XPR Network Loses $9M in Smart Contract Exploit, Shaking Investor Confidence
XPR Network, a layer 1 blockchain, suffered a major exploit after an attacker found a flaw in the withdrawal function of its proton.swaps protocol. The function incorrectly accepted negative amounts, allowing the attacker to manipulate internal balances before withdrawing real tokens. This technique was applied across several asset pools, including XUSDC, XMD, METAL, LOAN and bridged assets, resulting in more than $9 million drained within just 11 minutes.
The attacker also borrowed against stolen stablecoins through the LOAN protocol, bringing the total XPR tokens touched to roughly 2.12 billion, about 6.5% of the circulating supply. Funds were subsequently moved between accounts, though most of the tokens, around 1.80 billion, remained within attacker-controlled accounts on the network rather than reaching external exchanges. Network producers identified the issue and applied a patch to the contract at 21:32 UTC, limiting further losses.
The incident had a visible impact on market confidence, with XPR's price falling sharply the following day before a partial recovery. The event highlights how a single weak point in input validation can cascade rapidly across interconnected liquidity pools in decentralised finance systems.