xPet Hack
What happened
xPET, a Social Fi and Game Fi platform on Arbitrum, was exploited due to a smart contract vulnerability, resulting in a loss of 91.5 ETH worth 256,570 USD.
On February 16, 2024, xPET's on-chain PvP contract was exploited, allowing the attacker to withdraw a large amount of $BPET tokens. The vulnerability was related to the newly launched PvP feature. The attacker dumped over 1 million BPET tokens to obtain 91.5 ETH, which was then transferred to another EOAs and bridged to the Ethereum chain via Across Protocol.
The CEO of xPET, @Michaeltalkhere posted on X account that how they got the money back.The attacker returned all part of the stolen funds in two transactions on Feb 17,2024.
Attacker Address:
https://arbiscan.io/address/0x22518a5c…c99f31
Funds Holder as of Feb 17, 2024:
https://arbiscan.io/address/0x0671E335…79B6e1
Malicious Transactions:
https://arbiscan.io/tx/0x058b8808…03dec6
https://arbiscan.io/tx/0x1ad1f753…c4ef53
Funds Returned Transactions:
https://arbiscan.io/tx/0x825e63fd…d541ee
https://arbiscan.io/tx/0xaeb79241…9c2573
Bridged Transaction via Across Protocol:
https://arbiscan.io/tx/0x43230132…9276bf
CEO's post on X about stolen funds reward:
https://twitter.com/Michaeltalkhere/status/1758558740461306362
Case & protocol details
Funds Recovery
Recovered
$255K
Net Loss
$1,796
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- analysis Web Archive archive.is
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.