X7 Finance Hack

Reported loss $16K
Abandoned

What happened

On October 8, 2026, X7 Finance’s X7Pioneer contract on Ethereum was exploited for approximately 6.78 ETH (~$16,514 USD) due to a reward accounting logic flaw in claimRewards() that repeatedly credited unrecorded ETH balances when called with an empty token array.

The vulnerability existed in the X7Pioneer contract (0x7000...) within its claimRewards() function, which incremented totalRewards by address(this).balance - lastETHBalance on every invocation but updated lastETHBalance only when claimable > 0. The attacker purchased X7 Pioneer NFT #300 for 0.15 ETH and donated additional ETH directly to the contract to widen the balance delta, then repeatedly invoked claimRewards() passing an empty array to keep claimable at zero. Because lastETHBalance was never updated, each empty-array call repeatedly added the same unrecorded ETH delta to totalRewards, artificially inflating the per-token reward index.

The attacker then claimed the inflated rewards to drain 6.78 ETH from the contract, subsequently routing 3.3 ETH into Tornado Cash and transferring the remaining proceeds across secondary wallet addresses.

Attack Transaction Hash: 0xc98056d6…21766d

Attacker Address: 0xc7935211…7bacf2

Vulnerable Contract: 0x70000299…c9e4f7

Protocol details

Classification Exchange (DEX)
Protocol Type DEX
Protocol links Website @X7_Finance

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.