UXLINK hack — September 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 22, 2025 |
| Target type | Token contract |
| Loss | $11,300,000Published estimates range $11,300,000 to $41,000,000Price at time of incident |
| Method | Access control flawA delegateCall executed in the context of UXLINK's multi-signature wallet removed the existing signers and installed the attacker as sole owner on Ethereum and Arbitrum, giving control of the treasury and the token contract's mint function |
| Chains | Ethereum, Arbitrum |
| Outcome | Users reimbursed |
What happened
UXLINK, a Web3 social platform issuing the UXLINK token on Ethereum and Arbitrum, lost control of its multi-signature treasury wallet on 22 September 2025. On-chain analysis by Blockscope and AMLBot describes the attacker using a delegateCall to execute code in the wallet's context, removing the existing signers and installing their own address as sole owner on both chains at about 14:45 UTC. How the attacker obtained the ability to trigger that call has not been publicly explained; UXLINK's own notices refer to compromised keys.
Within about ten minutes the treasury was drained of roughly $4 million USDT, $500,000 USDC, 3.7 WBTC, 25 ETH and around 490 million UXLINK tokens. Monitoring firm Cyvers put the immediate loss at about $11.3 million; Blockscope described roughly $12 million extracted.
The attacker then used control of the token contract to mint additional UXLINK — reported quantities vary widely between sources — and sold them, bridging about 6,732 ETH (roughly $28.1 million) from Arbitrum to Ethereum and converting much of it to DAI. Counting those sales, analysts placed the attacker's realised proceeds near $41 million. That larger figure is contested as a theft number, because most of it came from selling newly minted tokens into liquidity pools and exchange order books rather than from draining assets UXLINK already held. The token fell more than 70 per cent.
UXLINK deployed a new contract with a hard-capped supply and ran a 1:1 migration for holders qualifying at a snapshot taken at the attacker's first transfer, covering gas itself. Exchanges froze part of the proceeds. Within a day the attacker was itself phished, losing hundreds of millions of UXLINK tokens to an address linked to Inferno Drainer.
Sources
- UXLINKPrimary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- BlockscopeSecondary · retrieved 2026-08-01
- UnchainedSecondary · retrieved 2026-08-01
- AMLBotSecondary · retrieved 2026-08-01
Official post-mortem: https://docs.uxlink.io/layer/announcement/notice
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "UXLINK hack — September 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/uxlinkhttps://itokenly.com/hacks/uxlinkPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.