Low Smart contract exploit Source: SlowMist Team

X7.Finance experienced a loss of approximately 6.78 ETH due to a vulnerability in its `claimRewards()` function

X7.Finance experienced a loss of approximately 6.78 ETH due to a vulnerability in its `claimRewards()` function. The `totalRewards` variable was incorrectly incremented without proper updates to `lastETHBalance` when rewards were not claimable.

Protocols
X7.Finance
Confidence
High
First seen
8 Oct 2026, 10:38 UTC

Read the original report ↗ (opens in a new tab)