XPR Network patched a smart contract vulnerability in proton.swaps that allowed negative withdrawals. Recovery efforts recovered approximately 1.856 billion XPR tokens (87% of stolen assets) and 100% of stablecoins, with 20 block producers coordinating the multisig recovery and broader infrastructure improvements underway.
Mizo (MIZO) denies claims that its smart contract project is fake or plagiarized, arguing that creating a full platform requires more than copying a frontend—including GitHub history, backend systems, smart contracts, and infrastructure. The team invites critics to provide evidence of the alleged original project.
A liquidity pool smart contract exploit on XPR Network was quickly contained with 90% of funds recovered immediately and more recoverable. The network itself remained secure; only the swap contract was compromised. Metallicus is coordinating with exchanges to freeze remaining funds, with over 85% expected to be recovered.
XPR Network's proton.swaps contract was exploited on September 12, 2026, with attackers draining 1.56B XPR and millions in other tokens through a double-withdraw bug that allowed subtracting negative values. The attacker account was created hours before the attack and funded from KuCoin; stolen funds have moved across exchanges while Metallicus has not issued an official statement.
A smart contract exploit resulted in $326 million appearing unexpectedly, trending on X as of September 12, 2026. Details of the incident are referenced in a post by ContraCop.
A trending discussion on X about smart contract exploits, hacks, or drains. Sumex Labs, a Web3 SuperApp, posted about crypto wallet security on September 9, 2026.