Crypto Lender Kokomo's Developers Used Wrapped Bitcoin for $4M ‘Exit Scam,’ Security Firm Says

Kokomo's tokens fell 97%, and the project deleted its presence on social media.

AccessTimeIconMar 27, 2023 at 7:20 a.m. UTC
Updated Mar 27, 2023 at 7:35 p.m. UTC
10 Years of Decentralizing the Future
May 29-31, 2024 - Austin, TexasThe biggest and most established global hub for everything crypto, blockchain and Web3.Register Now

Developers behind the Optimism-based lending platform Kokomo Finance seemed to have conducted an exit scam over the weekend after manipulating tokens on the protocol to effectively steal $4 million in user funds.

An exit scam is said to occur when developers or promoters of a crypto project seem to market a legitimate-looking project to investors, only to pull liquidity and erase their online or offline presence once a sizable amount of money has been attracted to that project.

Launched on Saturday, Kokomo Finance allowed users to trade, borrow and lend wrapped bitcoin (WBTC), ether (ETH), tether (USDT), USD coin (USDC) and dai (DAI). It quickly gained favor among Optimism users.

On Sunday night, Kokomo developers deployed an attack contract cBTC from the main address of KOKO, Kokomo’s native tokens. They then set the reward speed, paused a borrow feature and created a malicious contract to interact with the rest of the protocol, security firm CertiK said.

cBTC is a wrapped bitcoin derivative issued on the Ethereum network. The issuance of the token was ultimately used to trick the protocol into falsely believing it had more liquidity when there was none.

Another developer address was then used to maliciously approve a transfer of spending more than 7,000 sonne wrapped bitcoins, another bitcoin derivative token on Ethereum. Those tokens were then used to swap all user-supplied liquidity to Kokomo, amounting to over $4 million.

Social-media accounts and the Kokomo website were quickly deleted in the following and were inaccessible during Asian morning hours.

Meanwhile, KOKO tokens fell 97%, wiping nearly all value for holders.

The exit scam was the latest in line of a number of growing attacks and exploits in the crypto market. Earlier this month, Euler Finance, another lending platform, was exploited for $200 million.

Disclosure

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.

Shaurya Malwa

Shaurya is the Deputy Managing Editor for the Data & Tokens team, focusing on decentralized finance, markets, on-chain data, and governance across all major and minor blockchains.


Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.



Read more about