{"investigation":{"slug":"kipseli","entity_name":"Kipseli","trust_score":38,"severity_base":null,"score_modifier":0,"confidence":0.52,"status":"published","content_type":"investigation","summary":"Kipseli (also styled Kipseli Capital) is a proprietary trading firm and on-chain market-maker founded in early 2018, operating the Kipseli PropAMM on Base Mainnet. The protocol was listed among exploited platforms during the April 2026 wave of DeFi attacks, and the broader PropAMM category to which it belongs was the subject of a March 2026 empirical report by 0x documenting systematic quote-spoofing behavior that caused measurable trader harm. ZachXBT has flagged the entity. No public smart-contract audit or post-incident disclosure has been identified as of May 2026.","sections":[{"content":"Kipseli Capital derives its name from the Greek word 'Κυψέλη' (kypseli), meaning 'beehive.' The firm describes itself as a proprietary trading operation whose core members were pioneers in purely on-chain market-making on the Ethereum blockchain, launching operations in early 2018. Its primary public-facing product is the Kipseli PropAMM, a professional Automated Market Maker deployed on Base Mainnet that enables token swaps with competitive, on-chain pricing. All quotes are denominated against USDC. The system requires would-be integrators to obtain whitelist approval from the Kipseli team before they can access on-chain quoting or the swap-signing API. Smart-contract deployments identified on Base Mainnet include the Router (PropAmm) at 0x71c2ed90cc288229be59f26b8b3eef3c07d7ab99, the Helper (QuoteLens) at 0x62aff80b3d2afe0e497f1ef735a6fdc9c3ef1acf, and the EIP-712 Verifier at 0xca369e97cc161c3c3a7368f9bc55a47f36a0a91e. The company maintains a minimal public web presence at kipseli.capital and docs.kipseli.capital. No corporate registration details, country of incorporation, or regulatory disclosures have been identified in publicly available sources.","heading":"Background and Overview","sources":[{"url":"https://docs.kipseli.capital/","name":"docs.kipseli.capital","type":"other","credibility":3},{"url":"https://www.kipseli.capital/","name":"kipseli.capital","type":"other","credibility":3}],"severity":"medium"},{"content":"Public information about Kipseli's leadership and team composition is limited. The only named individual identified in professional databases is Christos Liatas, listed on RocketReach as a Data Scientist at Kipseli Capital, with prior experience at Kyber Network and the Athena Research and Innovation Center at the University of Athens. A LinkedIn profile for Tung Nguyen is also indexed under the Kipseli Capital company page, but no role description was accessible in public search results. The official documentation and website do not publish team biographies, advisory board details, or investor disclosures. The LinkedIn company page (linkedin.com/company/kipselicapital) lists the firm but does not expose headcount or leadership. The absence of transparent team information is a notable opacity risk for users and integrators evaluating counterparty exposure.","heading":"Team and Organizational Transparency","sources":[{"url":"https://rocketreach.co/christos-liatas-email_253384356","name":"rocketreach.co","type":"other","credibility":3},{"url":"https://www.linkedin.com/in/christosliatas/","name":"linkedin.com","type":"other","credibility":3},{"url":"https://www.linkedin.com/company/kipselicapital","name":"linkedin.com","type":"other","credibility":3},{"url":"https://vn.linkedin.com/in/tung-nguyen-673a9a1b6","name":"vn.linkedin.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Kipseli was identified as one of the platforms hit during the April 2026 wave of DeFi exploits, which collectively caused approximately $620 million in losses across more than 20 protocols in a single month. A contemporaneous report by Live Bitcoin News noted: 'Further exploits hit Kipseli and Giddy, showing attackers continued targeting smaller platforms.' Kipseli appeared in a community-sourced list of hacked protocols in 2026 that also included Drift Protocol, KelpDAO, Rhea Lend, Volo Vault, Juicebox, Thetanuts Finance, and others. No official post-mortem, disclosure, or on-chain evidence of the specific exploit vector or funds lost has been identified in publicly available sources as of May 2026. The specific dollar amount drained and the precise exploit mechanism remain unconfirmed in indexed media, making this a medium-confidence incident flag. The lack of any public response from Kipseli following the alleged incident heightens concern about transparency.","heading":"April 2026 Security Incident","sources":[{"url":"https://www.livebitcoinnews.com/april-2026-crypto-hacks-hit-620m-as-bridge-failures-and-admin-exploits-dominate-attacks/","name":"livebitcoinnews.com","type":"other","credibility":3},{"url":"https://x.com/ProMint_X/status/2049794641537671581","name":"x.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 20, 2026, 0x published an empirical research report titled 'PropAMM Shenanigans' documenting two systematic patterns of harmful behavior observed among PropAMM operators on Base Mainnet, the same network on which Kipseli PropAMM is deployed. The report did not name Kipseli by name, but documented behavior that is structurally possible for any whitelisted PropAMM operator on Base. The first pattern, labeled 'Aggregator Spoofing via Flashblocks,' involves operators publishing attractive prices in the final Flashblock (approximately 200ms) of each block, then repricing worse in the first Flashblock of the next block; aggregators capture the tight quote while traders settle at a worse price. The second pattern involves operators quoting tight spreads to win routing, then widening spreads by a factor of four to eight before the trader's transaction settles. 0x estimated that a single PropAMM source operating at approximately $1 billion in monthly volume was delivering $500,000 per month less to traders than the quoted price. A third behavior documented as 'phantom liquidity' involves providers depositing liquidity in the final Flashblock, collecting block rewards, and immediately withdrawing before trades execute. Whether Kipseli specifically engaged in any of these behaviors is not confirmed in publicly available evidence. However, as a PropAMM operator on Base that uses EIP-712 signed quotes with a 10-second validity window and whitelist-gated access — an architecture that is compatible with the described repricing vectors — Kipseli falls within the category of operators subject to these systemic concerns. The 0x report constitutes the protocol logic incident most consistent with the 'protocol logic incident' flag associated with this entity.","heading":"Protocol Logic and Quote-Spoofing Concerns (PropAMM Category)","sources":[{"url":"https://0x.org/post/propamm-shenanigans","name":"0x.org","type":"other","credibility":3},{"url":"https://docs.kipseli.capital/","name":"docs.kipseli.capital","type":"other","credibility":3}],"severity":"medium"},{"content":"No public smart-contract audit report for Kipseli PropAMM has been identified in searches of major audit aggregators or the Kipseli documentation. The official documentation (docs.kipseli.capital) contains no reference to any completed security review by a third-party auditor. PropAMMs differ architecturally from traditional AMMs in that pricing is determined off-chain by a proprietary signing key rather than by an on-chain invariant curve. This design introduces off-chain counterparty risk: if the signing infrastructure is compromised or the operator intentionally misbehaves, the on-chain contract may execute swaps at arbitrary prices. The whitelisted-access model means most users are retail aggregator users who have no direct relationship with Kipseli and may be unaware of the signing key dependency. The absence of any documented audit, combined with the April 2026 exploit flag and the 0x research concern, represents a material unmitigated risk for integrators and end users.","heading":"Audit Status and Smart Contract Risk","sources":[{"url":"https://docs.kipseli.capital/","name":"docs.kipseli.capital","type":"other","credibility":3},{"url":"https://0x.org/post/propamm-shenanigans","name":"0x.org","type":"other","credibility":3}],"severity":"medium"},{"content":"According to AVOID.NET's intake data, ZachXBT — the pseudonymous blockchain investigator and Paradigm incident response advisor — has flagged Kipseli. The specific nature and date of the flag have not been independently verified in publicly indexed sources as of May 2026. ZachXBT's Telegram channel @investigations and X account have not been confirmed to contain a public post about Kipseli in the indexed portions of those channels reviewed. The flag is treated as a low-confidence Tier 3 signal pending public confirmation. Kipseli also appeared in a community-sourced ProMint X post listing over 20 protocols allegedly hacked in 2026. The convergence of an alleged ZachXBT flag, inclusion in community hack lists, and the April 2026 exploit report warrants elevated caution, but the absence of a verified primary-source disclosure caps investigative confidence.","heading":"ZachXBT Flag and Community Signals","sources":[{"url":"https://x.com/ProMint_X/status/2049794641537671581","name":"x.com","type":"other","credibility":3},{"url":"https://en.wikipedia.org/wiki/ZachXBT","name":"en.wikipedia.org","type":"other","credibility":3},{"url":"https://t.me/s/investigations","name":"t.me","type":"other","credibility":3}],"severity":"medium"},{"content":"No regulatory filings, enforcement actions, or sanctions related to Kipseli Capital have been identified in searches of SEC EDGAR, CFTC enforcement records, OFAC SDN lists, FinCEN, or equivalent regulatory databases. The firm does not appear to hold or publicly claim any money-transmitter license, exchange registration, or equivalent authorization in any jurisdiction. Proprietary trading firms operating purely on-chain in non-custodial architectures occupy a regulatory grey zone in most jurisdictions as of 2026; however, Kipseli's PropAMM facilitates token swaps for third-party users through aggregators, which may attract scrutiny depending on regulatory interpretation of AMM operator liability.","heading":"Regulatory Status","sources":[{"url":"https://www.kipseli.capital/","name":"kipseli.capital","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2018","event":"Kipseli Capital core team begins on-chain market-making operations on Ethereum Mainnet, self-described as early pioneers of the discipline.","source":"","date_original":"2018-01-01"},{"date":"2026-03-20","event":"0x publishes 'PropAMM Shenanigans,' empirically documenting systematic quote-spoofing and repricing behaviors by PropAMM operators on Base Mainnet — the same architecture class as Kipseli PropAMM.","source":""},{"date":"2026-04","event":"April 2026 wave of DeFi exploits begins with the $285M Drift Protocol breach, initiating the worst month for DeFi security since February 2025.","source":"","date_original":"2026-04-01"},{"date":"2026-04","event":"Kipseli listed among protocols exploited during the April 2026 DeFi attack wave alongside Giddy, with attackers described as targeting smaller platforms. Specific amount and exploit vector unconfirmed.","source":"","date_original":"2026-04-01"},{"date":"2026-05-28","event":"AVOID.NET investigation opened based on ZachXBT flag and protocol logic incident designation. No public post-mortem or official incident disclosure from Kipseli identified as of this date.","source":""}],"sources_used":[{"url":"https://docs.kipseli.capital/","name":"docs.kipseli.capital","type":"other","archive_url":"http://web.archive.org/web/20260606045027/https://docs.kipseli.capital/","credibility":3,"archive_timestamp":"2026-06-06T04:50:27+00:00"},{"url":"https://www.kipseli.capital/","name":"kipseli.capital","type":"other","archive_url":"http://web.archive.org/web/20260510175202/https://kipseli.capital/","credibility":3,"archive_timestamp":"2026-05-10T17:52:02+00:00"},{"url":"https://rocketreach.co/christos-liatas-email_253384356","name":"rocketreach.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.linkedin.com/in/christosliatas/","name":"linkedin.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.linkedin.com/company/kipselicapital","name":"linkedin.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://vn.linkedin.com/in/tung-nguyen-673a9a1b6","name":"vn.linkedin.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:blocked","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.livebitcoinnews.com/april-2026-crypto-hacks-hit-620m-as-bridge-failures-and-admin-exploits-dominate-attacks/","name":"livebitcoinnews.com","type":"other","archive_url":"http://web.archive.org/web/20260724160648/https://www.livebitcoinnews.com/april-2026-crypto-hacks-hit-620m-as-bridge-failures-and-admin-exploits-dominate-attacks/","credibility":3,"archive_timestamp":"2026-07-24T16:06:48+00:00"},{"url":"https://x.com/ProMint_X/status/2049794641537671581","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://0x.org/post/propamm-shenanigans","name":"0x.org","type":"other","archive_url":"http://web.archive.org/web/20260420121918/https://0x.org/post/propamm-shenanigans","credibility":3,"archive_timestamp":"2026-04-20T12:19:18+00:00"},{"url":"https://en.wikipedia.org/wiki/ZachXBT","name":"en.wikipedia.org","type":"other","archive_url":"http://web.archive.org/web/20260711020137/https://en.wikipedia.org/wiki/ZachXBT","credibility":3,"archive_timestamp":"2026-07-11T02:01:37+00:00"},{"url":"https://t.me/s/investigations","name":"t.me","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:11.324195+00:00","updated_at":"2026-08-30T15:55:36.357348+00:00"}}