X319 Hack

Reported loss $13K
BNB Chain
Improper Access Control

What happened

On November 9, 2024 an attacker drained 20.85 BNB (about $12,900) from the staking contract of the X319 protocol on BNB Chain in a single transaction. The contract's claimEther function had no check on who was calling it. TenArmor noted it was meant to be called only by the X319 token after it had confirmed a user's claim eligibility. A decompilation of the unverified contract shows the function's only check was that the receiver was not the operator. Any caller other than the operator triggered a plain BNB transfer of the requested amount to the receiver.

Attacker: 0xe60329a82c5add1898ba273fc53835ac7e6fd5ca Attack contract: 0x54588267066ddbc6f8dcd724d88c25e2838b6374 Attack tx: 0x679028cb0a5af35f57cbea120ec668a5caf72d74fcc6972adc7c75ef6c9a9092

How it happened

  1. The staking contract held 20.85 BNB as its own balance.
  2. The attacker deployed a contract whose constructor called claimEther(tx.origin, 20.85 BNB) on the staking contract.
  3. Because the caller was not the operator, claimEther took the branch that sends native BNB and transferred the full 20.85 BNB to the attacker's wallet. No flash loan or price manipulation was involved.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.