In a post-mortem published by KiloEx, the platform confirmed that the attacker exploited a permissionless function. The DEX said the attacker crafted a request that only authorized entities should have been able to do.