🚨 KRC 20 Indexer Signature Bypass: Incident Report
We have completed our analysis of the KRC 20 incident that affected ZEAL and other bridged assets.
Importantly, our investigation found no exploit in ZealousSwap, Igra, or Kaspa L1. All three operated as intended. The vulnerability was in the Kasplex KRC 20 indexer.
The report covers the signature bypass, how unauthorized KRC 20 balances were created, how they were bridged to L2, and the resulting impact on liquidity.
Full incident report in the reply.