
Blockchain security company CertiK warned users about the situation in a tweet on March 26.
#CertiKSkynetAlert
— CertiK Alert (@CertiKAlert) March 26, 2023
On 26 March 2023, Kokomo Finance conducted an exit scam and stole ~$4 million in user funds.
Details Below https://t.co/BEPwfahblz
According to CertiK, the KOKO token implementer hacked cBTC’s smart contract code by resetting the reward rate and halting the borrowing function. An address starting with "0x5a2d.." then approved the new cBTC smart contract to spend over 7000 Sonne Wrapped Bitcoin (So-WBTC). The attacker then invoked another command to swap So-WBTC to address 0x5a2d, generating a profit of $4 million.
CertiK also noted that Kokomo Finance deleted all social media accounts shortly after the alleged rugpull incident. The protocol has risen in rankings rapidly in recent days, with blockchain data platforms like CoinGecko and DefiLlama officially following it shortly after Kokomo Finance launched on Optimism on March 25. Recent screenshots revealed that over $2 million was locked into Kokomo Finance previously down over 97%.
According to data from DefiLlama, more than 72% of the total value is locked in the Kokomo Finance protocol as wrapped Bitcoin. Although most aspects of the test passed, a "typo" was found and KOKO token holders were also found to be able to once generate 45% of the supply. maximum allocation for an arbitrary address.
Kokomo Finance is a lending protocol that allows trading users to receive wBTC, Ether (ETH), Tether (USDT), USD Coin (USDC) and Dai (DAI). It works on top of Optimism's layer 2 scaling solution, allowing for faster and cheaper transactions on the Ethereum network.
Scam allegations against Kokomo Finance have raised concerns about the security of decentralized finance (DeFi) protocols. While DeFi has brought financial freedom and greater accessibility to users, it has also brought new risks and challenges. Smart contract vulnerabilities and security holes can be exploited by bad actors, as is the case with Kokomo Finance.
VIC Crypto synthesizes
Related articles:
The owner of a CryptoPunk accidentally burned his 135,000 USD worth of NFT
Animoca Brand denies Reuters report on shrinking Metaverse fund target and valuation plunges 3x
The token “rewards” skyrocketed 2000% thanks to the same name as Arbitrum’s token


