Kinto Bridge
Summary
Kinto was a KYC-enforced Ethereum Layer 2 built on the Arbitrum Nitro stack, marketing itself as a 'safety-first' DeFi protocol with built-in AML and identity verification. On July 10, 2025, an attacker exploited a CPIMP proxy vulnerability in the $K token contract on Arbitrum, minting 110,000 unauthorized tokens and draining approximately $1.55–1.9 million from Uniswap V4 and Morpho Blue liquidity pools. Despite a partial recovery effort dubbed 'Phoenix,' the project announced shutdown effective September 30, 2025, as fundraising options collapsed and the team ran unpaid for months.
Connected Entities
1 entities- + 2 more
Timeline(13 events)
2023-11-15
Kinto raises $3.5–5 million seed round led by SALT with participation from ParaFi Capital, Robot Ventures, SkyBridge Capital, Kraynos Capital, Modular Capital, and The Spartan Group; announces migration to Arbitrum Nitro stack.
2024-05-01
Kinto mainnet launches on the Arbitrum ecosystem as a KYC-enforced Layer 2.
2024-06-30
$K token contract deployed on Arbitrum.
2025-01-01
Final investor token round occurs at $10 per $K token.
2025-03-19
Kinto developers deploy the $K token proxy on Arbitrum without atomic initialization; attacker initializes the proxy with a backdoor hidden implementation two seconds later.
2025-04-01
$K token airdrop and public listing proceeds; token launches at approximately $7.68.
2025-07-09
CPIMP (ERC-1967 proxy) vulnerability publicly disclosed at 20:17 UTC; Venn Network runs a 36-hour remediation war room notifying affected protocols — Kinto is not reached in time.
2025-07-10
Attacker exploits $K token proxy at 08:40 UTC; mints 110,000 unauthorized $K tokens; drains 577 ETH (~$1.55–1.9M) from Uniswap V4 and Morpho Blue pools. Kinto issues first public alert at 09:50 UTC. $K token crashes 90–95%.
2025-07-10
Kinto freezes CEX trading, pulls remaining liquidity, and begins collaboration with ZeroShadow for on-chain investigation.
2025-07-01
Kinto launches Phoenix recovery initiative; raises just over $1 million in debt financing; deploys new hardened $K contract; restores balances to pre-hack block 356170028.
2025-09-07
Kinto announces full shutdown effective September 30, 2025, citing failed fundraising and unsustainable unpaid operations. $K token falls an additional 81–85% on announcement day.
2025-09-30
Kinto L2 operations, bridge, UI, and wallets shut down. Users directed to claim portals active October 1 through November 30, 2025.
2025-10-15
ERA airdrop distribution targeted; Ethereum mainnet claim contract for hack victims launches.
Decision Log
- hash: Ddn4iXf6UshmtNykr22p6DaCNxUfZApUp2eS1rovBnoN
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:22 AM
last updated: 5/27/2026, 8:21:19 PM
avoid.net — verified advice for a post-truth world