XPEPE Token Incident Analysis
ID: 8b665ec6-602f-53ab-836f-ccbaac5d193a
STIX ID: report--8b665ec6-602f-53ab-836f-ccbaac5d193a
Feed Name: CertiK Blog
On 25 January 2025 an attacker used a Uniswap V3 flash loan to stake then repeatedly withdraw and call transferFrom against XPEPE's TokenStaker due to an un-revoked spend allowance, allowing iterative token duplication and draining the pool (99% price drop); the attacker sold the drained tokens for ~0.6805 ETH. The report includes the exploit transaction link, involved addresses and contracts, funding traces via Tornado Cash and Orbiter Bridge, and identifies the root cause as missing allowance revocation in withdrawAll().
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
