# protocol exploit — X 热门讨论 (2026-09-17 16:38 UTC)

## @xExchangeApp (xExchange ⚡) · 09-17 16:22 · ♥23 ↻10 💬3 Trading has resumed on the MEX/EGLD, MEX/USH and MEX/USDC pairs following coordinated recovery work with Hatom. Hatom has confirmed that user funds remain safe. xExchange users do not need to take any action.

On Sunday evening, Hatom contacted xExchange after investigating concentrated MEX buying and a sharp price rise over a short period. Based on the full onchain sequence and the economics of the positions, Hatom concluded that this was a deliberate attempt to exploit its MEX money market—not ordinary trading activity. According to its analysis, MEX was repeatedly bought and deposited as collateral, enabling further borrowing as the price used to value that collateral increased. The trades incurred slippage losses while the borrowing position became less healthy. Hatom concluded that the route to profit depended on borrowing against an inflated collateral valuation, not on trading gains.

Hatom's analysis also showed that allowing the activity to continue would have put its money market at risk of bad debt and user losses. Because liquidity in the affected xExchange pools was thin relative to the size of the position, liquidation would likely have triggered large automatic MEX sales, severe slippage and a disorderly price decline. This would have materially harmed xExchange users exposed through MEX and the MEX/EGLD, MEX/USH and MEX/USDC pools.

xExchange believes in open markets. We would not pause trading to shield a protocol from normal market outcomes or to defend a token price. Temporarily pausing markets is an extraordinary measure. In this case, the evidence presented by Hatom showed a malicious cross-protocol attack with severe downstream consequences for users. In our assessment, and that of the independent experts consulted, the risk warranted temporary intervention to protect users while Hatom contained and unwound the attack.

Only the MEX/EGLD, MEX/USH and MEX/USDC pairs were paused. All other xExchange pairs and the rest of xExchange's frontend and API functionality remained available. The affected pairs were reopened after Hatom confirmed that the attacker-driven positions had been removed and it was safe to proceed.

We are grateful to everyone who helped assess the risk and safely restore normal operations.

Hatom has moved separately to compensate users affected on its money market and will publish its detailed incident report and recovery accounting. We will also use the lessons from this incident to strengthen escalation contacts and joint-response processes across the ecosystem.

Thank you for your support. https://x.com/xExchangeApp/status/2100621427779018974