The most instructive crypto exploit of the past week did not touch a blockchain's consensus layer at all. On September 20, an attacker moved 186,425,259 ZEAL and 54,397,983,246 NACHO out of a Kaspa KRC-20 bridge custody address without ever holding its private key — using five transactions that were, as far as Kaspa's Layer 1 was concerned, perfectly valid.

The incident, reconstructed in detail by Bitcoin.com News and confirmed by ChainCatcher and KuCoin's news desk, turned on the gap between two systems: a base chain that validates transactions, and an off-chain indexer that decides what those transactions mean.

KRC-20's Structural Assumption

KRC-20 token ownership is not enforced by Kaspa consensus. Token instructions ride inside ordinary Kaspa transactions, and the Kasplex indexer reads them to determine balances. Normally a KRC-20 transfer carries a public key, token instructions and a valid signature. The attacker kept that shape but supplied an empty signature and appended an OP_NOT after the script's OP_ENDIF.

An empty signature makes OP_CHECKSIG return false rather than invalidate the transaction outright. The extra OP_NOT flips that false back to true — leaving Kaspa holding a validly structured transaction. The indexer, however, recognized the KRC-20 envelope without requiring the script to match the canonical format exactly, and credited the forged transfer as legitimate. Kasplex's own API returned opAccept: 1 on the first forged ZEAL transaction.

Two details make the bug worse than a one-off. First, the public key needed to construct a forged operation is exposed by any standard Kaspa address — no hidden credential was required. Second, that means moving remaining balances to a fresh address fixes nothing until the indexer itself is patched and its full history reindexed. The custody wallet held roughly fifty other KRC-20 tokens; the attacker chose two.

Recycled Through L2, Sold Into Pools

The stolen tokens were sent back to the same custody address as ordinary bridge deposits, minted on Igra Labs' EVM layer and Kasplex L2, and sold into Zealous Swap liquidity pools. By the time the attacker's L2 balances were empty, affected pools had lost between 94% and 99.6% of their KAS-side value.

Igra Labs said the custody wallet's entire ZEAL and NACHO holdings were taken, leaving 97,651,212 ZEAL and 42,570,879,908 NACHO circulating on the L2 networks without full L1 backing, with another 4.5 billion NACHO still held by the attacker on L1. The operator paused iKAS exits to Kaspa L1 and Hyperlane transfers, and warned users against bridging KRC-20 tokens, buying ZEAL or NACHO on L2 exchanges, or adding liquidity. Native KAS, Kaspa's consensus, and non-bridged Igra assets were unaffected — a distinction Cointribune also stresses: the flaw sat in an L2 component, not the base protocol.

The Fix Is Structural, Not Cosmetic

Zealous Swap says the remediation requires patching the indexer and reindexing its history — rejecting empty signatures, malformed tags, and any script that continues beyond OP_ENDIF. The Nacho the Kat project says the community intends to move toward KCC-20, a standard that puts token rules inside scripts enforced by the network itself. Coverage by TheCryptoUpdates reports that Kron, a Kaspa DEX built on exactly such native covenants, completed a manual Hashlock audit this month rated Secure — an indication of where the ecosystem is heading: token logic enforced by consensus, with no second system left to fool.

The general lesson travels beyond Kaspa. Any architecture where a base chain records data and a separate off-chain component interprets it has two notions of validity, and every difference between them is an attack surface. Kaspa's Layer 1 did exactly what it was designed to do on September 20. That was the problem: nothing at the consensus layer disagreed with the forgeries, because token meaning was never its job.

TrustGrade tracks protocol security posture and incident history. Verified trust data: trustgrade.ai.