XBridge Hack

REPORTED LOSS $1.9M
Medium Permissionless token-owner overwrite followed by withdrawal of bridge reserves Ethereum

What happened

SaitaChain's XBridge was exploited on Ethereum after a permissionless token-listing function could overwrite the stored owner of an already listed asset. The attacker then withdrew bridge reserves. Reported loss estimates range from about $1 million to $1.9 million; this page retains $1.9 million only as an approximate external estimate.

Technical Root Cause

listToken allowed any caller to overwrite _tokenOwner for an already listed asset. withdrawTokens trusted that mutable owner entry, so the attacker could grant itself withdrawal authority over bridge reserves.

Case & protocol details

Classification Access control failure / bridge reserve drain
Protocol Type Exploit/Access control
Implementation language Solidity
Official Website xbridge.tech/
Protocol Twitter/X @XBridge_

How it happened

The attacker paid the listing fee to call listToken for an existing asset, replacing its recorded owner. As the new owner, the attacker called withdrawTokens to remove the bridge's STC reserve. The ownership-overwrite and withdrawal sequence was repeated for other assets including SRLTY and Mazi.

SaitaChain said it was investigating and coordinating with exchanges to block transfers. No source-backed recovery amount has been published.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.