Beleaguered DeFi project xToken suffers second major exploit since May

Beleaguered DeFi project xToken suffers second major exploit since May

The decentralized finance project xToken has suffered another exploit over the weekend after hackers discovered a vulnerability in the smart contracts for its xSNX product.

On Aug. 29, the xToken team reported that the attack had resulted in roughly $4.5 million worth of funds being drained from xToken’s xSNX product — which allows users to gain exposure to Synthetix-based assets without directly interacting with the protocol’s complex smart contracts.

Our top trading bots

The project published a post mortem a few hours later, explaining that the malicious actor had taken out a flash loan from the dYdX decentralized exchange (DEX) for 25,000 ETH (roughly $81 million) to carry out the attack.

They then used the Ether as collateral to borrow 1.5 million Synthetix governance tokens (SNX) using popular DeFi money market protocol Aave, and pooled liquidity token exchange, Bancor.

These were swapped for 6.5 million USDC on decentralized exchange, Kyber, exerting downward pressure on the price of SNX. The attacker then swapped the USDC for Synthetix’s USD token (sUSD), before exploiting a flaw in xToken’s contracts to purchase 614,000 SNX at an artificially depressed price for 811,000 sUSD.

At current prices, the hacker made off with $7 million worth of SNX.

In response to the latest attack, xToken has announced it will retire the xSNX product, stating:

“The current xSNX implementation is by far our most complicated product, with complex dependencies and significant surface area for vulnerabilities.”

Related: How do DeFi protocols get hacked?

xToken allows users to hold interest-bearing derivatives of crypto assets like AAVE and SNX that require holders to participate in staking, governance, or other protocol interaction in order to receive yield.

The incident is not the first time xToken has been exploited this year. In May, the protocol suffered a similar fate when a malicious actor manipulated the Kyber DEX while also simultaneously taking advantage of xToken price calculations. The breach cost the protocol around $25 million in SNX tokens at the time.

Moving forward, the xToken team stated it will spend the coming week working to calculate investor losses and structure a compensation program based on using its native token, XTK.

At the time of writing, XTK had dumped 45% over the past 24 hours, according to CoinGecko, and is down more than 90% from its April all-time high which preceded the first exploit.

Continue reading about Cointelegraph
OpenSea disables features temporarily as contract migration completes
The week-long period that OpenSea gave users to migrate their nonfungible token (NFT) listings ends today. Following the deadline, the platform announced...
3 reasons why Telos (TLOS) price hit a new all-time high
It seems crypto winter is upon us and during times like these, projects that continue to forge ahead by focusing on development and expansion are often...
Bitcoin sees ‘non-stop’ end-of-year buying as 10K BTC leaves Coinbase in a single day
Almost 10,000 Bitcoin (BTC) left major United States-based exchange Coinbase on Dec. 30 in a sign that investor appetite is returning to the sphere. Data...
Coinbase Wallet rolls out support for NFTs
United States crypto exchange Coinbase has made new upgrades to its self-custody wallet, including adding support for nonfungible tokens, or NFTs, in a...
Bitcoin falls 9.2% to $48,782
(Reuters) - Bitcoin dropped 9.29% to $48,752.15 at 22:01 GMT on Saturday, losing $4,991.54 from its previous close.Bitcoin, the world's biggest and best-known...
Altcoin Roundup: 3 Proof-of-work protocols focused on building Web 3.0
The proof-of-work (PoW) consensus model is the mechanism that kicked off the revolution that launched Bitcoin (BTC) in 2009 and it was the model of choice...
Brazilian federal deputy proposes crypto payment option for workers
Federal Deputy Luizão Goulart, a Brazilian congressman, proposed a bill to legalize crypto payments as a mode of payment for public and private sector workers.Goulart’s...
Illuvium, LCX and Tokemak hit new highs as Bitcoin dominance lingers
During bull markets, altcoins tend to accrue gains when Bitcoin price consolidates and at they run in tandem with BTC price during breakouts. This dynamic...
3 reasons why a Bitcoin ETF approval will be a game changer for BTC price
Some financial experts believe that the price of cryptocurrencies is solely driven by investors' speculation, and in the past few years detractors have...
5 easy ways crypto investors can make money without needing to trade
Large price jumps and 100x gains get a lot of attention from pundits and influencers in the cryptocurrency community because they offer the hope of overnight...
Ethereum 2.0 approaches 6 million staked ETH milestone
Ethereum 2.0 is approaching what some are calling a major milestone in its short history — 6 million staked Ether (ETH). The Ethereum Launchpad, Ethereum...
Trading apps usurp TikTok in popularity
Two trading apps have risen to the top of Apple's App Store in recent days. Robinhood holds the number one position, with Coinbase in second, at the time...
Top 5 cryptocurrencies to watch this week: BTC, XLM, MIOTA, XMR, XTZ
Bitcoin’s (BTC) hesitation near the all-time high suggests that the bulls and the bears are waiting for a trigger to start the next trending move. The bulls...
Cryptos vs. Blockchain: One Is Useless, The Other Has a Chance
The author of the latest Economist’s article regarding cryptos and blockchain argues that the former are of no use, while the latter still have something...
Venezuela Says Petro Raised $735 mln in The First Day of Pre-Sale
Just a little bit more than 24 hours ago Venezuela finally instructions for purchasers as well as the manual on how to prevent money laundering. Also,...