xToken Hack

TOTAL LOST $4.5M
Medium Flashloan Price Oracle Attack / Flash Loan Attack / Spot Price Manipulation ethereum
Chain ethereum Primary network
Recovered - No recovery reported
Loss Rank #531 All-time
Audit Firms 1 Before incident

What happened

The exploitation of Synthetix and Bancor protocols led to a loss of $24.5M in ETH, BNT, SNX, and xBNTa tokens.

The attacker initiated the exploit by borrowing a 61.8k ETH flash loan from dYdX. They then deposited 10k ETH to borrow 564k SNX on Aave and swapped 5.5k ETH for 700k SNX on SushiSwap. The attacker sold 1.2M SNX for 818 ETH on Uniswap v2, significantly reducing the SNX price. They then used only 0.12 ETH to mint 1.2B xSNXa, because the protocol buys SNX through Kyber, who in turn led to use Uniswap v2 for this swap. However, within the protocol, the xSNXa price turned out to be normal, which made it possible to swap 105M xSNX into 414 ETH. The attacker then began to do reverse swaps in SushiSwap and Uniswap and repaid loans in Aave. They began to sell the existing xSNXa to the Balancer SNX/ETH/xSNXa (25/25/50) pool, repaid the flash loan to dYdX, issued xBNTa four times for 0.03 ETH, which ultimately gave them 3.9B xBNTa, and swapped half of xBNTa to 781k BNT.

Stolen funds:

- 2.4k ETH ($10.3M)

- 781k BNT ($6.2M)

- 407k SNX ($8M)

- 1.9B xBNTa

The attacker's address:

https://etherscan.io/address/0x07e02088…79dc3e

The transaction behind the attack:

https://etherscan.io/tx/0x7cc7d935…40da22

Case & protocol details

Classification Ecosystem / Token / Oracle Manipulation
Protocol Type Liquidity manager
Affected asset / contract XTK
Smart Contract Language Solidity
Official Website xtoken.market/
Protocol Twitter/X @xtokenmarket
Team Anonymous
Source Code Unverified

Market Context at Time of Hack

Token Categories
Marketplace Centralized Exchange (CEX) Token Discount Token Ethereum Ecosystem Made in China

Audit assessment

Review priorities based on the documented failure pattern in xToken (August 2021).

Critical checks

  • Verify every sensitive logic path is guarded by appropriate access controls and input validation - see the Flash Loan Attacks attack class for patterns
  • Audit oracle price feeds for manipulation risks - ensure time-weighted average prices (TWAPs) or multi-source aggregators are used, not spot prices

Review history

A prior review is not a guarantee of safety, particularly when code changes after the reviewed version.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.