X319 Hack
What happened
On November 9, 2024 an attacker drained 20.85 BNB (about $12,900) from the staking contract of the X319 protocol on BNB Chain in a single transaction. The contract's claimEther function had no check on who was calling it. TenArmor noted it was meant to be called only by the X319 token after it had confirmed a user's claim eligibility. A decompilation of the unverified contract shows the function's only check was that the receiver was not the operator. Any caller other than the operator triggered a plain BNB transfer of the requested amount to the receiver.
Attacker: 0xe60329a82c5add1898ba273fc53835ac7e6fd5ca
Attack contract: 0x54588267066ddbc6f8dcd724d88c25e2838b6374
Attack tx: 0x679028cb0a5af35f57cbea120ec668a5caf72d74fcc6972adc7c75ef6c9a9092
How it happened
- The staking contract held 20.85 BNB as its own balance.
- The attacker deployed a contract whose constructor called
claimEther(tx.origin, 20.85 BNB)on the staking contract. - Because the caller was not the operator,
claimEthertook the branch that sends native BNB and transferred the full 20.85 BNB to the attacker's wallet. No flash loan or price manipulation was involved.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.