RISEx Issues Announcement Today: An RWA Strategy Linked to Its XLP Vault Suffered Unauthorized Withdrawals, Involving an Amount of 673,011.56 USDC.
According to the official statement, the incident was caused by a configuration error left behind during a July 13 deployment. The team discovered it within minutes and completed the fix. Key points are as follows:
① No loss of funds to XLP depositors;
② All losses have been covered by RISEx using the partial protocol fees from July;
③ RISEx main protocol is operating normally, and the incident was isolated to a single strategy;
④ The team reviewed all transactions and other strategies, confirming that the anomaly occurred only in this one instance;
⑤ A post-mortem report will be released later;
⑥ Currently working with SEAL 911 to trace the funds, and attempting to contact the relevant addresses to negotiate their return.
From an emergency response perspective, the team reacted quickly, user funds were not affected, and it proactively assumed the losses and involved a third-party security firm for collaboration—overall, the response posture was relatively proactive. However, the configuration error went unnoticed for nearly three weeks and was exploited, revealing weaknesses in monitoring alerts and the release audit process.
For RWA protocols, while cross-chain assets and strategy combinations can improve capital efficiency, any lapse in parameters or permission configuration could be precisely detected and exploited by an attacker. RWA’s “security” depends not only on the authenticity of the underlying assets, but also on the engineering rigor at the strategy execution layer.
We will continue to monitor the incident, paying close attention to the attack path and improvement measures disclosed in the post-mortem report.
#RWA #DeFi安全 #RISEx