More than $9 million was siphoned out from the XPR network liquidity pool in just 11 minutes. The cause was a swap smart contract that allowed a ‘negative (minus) value’ in the withdrawal request, and the attacker relentlessly exploited this loophole.
Key point
The attacker withdrew more than $9 million from the XPR network liquidity pool for about 11 minutes.
Thanks to a flaw that allowed the withdrawal function to accept negative values, the attacker was able to inflate the internal balance and then remove the actual tokens.
The block producers modified the contract and managed to freeze roughly 1.8 billion XPR, successfully locking most of the stolen funds on-chain.
XPR swap attack targeting the “negative withdrawal” loophole
The target of the attack was the network’s on-chain swap contract, proton.swaps. In that contract, the attacker withdrew approximately 1.56 billion XPR (about $4.03 million at the time).
The core issue was that the withdrawal function allowed negative values.
The attacker exploited this by artificially inflating the “virtual balance” inside the contract and repeatedly withdrawing real tokens according to that amount.
This process continued across multiple pools sharing the same liquidity—such as the stablecoin pool, the bridge asset pool, and the lending (lending) pool—and the cumulative damage exceeded $9 million.
After that, about 563 million XPR (roughly $1.46 million) moved to the lending protocol.
As the attacker used the stolen stablecoins as collateral to trigger additional loans, the total number of tokens directly and indirectly involved in the attack rose to 2.12 billion XPR (about 6.5% of the circulating supply).
Then, about 764 million XPR (roughly $2 million) was moved to a second account.
Also read: XRP ETF records a historic $1.7 billion inflow with net inflows for 9 consecutive weeks
XPR price as support breaks down
The on-chain outflow was reflected in market prices within a few hours.
Following a decline on Sunday, the XPR price fell to around $0.00245 at one point and traded around $0.0026, down about 5.6% over 24 hours.
It dropped below $0.00271, a key support level, and failed to recover throughout the day.
The price, which had briefly risen to as high as $0.00277 earlier in the same session, retreated to a market-cap level of about $74 million.
The RSI dropped to 27.47, entering a deep oversold zone.
This suggests that it was not a gradual price repricing, but a one-way selloff that became concentrated.
Even trading volume at about $2.9 million per day showed that there wasn’t enough buy-side liquidity in the downtrend.
In terms of the absolute scale of damage alone, this incident is relatively smaller compared with major DeFi hacks earlier this year.
However, the bigger warning signal is that a single missed input-value validation in a single swap contract enabled the damage to spread sequentially across multiple protocols sharing the same liquidity, such as lending and bridge asset pools—rather than remaining isolated.
The attacker didn’t need flash loans or oracle manipulation.
One “minus sign” that the contract failed to filter was enough.
Metallicus, XPR frozen after theft
The block producers patched the problematic contract at 21:32 UTC, and about two hours later—around midnight—they froze roughly 1.8 billion XPR and transferred them to a community management wallet.
Among the 1.2 billion XPR that were directly exposed to the attack, the amount that actually left the network was only 319.5 million XPR.
Thanks to this, a substantial portion of the affected volume remains as “recoverable assets.”
This is possible because the XPR network adopts a Delegated Proof-of-Stake (DPoS) structure, allowing a small number of elected block producers to directly intervene in the chain’s state.
In the past, the XPR network has also pulled the same kind of “emergency lever.”
Metallicus, the core development team of the XPR network, previously disclosed in September 2024 that a re-entrancy vulnerability in its lending contract was exploited.
At the time, Metallicus immediately halted deposits, loans, and liquidations, froze the affected funds, and then resumed its lending services in a phased manner the following month.
Next Read: Sam Altman rules out the possibility of an OpenAI IPO in 2026… “AI safety regulation is a stumbling block”
