Risk Radar

/ critical

XPR Network / MetalX: proton.swaps exploit and recovery

\~2.1B XPR affected; \~1.85B XPR (87%) recovered; \~277M XPR + 310K METAL escaped to CEXs before freeze.

September 15, 2026Last updated 10:30 UTC2 min read

\~2.1B XPR affected; \~1.85B XPR (87%) recovered; \~277M XPR + 310K METAL escaped to CEXs before freeze.

A September 14 on-chain reconstruction says the September 12 MetalX proton.swaps exploit affected roughly 2.1B XPR: about 1.556B XPR directly plus 563.5M XPR borrowed through lending.loan against stolen stablecoin collateral.

Recovery

Approximately 1.85B XPR, around 87%, was recovered to a governance-controlled treasury. The reconstruction also reports recovery of the stolen stablecoin collateral, including about 1.37M XUSDC and 571K XMD, plus ecosystem-token reserves that remained within administrative reach.

Approximately 277M XPR + 310K METAL escaped to KuCoin, MEXC and Gate.io before the freeze and remain part of the recovery/enforcement track.

Governance boundary

The incident was a contract-accounting/withdrawal failure, not an XPR consensus compromise. Recovery required block-producer intervention. A second issue in eosio.wrap, used for BP recovery actions, also had to be fixed.

Evidence Status

Confirmed / On-chain reconstruction: drain, recovery percentage, escaped balances and submitted fixes. Developing: CEX recovery, law-enforcement outcome and final user/LP accounting.

Risk Assessment

Critical, with materially improved recovery status.

What to Watch Next

CEX freezes, law-enforcement recovery, treasury accounting, contract upgrades and independent review.

FAQ

Is the event confirmed?

The core facts above are limited to the latest verified official, on-chain or reputable incident reporting.

Are community claims included as facts?

No. Community-only claims remain Community / Unverified.

Can the status change?

Yes. Recovery, exchange freezes, votes and liquidation execution can materially change the status.

Does an application exploit mean the base chain failed?

No. Application-layer and governance failures are separated from base-layer consensus.

What should be monitored next?

The event-specific recovery, execution, governance or compensation milestones listed above.