Kite Foundation Contains Ethereum Mainnet Attack on KITE Token With No Funds Lost
Key Takeaways
- •The Kite Foundation detected and contained an attack on the KITE token on the Ethereum mainnet on August 6 without any tokens being stolen.
- •Kite AI had pre-existing security infrastructure in place, including a Sherlock bug bounty program offering up to 10,000 USDC and a CertiK security rating of 4.2.
- •KITE's market capitalization has fallen from over $363 million in February to approximately $187 million, a decline of more than 67% from its March 6 all-time high.
- •The KITE attack follows a wave of recent crypto exploits targeting Boltz, AQUA, and ZEUS, with the broader sector accumulating approximately $16.9 billion in stolen value.
- •Research from a16z Crypto found that AI agents' success rate at exploiting known vulnerabilities increased sevenfold from 10% to 70% when supplied with structured attack knowledge.

The Kite Foundation announced on X on August 6 that it detected and shut down an attack targeting the KITE token on the Ethereum mainnet. According to the foundation, no tokens were stolen during the incident.
The event adds KITE to a growing list of DeFi and crypto protocols targeted in recent weeks, including Boltz, AQUA, and ZEUS. What sets the KITE case apart is the outcome: while the broader sector has accumulated approximately $16.9 billion in stolen value according to DefiLlama's hacks database, the foundation reports zero loss.
Attack Detected and Contained on Mainnet
The foundation stated that its security monitoring systems identified unusual KITE transfer activity on the Ethereum mainnet. The threat was flagged and neutralized before any tokens could be moved.
"It was identified and contained immediately, and no tokens were lost," the foundation wrote on X.
Kite AI has been operating a live bug bounty program on Sherlock since July 20, offering rewards of up to 10,000 USDC for reported vulnerabilities. The project also maintained a CertiK security rating of 4.2 on its token page, indicating that audit infrastructure was in place prior to this week's alert. The Ethereum mainnet, where KITE is deployed, remains the most active blockchain for DeFi activity and has historically attracted the largest share of exploit attempts.
From Top-100 Debut to Significant Drawdown
In February, the Kite Foundation reported that KITE had surpassed a $363 million market capitalization with a $2 billion fully diluted valuation, placing it among the 100 largest cryptocurrencies at the time.
Weeks later, KITE ranked seventh by 24-hour spot trading volume on Upbit, South Korea's largest cryptocurrency exchange, with the KITE/KRW pair accounting for approximately 2.3% to 2.5% of the platform's total trading activity. That level of Korean exchange volume placed KITE alongside tokens with far larger global market capitalizations, reflecting concentrated retail interest in the AI-token narrative that has driven significant trading activity across Asian markets throughout 2025.
That standing has since shifted. According to CoinMarketCap data, KITE currently trades at approximately $0.104 with a market capitalization exceeding $187 million. This represents a decline of over 67% from its March 6 all-time high of $0.3212. The token now ranks 123rd among the largest cryptocurrencies.
Following the news of the attack, KITE's 24-hour trading volume surged by nearly 195% to approximately $60 million, consistent with the pattern observed across crypto assets where security incidents draw heightened market attention and liquidity spikes.
A Summer of Crypto Exploits
The KITE incident follows a series of attacks across the crypto ecosystem. On August 3, non-custodial Bitcoin bridge Boltz suspended swap operations after discovering that AI-assisted attackers were exploiting vulnerabilities faster than the team could patch them. The disruptions spread to other Lightning Network providers, with AQUA Wallet reporting swap disruptions on the same day. On August 5, Lightning wallet provider ZEUS took its infrastructure offline for a security audit. All three platforms stated that customer funds remained safe.
DefiLlama's hacks database also records a $115 million Coldcard-related loss on July 31 among a series of late-July exploits.
Yan Pritzker, co-founder and CTO of Swan, shared his perspective on the Boltz attack on X: "This is a sad day. AI attackers are getting more and more sophisticated and small teams are going to have a tough time keeping up with the attacks."
Pritzker added that the cost of maintaining enterprise-grade security in the age of large language models will price out many innovative startups seeking to handle client funds.
Research from a16z Crypto found that an off-the-shelf AI agent's success rate at exploiting known vulnerabilities increased sevenfold, from 10% to 70%, when supplied with structured attack knowledge. That finding underscores the asymmetric challenge facing projects like Kite, where defensive tooling must keep pace with increasingly automated and scalable offensive techniques.
AI-Focused Infrastructure Under Scrutiny
Kite describes itself as the first AI payment blockchain infrastructure, designed to enable autonomous AI agents to transact using verifiable identity, programmable governance, and native stablecoin access. The project sits at the intersection of two of the most actively developed sectors in technology: large-language-model-based agents and on-chain payments. As AI-driven attacks increasingly target platforms built around the agentic economy — where machines transact without human intervention — Kite's rapid detection and containment of this incident may serve as a reference point for similar projects facing evolving security threats. The coming months are likely to see increased attention on whether pre-emptive security measures such as bug bounties, continuous monitoring, and audit ratings prove sufficient against the escalating pace of AI-assisted exploitation documented across the sector.