T
iTokenly

xToken (xSNX) hack — August 2021

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedAugust 29, 2021
Target typeOther
Loss$4,500,000Price at time of incident
MethodAccess control flawA callback function in the xSNXAdmin contract, intended to be reachable only by dYdX's SoloMargin flash loan contract, checked the wrong condition (it compared against the contract's own address rather than SoloMargin's), leaving it publicly callable. The attacker combined this with price manipulation: a 25,000 ETH flash loan from dYdX and roughly 1 million SNX borrowed from Aave were used to push the SNX price down across Bancor, Kyber and Curve, after which the exposed callback made the xSNX contract buy SNX at the depressed price. Exploit transaction: 0x924e6a6288587b497f73ddcf6ae3c184f15ab35dfcb85f3074b55266974029ef
ChainsEthereum
Audited beforehandYes
OutcomeUnresolved

What happened

xToken, an Ethereum protocol that issued tokenised versions of yield strategies, lost about $4.5 million from its xSNX product on 29 August 2021 at 04:43 UTC. It was the protocol's second major exploit that year, following a roughly $24.5 million loss in May.

The root cause, set out in xToken's own post-mortem, was an access control bug in the xSNXAdmin contract. A callback function intended to be reachable only by dYdX's SoloMargin flash loan contract checked the wrong condition, comparing against the contract's own address instead of SoloMargin's, which left the function callable by anyone.

The attacker combined that flaw with price manipulation. They took a 25,000 ETH flash loan from dYdX and borrowed around one million SNX from Aave, then traded across Bancor, Kyber and Curve to push the price of SNX down. With SNX artificially cheap, they invoked the exposed callback to make the xSNX contract buy SNX at the depressed price, then unwound the trades and repaid the loans, keeping the difference. Halborn's later analysis reached the same conclusion and noted that the vulnerable code had been added within the three months before the attack, after the contract had been audited.

xToken said it would sunset xSNX, which it described as by far its most complicated product, and announced a compensation programme denominated in its XTK token, with snapshot scripts written to calculate individual losses including for holders who redeemed after the exploit. The stolen funds were not recovered and no attacker has been publicly identified or charged.

Sources

  1. xTokenPrimary · retrieved 2026-08-01
  2. HalbornSecondary · retrieved 2026-08-01
  3. crypto.newsSecondary · retrieved 2026-08-01

Official post-mortem: https://medium.com/xtoken/xsnx-post-mortem-666d35071f38

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "xToken (xSNX) hack — August 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/xtoken-xsnx
https://itokenly.com/hacks/xtoken-xsnx

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.