Jonathan Chew · · 6 min read

Under the hood of Kyber Network’s protocol code

In partnership withKyber Network

When talking business, operational transparency and privacy don’t usually see eye to eye.

In fact, it can even be argued that in cases where companies deal with other people’s money – an extremely private affair – having greater transparency should always win out. After all, a strict level of oversight is needed to protect users’ funds.

One method to ensure such firms toe the line is code audits, a common measure within the crypto sector that helps companies uncover possible errors within their protocols.

Photo credit: Shutterstock

Having audits is especially important in crypto, as there’s always new use cases and products being launched within the industry – from things like wallets and play-to-earn games to healthcare supply chain management tools. In these cases, poorly developed products can introduce new risks for users.

That’s why in 2021, as part of its ongoing arrangements with external auditors, decentralized finance (DeFi) platform Kyber Network engaged ChainSecurity, a smart contract auditing firm, to check on its latest offering at the time.

The subject of the audit was KyberSwap Elastic, a concentrated liquidity protocol that helps users minimize slippage – the loss that occurs when there’s a difference between the expected and actual trade price – when swapping tokens.

“Audits help prevent attacks, allow companies to launch safer DeFi products, give developers more confidence in new product launches, and increase trust in the brand,” says Mike Le, chief technology officer at Kyber Network.

“They are a must-have process.”

Getting ahead of attackers

The initial audit flagged several potential exploits in the KyberSwap Elastic code, which were promptly rectified by Kyber Network.

One of these potential exploits was in the anti-snipping protection feature. On decentralized exchanges, token swaps can take place because users provide liquidity – or their own tokens – to a shared pool, allowing traders to swap between tokens for a small fee.

For example, if you wanted to swap Wrapped Bitcoin (WBTC) for Wrapped Ethereum (WETH) on KyberSwap, you’d effectively be “buying” WETH from the liquidity pool, with those WETH tokens supplied by another person (known as the liquidity provider).

On the KyberSwap Elastic protocol – much like on many other trading platforms – people who provide liquidity to the protocol’s liquidity pool earn fees proportionate to the amount of tokens they added. The fee is issued whenever a token swap takes place using that particular liquidity pool.

Screenshot of the liquidity pools available on KyberSwap Elastic

However, attackers who can detect when large swaps are about to take place can intercept these trades to earn a large portion of the fee instead, says Le. This is known as a liquidity snipping attack.

Bad actors carry out this attack by adding a large amount of liquidity to the pool right before the swap is executed, causing the protocol to issue the trade fee to the attacker instead of the original liquidity provider. In doing so, the “sniper” takes almost all the fees generated in the swap while preventing impermanent loss to themselves.

To counter this risk, KyberSwap had originally built in a protection designed to negate the fees generated if someone were to remove their liquidity soon after adding it to the pool. However, there was an undetected loophole where attackers could add even more liquidity after their original tokens are removed, wait for the vesting period to pass, and then remove their funds without incurring the original penalty. This caused the code to fail to recognize that there was a snipping attack taking place.

“This method of attack requires multiple steps to work, but we didn’t manage to replicate those exact steps while testing out the protocol,” says Le.

Mike Le, chief technology officer at Kyber Network / Photo credit: Kyber Network

That said, the CTO adds that fixing the loophole was “quite straightforward.” Kyber Network ensured that as long as any liquidity was removed before the vesting period was up that the person removing it wouldn’t get a fee.

While this might have seemed like a hiccup, it was still important to ensure that users’ experiences weren’t affected once the fix was in place.

“Once we rectified it, we had to check again to make sure we didn’t introduce any potential new attack vectors,” says Le.

Wait it out

The next potential issue that was found in the audit was within the protocol’s vesting period function.

To put it simply, if users place funds in the pool during the vesting period and the vesting period was changed to a value of zero, the tokens would remain locked within the protocol, as the code would incorrectly assume that there were no locked funds previously.

According to Le, this also caused the anti-snipping protection to fail: with a vesting period of zero, attackers could remove their liquidity immediately without any penalty at all.

Photo credit: Shutterstock

However, he points out that while the loophole exists, changing the vesting period to zero would be extremely difficult. Attackers would not be able to change the value themselves, as it requires a multisig approval – in other words, the change has to be approved by several stakeholders.

Additionally, the value of the vesting period could only be changed if Kyber Network’s decentralized autonomous organization (DAO) voted on allowing the change.

“In practice, this loophole can be exploited if the DAO vote passes and we change the value to zero. But if this were to happen, we can always vote again and change it back to its normal value, removing this issue,” says Le.

They shall not pass

Audits like these are just one of several inspections that ChainSecurity has done for Kyber Network since 2018, and the latter has continued to engage the firm – as well as cybersecurity company Hacken – for more audits over the past few years.

Le says that the company is always happy to work with auditors and has had a good experience with them.

“The process is really smooth, and we’re always willing to delay new product launches until the audits are complete,” he shares.

Of course, these inspections aren’t the only things stopping attacks on Kyber Network. The company also has several other internal processes to secure its users and protocols.

“We’ve got a research department running checks and tests to ensure our code is sound, and our engineering team always has a clear technical design that they test for risk factors,” Le explains.

Other measures include the firm’s implementation department, teams that run security tools and check on the code, third-party services that offer insurance coverage, and an official bug bounty program, among other safeguards.

All this, Le says, is critical to have as the crypto sector continues growing.

“More users attract more malicious actors,” he points out. “People should always use crypto products with caution, but it’s also on us to detect malicious actions and ensure that we’re alerted early, allowing us to take action quickly and bring better security for our users.”


Kyber Network’s KyberSwap is a decentralized exchange aggregator that enables users to swap, earn, and participate in DeFi in a seamless manner. Curious about seeing what products and services it has in store? Check out its website.

VISIT SITE


Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

How would you feel if you could no longer use Tech in Asia?

Editing by Winston Zhang and Jaclyn Tiu

(And yes, we’re serious about ethics and transparency. More information here.)

TIA Writer

Jonathan Chew

Has a strange liking for grabbing tiny plastic things on wooden walls