’ KAS-side value was subsequently lost.
Kaspa’s base blockchain was not compromised. Instead, five valid transactions persuaded the indexer to accept transfers that had not been authorised, leaving the newly bridged tokens without full backing.
The incident was identified on 20 September. Although a private key should determine control of crypto assets, KRC-20 ownership is not enforced directly by Kaspa consensus. Token instructions are carried inside Kaspa transactions, while the Kasplex indexer interprets them and records ownership.
A conventional KRC-20 transfer includes a public key, token instructions and a valid signature. In this case, the attacker used the same broad structure but provided an empty signature and added an OP_NOT instruction after OP_ENDIF.
That caused OP_CHECKSIG to return false without invalidating the transaction. OP_NOT then reversed the result to true, allowing the transaction to remain valid on Kaspa. The indexer, however, accepted the KRC-20 envelope without checking that the script precisely followed the canonical format.
Kasplex’s API returned `opAccept: 1` for the first forged ZEAL transaction, which was then treated as genuine.
The vulnerability did not require a concealed credential. A standard Kaspa address reveals the public key needed to construct the forged operation, meaning that transferring tokens to another address would not remove the underlying risk. Until the indexer is patched and its historical records reindexed, other KRC-20 balances could theoretically be exposed to the same method.
Nine small withdrawals of one unit each were genuinely signed by the custody wallet and appear to have tested whether the exit route worked. The wallet held about 50 other KRC-20 tokens, but the attacker targeted ZEAL and NACHO.
Igra said on Sunday morning that the wallet’s entire holdings of both tokens had been taken. That left 97,651,212 ZEAL and 42,570,879,908 NACHO on L2 without complete L1 backing. A further 4.5 billion NACHO remained with the attacker on L1.
Igra suspended iKAS withdrawals to Kaspa L1 and Hyperlane transfers. Users were advised not to bridge KRC-20 tokens, buy ZEAL or NACHO on L2 decentralised exchanges, or add liquidity to the affected pools. Native KAS, Kaspa consensus and Igra assets that were not bridged KRC-20 tokens were said to be unaffected.
Zealous Swap said the indexer must reject empty signatures, malformed tags and scripts continuing beyond OP_ENDIF, as well as being reindexed. Nacho the Kat said the community planned to move towards KCC-20, whose token rules are enforced by the network through scripts.
The incident follows several recent exploits, bugs, hacks and data breaches. Blink Wallet, which offers custodial and non-custodial Lightning Network services, said on Saturday that “a few dozen” custodial accounts had been drained. Cybersecurity company DCENT also reported that DCENT App Wallets had been siphoned during the week.
