xToken Hack

Reported loss $4.5M
Ethereum
Flashloan Price Oracle Attack

What happened

On August 29, 2021, xToken's Ethereum xSNX product was exploited for an estimated $4.5 million loss to holders. The attacker combined a 25,000-ETH flash loan, SNX borrowing, and trades that sharply depressed the SNX price. They then invoked a rebalance-related xSNXAdmin function that xToken intended to restrict to its dYdX flash-loan integration.

xToken decided to sunset xSNX and said it would calculate investor losses for a compensation program.

How it happened

  1. The attacker flash-borrowed 25,000 ETH, borrowed approximately 1 million SNX from Aave, and acquired additional SNX on Bancor.
  2. They sold approximately 1.5 million SNX through Kyber, materially lowering the SNX price, then exchanged the resulting USDC for sUSD.
  3. The attacker transferred sUSD to xSNXAdmin and called callFunction, which burned the contract's sUSD debt and exchanged SNX at the artificially depressed price.
  4. They reversed the surrounding trades, repaid the loans, and extracted value through the price distortion and resulting external arbitrage.

Protocol details

Classification Ecosystem / Token / Oracle Manipulation
Protocol Type Liquidity manager
Affected asset / contract XTK
Implementation language Solidity
Protocol links Website @xtokenmarket

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.