xPet Hack
Incident Overview
xPET, a Social Fi and Game Fi platform on Arbitrum, was exploited due to a smart contract vulnerability, resulting in a loss of 91.5 ETH worth 256,570 USD.
On February 16, 2024, xPET's on-chain PvP contract was exploited, allowing the attacker to withdraw a large amount of $BPET tokens. The vulnerability was related to the newly launched PvP feature. The attacker dumped over 1 million BPET tokens to obtain 91.5 ETH, which was then transferred to another EOAs and bridged to the Ethereum chain via Across Protocol.
The CEO of xPET, @Michaeltalkhere posted on X account that how they got the money back.The attacker returned all part of the stolen funds in two transactions on Feb 17,2024.
Attacker Address:
https://arbiscan.io/address/0x22518a5c…c99f31
Funds Holder as of Feb 17, 2024:
https://arbiscan.io/address/0x0671E335…79B6e1
Malicious Transactions:
https://arbiscan.io/tx/0x058b8808…03dec6
https://arbiscan.io/tx/0x1ad1f753…c4ef53
Funds Returned Transactions:
https://arbiscan.io/tx/0x825e63fd…d541ee
https://arbiscan.io/tx/0xaeb79241…9c2573
Bridged Transaction via Across Protocol:
https://arbiscan.io/tx/0x43230132…9276bf
CEO's post on X about stolen funds reward:
https://twitter.com/Michaeltalkhere/status/1758558740461306362
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to xPet, these are the critical security checks that could have prevented this incident (February 2024).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialFunds Recovery
Recovered
$255K
Net Loss
1795
Sources & References
- 01
-
02
Web Archive https://archive.is/FMMq1
Learn to Prevent the Next xPet
The xPet hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.