Kipseli PropAMM exploited for $72.35K via decimal-mismatch vulnerability; attacker demanded 20% bounty, signaling shifting bug-bounty economics.
Security & Exploits ·
A known attacker exploited Kipseli's proprietary AMM on Base for $72.35K by swapping 0.04 WETH (approximately $95) for 0.926 cbBTC, according to Defimon Alerts. Following the incident, the attacker demanded a 20% bug bounty from the project's CEO, who agreed to the terms—a shift from what had previously been considered a 10% industry standard for such disclosures.
The vulnerability stemmed from a decimal-mismatch flaw in Kipseli's pricing mechanism. The PropAMM Router generated quotes in USDC-denominated scale (6 decimals) but directly transferred the resulting integer as cbBTC (8 decimals), causing a ~760x price distortion. The swap used an unsupported trading pair (WETH to cbBTC), yet the on-chain wrapper's signature validation only bound the token pair and timestamp—not amounts or rates—leaving no safeguard against the mispriced direction.
The incident raises questions about how bug-bounty economics are evolving across DeFi protocols. While the 20% demand was met in this case, it remains unclear whether this signals a broader recalibration of bounty expectations or reflects leverage specific to repeat attackers with demonstrated access to multiple vulnerable systems.