logo

XPEPE Token Incident Analysis

ID: 8b665ec6-602f-53ab-836f-ccbaac5d193a

STIX ID: report--8b665ec6-602f-53ab-836f-ccbaac5d193a

Feed Name: CertiK Blog

Threat Score
55/100

Date Published: 2025-02-12

Date Updated: 2026-06-11

...
...

On 25 January 2025 an attacker used a Uniswap V3 flash loan to stake then repeatedly withdraw and call transferFrom against XPEPE's TokenStaker due to an un-revoked spend allowance, allowing iterative token duplication and draining the pool (99% price drop); the attacker sold the drained tokens for ~0.6805 ETH. The report includes the exploit transaction link, involved addresses and contracts, funding traces via Tornado Cash and Orbiter Bridge, and identifies the root cause as missing allowance revocation in withdrawAll().

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.