{"investigation":{"slug":"xtoken","entity_name":"xToken","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":0.87,"status":"published","content_type":"investigation","summary":"xToken (XTK) was a DeFi protocol offering wrapped staking tokens and liquidity management on Ethereum, founded by Michael J. Cohen in 2020. The protocol suffered two major flash loan exploits in 2021 — a $24.5 million attack in May and a $4.5 million attack in August — resulting in total losses exceeding $29 million and the permanent retirement of its flagship xSNX product. The XTK governance token subsequently lost approximately 99.84% of its value, and compensation paid to victims was significantly below the amounts stolen.","sections":[{"content":"xToken was a decentralized finance (DeFi) protocol launched in 2020 and headquartered in Brooklyn, New York. The project was founded by Michael J. Cohen and offered wrapped staking tokens — including xSNXa (Synthetix), xBNTa (Bancor), xAAVEa (Aave), and xKNCa (Kyber Network) — designed to automate staking rewards and compound yields for DeFi users. The protocol also later launched xToken Terminal, described as a capital markets platform for Web3 projects seeking liquidity management tools. xToken raised $3 million in funding across two rounds, with its first funding round in September 2020. The protocol was audited by PeckShield prior to its exploits, though the audit did not prevent either incident.","heading":"Overview","sources":[{"url":"https://medium.com/xtoken/introducing-xtoken-2fd50d0f943b","name":"medium.com","type":"other","credibility":3},{"url":"https://tracxn.com/d/companies/xtokenmarket/__dtK8Ocu4Lkbht1eagx29wYdwwxbeIzmi0c4gIV1rRX0","name":"tracxn.com","type":"other","credibility":3},{"url":"https://www.defipulse.com/blog/founder-fireside-chat-with-michael-j-cohen-of-xtoken","name":"defipulse.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On May 12, 2021, at 9:44 AM EST, an attacker simultaneously exploited xToken's xBNTa and xSNXa contracts in a single transaction, draining approximately $24.5 million from yield-bearing liquidity pools hosted on Bancor and Balancer. The attacker borrowed 61,833 ETH (approximately $267 million) from dYdX via flash loan and used Flashbots MEV for private transaction execution to avoid front-running detection. The xBNTa vulnerability stemmed from the contract's failure to validate the trade path endpoint in its mint function: the attacker supplied a path terminating in a token called SPD rather than BNT, spoofing the contract's accounting and enabling an effectively unlimited mint of xBNTa tokens. The xSNXa vulnerability involved the protocol's reliance on Kyber Network (which in turn sourced from Uniswap v2) for SNX price data; the attacker dumped SNX on Uniswap v2 to suppress prices, then minted approximately 1.2 billion xSNXa tokens for minimal cost before reversing the trades. Total assets stolen included approximately 2,400 ETH (~$10.3 million), 781,000 BNT (~$6.2 million), 407,000 SNX (~$8 million), and 1.9 billion xBNTa tokens. xToken paused minting across all contracts by 10:14 AM UTC and acknowledged the breach publicly. This incident marked the fourth exploit involving PeckShield-audited projects appearing on rekt.news's leaderboard. The attack is documented at rekt.news as 'XToken - REKT.'","heading":"May 2021 Flash Loan Exploit ($24.5 Million)","sources":[{"url":"https://www.coindesk.com/markets/2021/05/12/defi-protocol-xtoken-suffers-245m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/104667/defi-protocol-xtoken-exploit-attack","name":"theblock.co","type":"other","credibility":3},{"url":"https://rekt.news/xtoken-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://medium.com/xtoken/initial-report-on-xbnta-xsnxa-exploit-d6e784387f8e","name":"medium.com","type":"other","credibility":3},{"url":"https://web3isgoinggreat.com/?id=2021-05-12-0","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On August 29, 2021, at 04:43 UTC, xToken suffered a second major exploit, this time targeting its xSNXAdmin contract. The attacker exploited a critical access control flaw: the contract's callFunction used the erroneous check `require(sender==address(this))` instead of the correct `require(msg.sender==soloMarginAddress)`, making the function publicly callable when it should have been restricted to dYdX's SoloMargin flash loan contract exclusively. The attacker borrowed 25,000 ETH from dYdX and approximately 1 million SNX from Aave V1 and Aave V2, then executed large SNX sell orders on Bancor and Kyber to artificially depress SNX prices. They subsequently called the vulnerable function to purchase SNX at suppressed prices, causing approximately $4.5 million in losses to xSNX holders. Notably, the vulnerable code had been introduced to the contracts within three months following the protocol's previous security audit — meaning the audit provided no protection against the introduced flaw. In response, xToken announced it would permanently retire the xSNX product, stating: 'The current xSNX implementation is by far our most complicated product, with complex dependencies and significant surface area for vulnerabilities.' Some sources reported the total value extracted as approximately $6.9–$7 million, while the team reported $4.5 million in net losses to holders. The attack is documented at rekt.news as 'X-Token - REKT X2.'","heading":"August 2021 Flash Loan Exploit ($4.5 Million)","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-xtoken-hack-august-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://rekt.news/xtoken-rekt-x2","name":"rekt.news","type":"other","credibility":3},{"url":"https://medium.com/xtoken/xsnx-post-mortem-666d35071f38","name":"medium.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/beleaguered-defi-project-xtoken-suffers-second-major-exploit-since-may","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://coingeek.com/xtoken-defi-protocol-loses-7m-in-yet-another-exploit/","name":"coingeek.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the May 2021 exploit, xToken proposed a compensation plan allocating XTK governance tokens to affected users. The initial proposal offered 1% of the total XTK supply (10 million tokens) vested over one year. Community feedback pushed the team to revise the proposal upward to 2% of total supply (20 million tokens). At post-hack token prices of approximately $0.192, this represented approximately $3.84 million in compensation — roughly 15% of the $24.5 million stolen. The team justified this level citing the XTK pre-hack fully diluted valuation of approximately $500 million, making the stolen amount roughly 5% of FDV with 2% as a 'fair compromise.' The XTK token had declined approximately 50% immediately following the exploit. Following the August 2021 exploit, the team again pledged a XTK-based compensation program for xSNX holders, but acknowledged the difficulty of full restitution given the treasury's limited size relative to losses. In neither case were users made whole in dollar terms. The protocol's compensation in the form of a declining token rather than stable value has been noted as a structural limitation of such recovery programs in DeFi.","heading":"Compensation and Recovery Efforts","sources":[{"url":"https://beincrypto.com/xtoken-proposes-compensation-after-25m-defi-hack/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://gov.xtoken.cafe/t/proposal-for-compensation-for-xtoken-hack/109","name":"gov.xtoken.cafe","type":"other","credibility":3},{"url":"https://coingeek.com/xtoken-defi-protocol-loses-7m-in-yet-another-exploit/","name":"coingeek.com","type":"other","credibility":3}],"severity":"medium"},{"content":"xToken's contracts were audited by PeckShield prior to the May 2021 exploit. Despite this, both the xBNTa and xSNXa contracts contained critical vulnerabilities. The May 2021 exploit specifically highlighted oracle manipulation risks and the absence of input validation in the xBNTa mint function. The August 2021 exploit added a further failure: the access control bug in the xSNXAdmin callFunction was introduced to the codebase within three months after the existing audit was conducted. This means no audit covered the vulnerable code at the time of the attack, illustrating that security reviews do not protect against post-audit code changes. The rekt.news analysis noted that xToken's May 2021 breach was the fourth documented exploit associated with PeckShield-audited projects. Security analytics platform Halborn later published a technical breakdown of the August 2021 attack, confirming the access control error as the root cause.","heading":"Security Audit Failures","sources":[{"url":"https://rekt.news/xtoken-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-xtoken-hack-august-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://rekt.news/xtoken-rekt-x2","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"},{"content":"The XTK governance token experienced severe and sustained value destruction following the two exploits. After the May 2021 hack, XTK prices fell approximately 50% immediately. By the time of the August 2021 hack, XTK had already declined from an April 2021 peak of approximately $1.36 to roughly $0.12 — a drop of approximately 90% in under five months. As of available data in 2024, XTK traded at fractions of a cent, representing a decline of approximately 99.84% from its all-time high. The protocol's fully diluted market capitalization declined from approximately $500 million to well under $10,000 in market capitalization. Users who received XTK as compensation for the exploits saw the value of those compensation tokens decline further over time. xToken Terminal launched in early 2022 as an attempted pivot toward liquidity mining infrastructure for Web3 projects, but the protocol never recovered meaningful user adoption or TVL.","heading":"Token Price Collapse and Long-Term Impact","sources":[{"url":"https://beincrypto.com/xtoken-proposes-compensation-after-25m-defi-hack/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/beleaguered-defi-project-xtoken-suffers-second-major-exploit-since-may","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://medium.com/xtoken/xtoken-2-0-a8e8db69eefd","name":"medium.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/xtoken","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"xToken has been flagged by ZachXBT, the pseudonymous on-chain investigator known for documenting crypto fraud, exploits, and rug pulls. While the specific context of ZachXBT's flag on xToken is not independently documented in available Tier 1 or Tier 2 sources, the protocol's inclusion on trust intelligence platforms at a score of 10/100 reflects the cumulative weight of two confirmed major exploits totaling over $29 million in losses, inadequate victim compensation, a near-total token value collapse, and repeated smart contract failures. The protocol appears on rekt.news's leaderboard — a widely referenced Tier 2 registry of DeFi exploits — with two separate entries.","heading":"ZachXBT and Community Flags","sources":[{"url":"https://rekt.news/xtoken-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://rekt.news/xtoken-rekt-x2","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-09-10","event":"xToken completes its first funding round, raising funds toward a total of $3 million across two rounds. Protocol founded by Michael J. Cohen in Brooklyn, NY.","source":""},{"date":"2021-05-12","event":"xToken suffers its first major exploit. An attacker borrows 61,833 ETH via dYdX flash loan and exploits vulnerabilities in both xBNTa (invalid mint path) and xSNXa (oracle manipulation via Uniswap v2 / Kyber). Approximately $24.5 million is drained from Bancor and Balancer liquidity pools. Assets stolen include ~2,400 ETH, 781,000 BNT, 407,000 SNX, and 1.9 billion xBNTa tokens. xToken pauses minting across all contracts.","source":""},{"date":"2021-05-16","event":"xToken proposes a compensation plan offering 1% of XTK supply to hack victims, vested over one year. Community feedback leads to an upward revision to 2% (~20 million tokens, worth approximately $3.84 million at prevailing prices — roughly 15% of the stolen amount).","source":""},{"date":"2021-08-29","event":"xToken suffers its second major exploit. An attacker exploits an access control bug in the xSNXAdmin callFunction (using `require(sender==address(this))` instead of verifying the dYdX flash loan caller). The attacker borrows 25,000 ETH from dYdX and 1 million SNX from Aave, manipulates SNX price, and extracts approximately $4.5 million from xSNX holders.","source":""},{"date":"2021-08-30","event":"xToken announces permanent retirement of the xSNX product and pledges a second XTK-based compensation program for affected users. XTK is trading at approximately $0.12, down ~90% from its April 2021 peak of ~$1.36.","source":""},{"date":"2022-03","event":"xToken launches xToken Terminal, a rebranded capital markets and liquidity management platform for Web3 projects, representing an attempted pivot away from staking token products.","source":"","date_original":"2022-03-01"},{"date":"2024","event":"XTK token trades at approximately $0.0000244 — a decline of approximately 99.84% from its all-time high. Market capitalization falls below $10,000. Protocol never recovers meaningful total value locked (TVL).","source":"","date_original":"2024-01-01"}],"sources_used":[{"url":"https://medium.com/xtoken/introducing-xtoken-2fd50d0f943b","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://tracxn.com/d/companies/xtokenmarket/__dtK8Ocu4Lkbht1eagx29wYdwwxbeIzmi0c4gIV1rRX0","name":"tracxn.com","type":"other","archive_url":"https://web.archive.org/web/20260902145318/https://tracxn.com/d/companies/xtoken-market/__dtK8Ocu4Lkbht1eagx29wYdwwxbeIzmi0c4gIV1rRX0#reports","credibility":3,"archive_timestamp":"2026-09-02T14:53:18+00:00"},{"url":"https://www.defipulse.com/blog/founder-fireside-chat-with-michael-j-cohen-of-xtoken","name":"defipulse.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coindesk.com/markets/2021/05/12/defi-protocol-xtoken-suffers-245m-exploit","name":"coindesk.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.theblock.co/post/104667/defi-protocol-xtoken-exploit-attack","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20251129224236/https://www.theblock.co/post/104667/defi-protocol-xtoken-exploit-attack","credibility":3,"archive_timestamp":"2025-11-29T22:42:36+00:00"},{"url":"https://rekt.news/xtoken-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260517233157/https://rekt.news/xtoken-rekt","credibility":3,"archive_timestamp":"2026-05-17T23:31:57+00:00"},{"url":"https://medium.com/xtoken/initial-report-on-xbnta-xsnxa-exploit-d6e784387f8e","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://web3isgoinggreat.com/?id=2021-05-12-0","name":"web3isgoinggreat.com","type":"other","archive_url":"https://web.archive.org/web/20260830131259/https://www.web3isgoinggreat.com/?id=2021-05-12-0","credibility":3,"archive_timestamp":"2026-08-30T13:12:59+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-xtoken-hack-august-2021","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260414114649/https://www.halborn.com/blog/post/explained-the-xtoken-hack-august-2021","credibility":3,"archive_timestamp":"2026-04-14T11:46:49+00:00"},{"url":"https://rekt.news/xtoken-rekt-x2","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260608195229/https://rekt.news/xtoken-rekt-x2","credibility":3,"archive_timestamp":"2026-06-08T19:52:29+00:00"},{"url":"https://medium.com/xtoken/xsnx-post-mortem-666d35071f38","name":"medium.com","type":"other","archive_url":"http://web.archive.org/web/20260322055925/https://medium.com/xtoken/xsnx-post-mortem-666d35071f38","credibility":3,"archive_timestamp":"2026-03-22T05:59:25+00:00"},{"url":"https://cointelegraph.com/news/beleaguered-defi-project-xtoken-suffers-second-major-exploit-since-may","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260801051138/https://cointelegraph.com/news/beleaguered-defi-project-xtoken-suffers-second-major-exploit-since-may","credibility":3,"archive_timestamp":"2026-08-01T05:11:38+00:00"},{"url":"https://coingeek.com/xtoken-defi-protocol-loses-7m-in-yet-another-exploit/","name":"coingeek.com","type":"other","archive_url":"http://web.archive.org/web/20260801051139/https://coingeek.com/xtoken-defi-protocol-loses-7m-in-yet-another-exploit/","credibility":3,"archive_timestamp":"2026-08-01T05:11:39+00:00"},{"url":"https://beincrypto.com/xtoken-proposes-compensation-after-25m-defi-hack/","name":"beincrypto.com","type":"other","archive_url":"http://web.archive.org/web/20251014111252/https://beincrypto.com/xtoken-proposes-compensation-after-25m-defi-hack/","credibility":3,"archive_timestamp":"2025-10-14T11:12:52+00:00"},{"url":"https://gov.xtoken.cafe/t/proposal-for-compensation-for-xtoken-hack/109","name":"gov.xtoken.cafe","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/xtoken/xtoken-2-0-a8e8db69eefd","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://defillama.com/protocol/xtoken","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250913230934/https://defillama.com/protocol/xtoken","credibility":3,"archive_timestamp":"2025-09-13T23:09:34+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:54.788503+00:00","updated_at":"2026-09-02T14:57:08.527658+00:00"}}