Kinto Token Exploit: Minting Abuse, Lending Collateral, and DeFi Risk
Summary
The document describes an exploit involving Kinto’s $K token on Arbitrum. A flaw in its minting contract reportedly let an attacker create nearly 7 million tokens against a circulating supply below 2 million. Rather than immediately selling the tokens, the attacker deposited them as collateral on Morpho and borrowed USDC, leaving the lending protocol with sharply devalued collateral. The account links the exploit to an 87% token price decline within 24 hours and notes Kinto’s statement that its mainnet, wallets, and bridge vaults were unaffected.
The article uses the incident, alongside a separate reported GMX exploit, to illustrate how contract weaknesses and low liquidity can expose DeFi protocols and their lenders. It mentions forensic investigations and a white-hat bounty as recovery responses, and recommends code review and stress testing. These are incident summaries rather than a technical audit: the document gives no exploit transaction analysis, contract details, or independent verification of its claims. Its market commentary also does not provide evidence for its broader claim that major crypto assets were resilient.
Key ideas
- A minting-contract flaw reportedly allowed the attacker to create tokens far beyond the circulating supply.
- The attacker used the new tokens as lending collateral to borrow USDC instead of selling them directly.
- Inflated token supply and weak collateral valuation can transfer losses to a lending protocol.
- The document recommends code review and stress testing but provides no technical audit or transaction-level evidence.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.