X7 Finance Hack
What happened
On October 8, 2026, X7 Finance’s X7Pioneer contract on Ethereum was exploited for approximately 6.78 ETH (~$16,514 USD) due to a reward accounting logic flaw in claimRewards() that repeatedly credited unrecorded ETH balances when called with an empty token array.
The vulnerability existed in the X7Pioneer contract (0x7000...) within its claimRewards() function, which incremented totalRewards by address(this).balance - lastETHBalance on every invocation but updated lastETHBalance only when claimable > 0. The attacker purchased X7 Pioneer NFT #300 for 0.15 ETH and donated additional ETH directly to the contract to widen the balance delta, then repeatedly invoked claimRewards() passing an empty array to keep claimable at zero. Because lastETHBalance was never updated, each empty-array call repeatedly added the same unrecorded ETH delta to totalRewards, artificially inflating the per-token reward index.
The attacker then claimed the inflated rewards to drain 6.78 ETH from the contract, subsequently routing 3.3 ETH into Tornado Cash and transferring the remaining proceeds across secondary wallet addresses.
Attack Transaction Hash: 0xc98056d6…21766d
Attacker Address: 0xc7935211…7bacf2
Vulnerable Contract: 0x70000299…c9e4f7
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.