MEV bot exploited Kipseli PropAMM Router for ~$20–30K by executing hundreds of round-trip swaps after same attacker previously drained $72.35K via decimals mismatch in pricing oracle.
Security & Exploits ·
An MEV bot exploited Kipseli's PropAMM Router for approximately $20,000–$30,000 by executing hundreds of round-trip swaps. The same attacker had previously drained $72.35K from the protocol through a decimals mismatch in its pricing oracle. When an off-chain market-maker bot supplied asymmetric order book values, the MEV bot compounded small per-cycle profits of roughly $9 across numerous WETH-to-USDC transactions to accumulate the larger loss.
The initial $72.35K exploit leveraged an unsupported trading path: the attacker swapped 0.04 WETH for 0.926 cbBTC via Kipseli's PropAMM Router. The pricing stack produced a quote denominated in USDC at 6 decimals, but that integer was transferred directly as cbBTC—which uses 8 decimals—resulting in a catastrophic mispricing. The on-chain wrapper's signature mechanism bound only token identities and timestamp, never validating the swap amount or rate, allowing the erroneous quote to execute unchecked.
The vulnerability in the pool implementation remains unresolved. It is unclear whether Kipseli has patched the signature validation logic or implemented safeguards to prevent similar decimal-misalignment attacks, or whether additional MEV extraction via the same vectors may continue.