← Radar

Incident case file

Sign in to watch

RISEx XLP Vault RWA Strategy Misconfiguration

Incident date 2026-08-02Last updated Aug 14, 2026

2 views

ResolvedRISE ChainSmart contract misconfigurationCluster: RISX-CFG-2026-08

Estimated loss

$673.0K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

95%

Facts and investigation

Ledger

Attacker

0xAAb85f96FeB6DaAc1E171e7e4B0118B16f1BB66d (caller/initiator, on-chain verified)

Funds moved to

673,011.565895 USDC.e withdrawn via exploited contract 0x04a7934245c9B804082e391Ee077c130d31B10a5 (source without publicly verified code) from source address 0x2C03C7d7e2974C6599b6B108879109281ef3F818. Funds traced through two RiseVault contracts (0xdEc93a1d6dE0267d5cDF3b1342A49b105AE37EF8 and 0x776e385A599B71AF893f58B4b8f8a67A5d9d63e5) into a TransparentUpgradeableProxy (0xA6FfE66379C34B85cd2Ff4B3c8A73D3dE7ABA043), which forwarded funds to a USDCMintBurnAdapter (0x82675d0553D802039e6776C006BEb1

Linked

Transaction 0xc52560bec154a3d5533a321bd9805305a5076194573ddb2fbb059059ace3e987 (block 18135959, timestamp 07:21:58 UTC August 3, 2026, fully verified on RISE Explorer/Blockscout) documents the complete fund flow. RISEx (rise.trade) is a fully on-chain perpetuals exchange operating on RISE Chain, backed by Galaxy Ventures and angel investors including Vitalik Buterin. Per independent analysis (PerpFinder), RISEx had no completed third-party security audit at the time of the incident despite opera

Chronology

1 beat
  1. T-X (July 13, 2026): RISEx deploys a Real World Asset (RWA) strategy linked to its XLP vault. A misconfiguration in the strategy's access control is introduced at deployment and remains undetected for approximately three weeks. T0 (August 3, 2026, 07:21:58 UTC, block 18135959): An unauthorized withdrawal of 673,011.565895 USDC.e occurs from the RWA strategy. The transaction is initiated by caller address 0xAAb85f96FeB6DaAc1E171e7e4B0118B16f1BB66d interacting with contract 0x04a7934245c9B804082e391Ee077c130d31B10a5. Funds are routed internally through two RiseVault contracts, then to a TransparentUpgradeableProxy, and finally to a USDCMintBurnAdapter contract, which burns the USDC.e — indicating an off-chain or cross-chain redemption pathway rather than a simple wallet transfer. T+minutes: RISEx's team detects the unauthorized withdrawal within minutes of its occurrence, per their own subsequent public statement. T+48 minutes (08:09 UTC): The team deploys a patch resolving the misconfiguration; all other components of the RISEx platform continue operating normally throughout the incident and its remediation. Post-incident (same day, 18:47:14 UTC): RISEx publishes an official statement via its X account confirming the exploit, the patch timeline, and stating that XLP vault depositors have been fully compensated using a portion of the platform's July fee revenue. The team states it reviewed every transaction and deployment during the affected period and confirmed this was the only unauthorized withdrawal to have occurred. No user funds remain lost as a result; the incident is closed with 100% compensation to affected depositors, funded entirely by the platform rather than external insurance or third-party recovery.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)