RiseX Hack
What happened
On August 3, 2026, perpetual exchange protocol RISEx experienced an unauthorized withdrawal of 673,011.56 USDC from the Real-World Asset (RWA) yield strategy linked to its XLP liquidity vault due to a smart contract misconfiguration. The team patched the vulnerability within minutes and fully reimbursed XLP depositors using protocol fee revenue, resulting in zero user losses.
The exploit was caused by a configuration flaw in the RWA yield strategy connected to RISEx's XLP vault, which had been present since its deployment on July 13, 2026. An unauthorized user took advantage of this misconfiguration at 07:21 UTC to execute an unverified withdrawal of 673,011.56 USDC. Because the withdrawal amount sat below the protocol's automatic rate-limiting and throttling thresholds, the transaction executed on-chain.
RISEx engineering detected the transaction within minutes and deployed a patch by 08:09 UTC. The protocol covered 100% of the lost capital using a portion of its July trading fee revenue.
Attack Transaction: 0xc52560be…e3e987
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.