Onchain Security Roundup: Sep 7 - 14

Nexus Mutual Team

·

XPR Network Metal X Swap Smart Contract Exploit

~1.56 billion XPR (~$4 million at the time) plus stablecoin and other pool assets drained, per community and press; block producers seized ~1.8 billion XPR from the attacker's account. No official XPR Network statement had been made at the time of this report.

XPR Network (formerly Proton) is a blockchain built on Antelope (EOSIO) technology, and Metal X Swap is its main decentralised exchange. Users deposit pairs of tokens into liquidity pools, and the exchange contract keeps a running balance for each depositor so they can withdraw their share later.

On September 12th, an attacker exploited a withdrawal function that accepted negative amounts, a bug that’s been present since the contract's last code update in March 2022. Withdrawing a negative amount made the contract increase the attacker's recorded balance instead of reducing it. A second, positive withdrawal then paid out that balance to the attacker. Every drained pool shows this two-call pattern onchain: 58 withdraw actions in matching negative/positive pairs. They pulled 1,556,473,391 XPR and drained the XUSDC, XMD, METAL, LOAN and ten other pool tokens, then deposited the stolen stablecoins (1.37M XUSDC, 572k XMD) as collateral on the LOAN lending protocol to borrow a further 563.6 million XPR: 2.12 billion XPR touched in total, about 6.5% of circulating supply. Exactly 319.5 million XPR (plus ~310k METAL) reached exchange deposit accounts, mostly KuCoin and MEXC.

XPR's block producers, the validators who run the chain, patched the contract at 21:32 UTC. At 23:26 UTC, they replaced the keys on the attacker's account, seizing about 1.8 billion XPR that still sat in the wallet. That seizure covered a large part of what was taken but did not fully settle the position. In an unwind executed via producer multisig early on September 13th, 565 million XPR was repaid to LOAN, the stablecoin collateral was redeemed in full, and all recovered assets were swept to a ‘recoverfunds’ account; ~48 million XPR sent toward one venue was also returned. The shortfall is the ~275 million XPR and METAL already at exchanges, recoverable only with exchange or legal cooperation, and liquidity providers remain unpaid until the announced pool refill completes.

Chainflip Cross-Chain Swap Exploit

736,442 USDT (protocol-reported); funds flagged, and Chainflip has pledged to make affected users whole.

Chainflip is a cross-chain swap network. A user deposits an asset on one chain and Chainflip's validators pay out a different asset on another chain. In early September it added support for USDT on Tron. On Tron, Chainflip reads swap instructions from a memo attached to the transaction itself, where most other supported chains use dedicated contract functions instead.

In the early hours of September 12th, an attacker found a way to attach a memo of their own to a transaction Chainflip's validators had already signed. Chainflip's systems read that memo as a separate swap request, treated it as malformed, and issued a refund, causing the same deposit to be paid out twice. Chainflip's public explorer data corroborates this account. Six Tron USDT deposits marked failed with reason INVALID_BROKER_FEES between 02:00 and 03:04 UTC, each roughly doubling the last — 13,000; 26,240; 52,468; 104,924; 209,836; 330,000 — totalling 736,468 USDT, about 26 USDT above the protocol's figure. Zero-amount phantom swap entries starting at 01:38 UTC put the full run at ~86 minutes, matching Chainflip's "eight times over about ninety minutes." Smaller USDT payouts kept clearing through the morning, but a 1.5 BTC swap due to pay 115,654 USDT at 09:59 UTC could not be paid (the pending swap Chainflip reported) and the network was paused.

Chainflip says only Tron USDT was affected and describes a memo-handling flaw rather than a key compromise. The Tron-side transaction identifiers and attacker address remain unpublished, the explorer is protocol-operated infrastructure, and neither the code change nor a third-party review of the fix has been released. The pause also cut off one of the two routes Symbiosis had moved its BTC swaps to just a day earlier (see the Symbiosis exploit section below).

Splash Protocol Smart Contract Exploit (Optim OADA Pool)

~2.43 million ADA and ~1.99 million OADA withdrawn from the pool; the attacker realised roughly 2.55 million ADA (~$520,000) after selling the OADA into a thin market. No recovery had been announced at the time of this report.

Splash is a decentralised exchange on Cardano. One of its pools paired ADA with OADA, a synthetic version of ADA issued by Optim Finance, and it was effectively the only liquid venue where OADA could be traded back into ADA. Like any stableswap pool, it holds reserves of both assets and, on every trade, checks that the amount leaving the pool is consistent with the amount coming in.

The failure was in how the pool's smart contract did that arithmetic. According to Splash's incident report, the contract tracked total reserves and a separate protocol-fee balance, and it calculated the tradable reserves as total reserves minus fees before running its trade checks. Three safeguards were missing: nothing required the calculated tradable reserves to stay positive; the fee accounting had only a lower bound, so a depositor could declare almost all of a deposit as protocol fees; and nothing checked that a swap actually sent one asset in while the other came out. At 00:47 UTC on September 13th, the attacker deposited ~9,870 ADA in a way the contract booked as fees. Forty-five seconds later, a second transaction withdrew 2,434,648 ADA and 1,988,222 OADA, all of the pool's ADA and ~1.99 million of its 3.43 million OADA. The contract's calculated tradable ADA reserve went negative, and because its checks assumed positive numbers, they passed. The Cardano ledger itself never holds a negative balance and no assets were created out of nothing. The negative figure was an internal number inside the pool's accounting that the contract should have rejected and did not.

The attacker, seeded with 12,186 ADA from a KuCoin withdrawal wallet 17 minutes earlier, netted ~2.42 million ADA and sold the OADA — via a thin FLDT pool on Minswap, its only meaningful exit — for just ~115,000 ADA. Roughly 2.55 million ADA went to KuCoin, Gate.io and two unidentified custodial clusters. One KuCoin deposit address had been used on September 9th, an account link Splash is pursuing. The drained pool cannot operate, and Optim has paused OADA, whose peg mechanism depended on this pool. Anastasia Labs audited the code in 2024. The swap logic was unchanged since, and none of the eight findings covered these checks. All figures are from Splash's own incident report.

Symbiosis Bitcoin Bridge Exploit (root cause not published)

~369 billion unbacked syBTC minted across two chains; observed attacker proceeds ~309 ETH (~$750,000), of which ~$336,000 came from a single WBTC conversion flagged by Blockaid. Symbiosis reports recovering ~15 BTC and says final accounting is in progress.

Symbiosis is a cross-chain swap protocol whose Bitcoin Bridge lets users move BTC into DeFi as a synthetic token, syBTC, backed by BTC the bridge holds. When a deposit is confirmed, a signed cross-chain message instructs the destination-chain contract to mint matching syBTC.

Starting at 04:28:40 UTC on September 11th, eight signed messages within 55 seconds, four on BNB Chain and four on Ethereum, each minted exactly 46.1 billion syBTC to the same freshly created wallet – 369 billion total, thousands of times more than all bitcoin in existence. The minted amount appears hand-crafted rather than the product of an accounting overflow. The messages arrived through Symbiosis's own relayer and the bridge's standard receive function, which narrows the failure to message authorization (a forged, replayed, or improperly validated signature). Symbiosis has not published why the messages were accepted, so the root cause is unresolved. The attacker ran small test transactions 105 minutes beforehand. Nothing capped any mint by the BTC the bridge held.

Because the tokens were unbacked, their face value is meaningless. The attacker could only realise what liquidity existed. Blockaid observed the same wallet selling about 4.39 WBTC on Ethereum for ~$336,000. That figure covers only the conversion Blockaid saw, not the protocol's total loss. Other analysts have put the realised figure at $376,000 and $750,000, and Symbiosis has said it will publish confirmed numbers once its accounting is complete. Symbiosis paused the Bitcoin Bridge, isolated the affected contracts and rerouted BTC swaps through Chainflip and THORChain. The Symbiosis team reports having recovered about 15 BTC to a team-controlled multisig, offered the attacker a 20% bounty through September 13th, and has since offered the same reward for information leading to recovery. A compensation framework for liquidity providers has been promised, but no terms have been published.

Zentra Finance Smart Contract Exploit

~$143,000 (protocol-reported) taken from the ctUSD reserve; lending markets paused and a bounty offered to the attacker. No recovery had been reported at the time of writing.

Zentra is an Aave v3 fork on Citrea, a zero-knowledge rollup bringing Ethereum-style contracts to bitcoin. Depositors receive receipt tokens (zUSDC, zctUSD) for supplied assets. Aave v3 lets borrowers repay debt by burning these receipt tokens instead of transferring the underlying.

At 12:59 UTC on September 9th, the attacker flash-borrowed 200,000 USDC.e as collateral, borrowed 140,000 ctUSD, deposited just 50 ctUSD for 50 zctUSD, then repaid the full debt with receipt tokens they didn't hold. The root cause is visible in the deployed, explorer-verified source: stock Aave v3 reverts when burning more receipt tokens than the caller owns, but Zentra added a "safety guard" that silently caps the burn at the caller's balance, added to patch a one-wei rounding revert introduced by their own rounding changes, while the repay logic still cleared the full debt. Burning ~50 zctUSD thus erased a 140,000 ctUSD debt, and the attacker withdrew their collateral whole.

The exploited code was effectively unaudited. Zentra's Sherlock collaborative audit (Jan–Feb 2026; 46 findings, all addressed) scoped only Zentra's custom modules, not the modified Aave core. The vulnerable code was deployed on June 25th, three months after the report and three days after Zentra's published source snapshot, which still shows the stock, safe version.

Zentra's onchain message offers a negotiable bounty and no legal action if the attacker replies by 12:00 UTC September 14th, with escalation otherwise. Whether the bounty was accepted, and what ctUSD holders' final position is, had not been reported at the time of this report.

YAM Finance Governance Takeover

~48 WETH and ~763 UMA (~$121,000) withdrawn from two legacy farming contracts; the attacker still controls YAM's governance Timelock, and no recovery has been reported.

YAM Finance launched in 2020 and has been largely dormant for years, but its governance contracts were never shut down. Token holders could still submit and vote on proposals, and the Timelock, the contract that executes approved proposals after a delay, still held administrative rights over old farming contracts that contained real collateral.

On September 1st, a freshly funded wallet holding ~5 ETH bought 504,427 YAM tokens (~3.3% of supply, just over quorum), delegated the voting power to itself and proposed making itself the pending admin of the Timelock. With almost no other votes cast, the proposal passed against thresholds set for 2020 levels of participation. It was queued on September 3rd and executed on September 8th, at which point the attacker accepted the admin role and queued a change cutting the Timelock delay from five days to twelve hours. That change took effect on September 13th, and on September 14th the attacker used the shortened delay to take control of two legacy UMA farming contracts, settle their expired positions to release the WETH held as collateral, and transfer about 48 WETH and 763 UMA to their own address. The UMA was swapped to ETH and 48.15 ETH was cashed out to four fresh addresses within four hours (via FixedFloat, per Defimon).

The campaign is still running. By 15:55 UTC on September 14th, the attacker had also captured YAMReserves2, IndexStaking2, TreasuryManager and a third farming contract (the last releasing another 1.14 WETH) and a capture of the YAM token contract itself sits queued. The takeover was visible onchain from September 1st, nearly two weeks before funds moved, and monitoring services flagged it publicly on September 2nd. No recovery or response from the YAM community has been reported.

ether.fi Legacy Contract Access Control Exploit

~15.45 ETH (~$38,000) taken from about a dozen users, per SlowMist; ether.fi says affected users will be reimbursed in full.

ether.fi is one of the largest liquid restaking protocols on Ethereum. The loss did not come from its vaults or from any compromised key. It came from the AtomicQueue, a retired helper contract built by Veda that once processed user withdrawal requests. Users who had used the queue in the past had granted it permission to move their tokens, and some had not revoked that permission after the contract was deprecated.

According to SlowMist, the queue's function for filling requests lets anyone specify which "solver" was fulfilling a request without checking that the caller actually was that solver. Around 07:21 UTC on September 11th, an attacker deployed a contract that, in a single transaction, submitted withdrawal requests naming itself as recipient and then forced each of eleven victims to act as the solver, causing the queue to pull their still-approved tokens via those leftover allowances. Nine users lost liquidETH (ether.fi's Veda-built Liquid vault token) and two lost USDC. The tokens were swapped to ETH on Uniswap, and 15.5 ETH was deposited into Tornado Cash within minutes.

ether.fi CEO Mike Silagadze said the affected contract was an old Veda-built queue that a small number of users had approved, that the issue was resolved, and affected users would be reimbursed. The 15.45 ETH figure is SlowMist's; the vulnerable queue and the drained liquidETH both belong to the same deprecated Veda stack.

Nomic Bridge Exploit (June incident disclosed by Osmosis in September)

40.65 nBTC (~$3.1 million) minted with no bitcoin behind it on June 25th, per Osmosis; ~671 ETH (~$1 million) sent through Tornado Cash; 22.65 allBTC frozen in the attacker's account. Osmosis's Alloyed BTC basket is reported to be about 36% unbacked, with a recovery plan under governance discussion.

Nomic is a small Cosmos chain that issues nBTC, a token meant to be backed one-for-one by BTC held by the bridge. Osmosis, the largest Cosmos exchange, combines several BTC-backed tokens, including nBTC, into a single basket token called Alloyed BTC (allBTC).

The attack occurred in June but was only recently disclosed in September. According to Osmosis, on June 25th an attacker combined two bugs in a custom message-forwarding mechanism on Nomic's side of the bridge to double-spend nBTC and send Osmosis false vouchers, minting 40.650602 nBTC on Osmosis with no BTCdeposited. Osmosis says its own chain and IBC, the standard messaging layer between Cosmos chains, were not compromised. The attacker deposited 39.84 nBTC into the allBTC basket, swapped out into other assets, bridged the proceeds to Ethereum and sent ~671 ETH, nearly $1 million at the time, to Tornado Cash between June 25th and June 28th.

The hole went undisclosed for 74 days. Nomic appears to be unmaintained (Protos reports its X account last posted in 2024 and its last GitHub commit was two years ago), and the exploit only surfaced when the Nomic chain halted and Osmosis examined its holdings. Osmosis disclosed the incident on September 9th, froze Nomic-related flows and executed an emergency upgrade freezing 22.65 allBTC still sitting in the attacker's account. That freeze stops the assets from moving but is not restitution. allBTC remains unbacked by roughly 36% of its declared BTC, and a governance proposal described by Protos would seize the frozen allBTC, cancel a pending liquidity redeployment and draw further allBTC from the Osmosis community pool to restore backing. The proposal had not been executed at the time of this report, and neither Nomic nor Osmosis have published a code-level analysis.

Contact us to structure cover for your portfolio

Subscribe to our newsletter

Be the first to know about our latest news, announcements and events!

This website is operated by Collective Risk Services CIC, with its registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, on behalf of Terrapin International Foundation

© 2026 Nexus Mutual