<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=XCarnival_Collateral_Logic_Error</id>
	<title>XCarnival Collateral Logic Error - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=XCarnival_Collateral_Logic_Error"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=XCarnival_Collateral_Logic_Error&amp;action=history"/>
	<updated>2026-07-26T11:15:39Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=XCarnival_Collateral_Logic_Error&amp;diff=5632&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/xcarnivalcollaterallogicerror.php}} {{Unattributed Sources}}  XCarnival Logo/Branding/HomepageXCarnival created a lending protocol which allowed participants to use their NFTs as collateral for loans. Unfortunately, the protocol wasn't entirely bullet-proof and was exploited by an attacker, who found a way to take out a loan and still retrieve the NFT they had put up as...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=XCarnival_Collateral_Logic_Error&amp;diff=5632&amp;oldid=prev"/>
		<updated>2024-04-08T20:03:24Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/xcarnivalcollaterallogicerror.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Xcarnival.jpg&quot; title=&quot;File:Xcarnival.jpg&quot;&gt;thumb|XCarnival Logo/Branding/Homepage&lt;/a&gt;XCarnival created a lending protocol which allowed participants to use their NFTs as collateral for loans. Unfortunately, the protocol wasn&amp;#039;t entirely bullet-proof and was exploited by an attacker, who found a way to take out a loan and still retrieve the NFT they had put up as...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/xcarnivalcollaterallogicerror.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Xcarnival.jpg|thumb|XCarnival Logo/Branding/Homepage]]XCarnival created a lending protocol which allowed participants to use their NFTs as collateral for loans. Unfortunately, the protocol wasn't entirely bullet-proof and was exploited by an attacker, who found a way to take out a loan and still retrieve the NFT they had put up as collateral. The attacker funded their account through TornadoCash and took the proceeds back through TornadoCash. They gave up half of their loot in exchange for a promise by the protocol against legal retribution.&lt;br /&gt;
&lt;br /&gt;
This is a global/international case not involving a specific country.&amp;lt;ref name=&amp;quot;newsletter-13117&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;peckshieldtwitter-13228&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-13229&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-13230&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;xcarnivallabtwitter-13231&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cryptotimes-13232&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;xcarnivallabmedium-13233&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cryptonomist-13234&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;xcarnivallabtwitter-13235&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;xcarnivalfi-13236&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;mexcblog-13237&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;mexc-13238&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;talbeerysectwitter-13239&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-13240&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-13241&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-13242&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-13243&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-13244&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About XCarnival ==&lt;br /&gt;
&amp;quot;A more convenient lending protocol for everyone.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;XCarnival is here to create a metaverse financial infrastructure. They will focus on providing liquidity options for all your metaverse assets. Furthermore, they hope to create an industry ecosystem for NFT and Metaverse. In order to do so, they are offering mortgage and loan services for NFT assets. These financial services are available in their P2P and Pool2C models. In addition, they also provide appraisal, leasing and sales solutions for your metaverse long-tail assets. Their featured products are XBroker and XPawn.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;XBroker is a smart contract on an EVM-based public chain. It is an NFT pledge and lending platform. It offers liquidity to the NFT market. In XBroker, users take parts in three different roles: mortgagor, lender and liquidator. It works in a very straightforward way. First, the mortgagor must submit an NFT to pledge and borrow money. Then the lender will earn interest by lending USDxc. Liquidator will then bid at the auction to collect NFTs.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;XCarnival is a lending aggregator for Metaverse assets, which offers innovative liquidation solutions for varieties of NFTs and long- tail crypto assets. As a pioneer of NFT lending provider, XCarnival has won the Championships of BSC Hackathon for Southeast Asia. It‘s also one of the first projects educating users to adopt the NFT-lending modes with mining rewards. XCarnival is a multi-chain protocol and will deploy on Ethereum, Polygon and Solana.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;On June 26, 2022 XCarnival lost $3.8M after an attacker exploited a logic error in the collateral handling mechanism.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The hack is made possible by allowing a withdrawn pledged NFT to be still used as the collateral, which is then exploited by the hacker to drain assets from the pool.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The initial fund (120 ETH) to launch the hack is withdrawn from @TornadoCash. Currently  3,087 ETHs of the illicit gains still stay in the hacker’s account&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Negotiations to partially return stolen funds are ongoing.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The hacker pledged one NFT, Bored Ape #5110, as security for a loan. The Bored Ape used as collateral should typically be locked up until the debt is paid up.&lt;br /&gt;
&lt;br /&gt;
But the hacker was able to retrieve the Bored Ape without paying back the loan and then used it to get a new loan by exploiting a vulnerability. This action was repeated many times, emptying 3,087 ETH from the protocol.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The overall logic is that the hacker first generates multiple contract addresses, then goes to call the XNFT contract, pledges the NFT, then generates an orderld, then withdraws the NFT, multiple times this operation, then calls the XToken contract’s borrow() through the previous contract address as well as the orderld In the call to borrow(), there is no judgment that the NFT has been withdrawn, so the hacker borrowed and then did not pay it back, then keeps repeating this operation.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;XCarnival then communicated with the hacker on-chain and asked for the funds to be returned. &lt;br /&gt;
&lt;br /&gt;
The platform first offered a $300,000 award as restitution for the stolen funds. The hacker later accepted XCarnival’s updated offer of giving them half of the ETH.&lt;br /&gt;
&lt;br /&gt;
The initial funding for the hack, around 120 ETH, was taken out via Tornado Cash. Security organizations and the police have since then worked closely to find the hacker’s geographical location. &lt;br /&gt;
&lt;br /&gt;
However, XCarnival did agree not to take legal action against the hacker in exchange for returning half of the stolen money.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;XCarnival was attacked on June 26, 2022 and suspended part of the protocol. XCarnival officials will give 0xb7CBB4d43F1e08327A90B32A8417688C9D0B800a owner 1500 ETH bounty. At the same time, XCarnival officals explicitly exempt the person from legal action.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
This is a global/international case not involving a specific country.&lt;br /&gt;
&lt;br /&gt;
The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.&lt;br /&gt;
&lt;br /&gt;
Include:&lt;br /&gt;
&lt;br /&gt;
* Known history of when and how the service was started.&lt;br /&gt;
* What problems does the company or service claim to solve?&lt;br /&gt;
* What marketing materials were used by the firm or business?&lt;br /&gt;
* Audits performed, and excerpts that may have been included.&lt;br /&gt;
* Business registration documents shown (fake or legitimate).&lt;br /&gt;
* How were people recruited to participate?&lt;br /&gt;
* Public warnings and announcements prior to the event.&lt;br /&gt;
&lt;br /&gt;
Don't Include:&lt;br /&gt;
* Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.&lt;br /&gt;
* Anything that wasn't reasonably knowable at the time of the event.&lt;br /&gt;
There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - XCarnival Collateral Logic Error&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|June 26th, 2022 5:12:24 AM MDT&lt;br /&gt;
|First NFT Purchase&lt;br /&gt;
|The first NFT purchased by the exploiter to use as collateral for the exploit.&lt;br /&gt;
|-&lt;br /&gt;
|June 26th, 2022 6:03:30 AM MDT&lt;br /&gt;
|Blockchain Transaction&lt;br /&gt;
|A transaction references on the blockchain as part of the attack.&lt;br /&gt;
|-&lt;br /&gt;
|June 26th, 2022 7:14:00 AM MDT&lt;br /&gt;
|PeckShield Tweet&lt;br /&gt;
|PeckShield shares a tweet about the incident.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount lost has been estimated at $3,800,000 USD.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?&lt;br /&gt;
&lt;br /&gt;
A bounty of $1,900,000 USD was paid for the discovery.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
The total amount recovered has been estimated at $1,900,000 USD.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;newsletter-13117&amp;quot;&amp;gt;[https://newsletter.blockthreat.io/p/blockthreat-week-25-2022 BlockThreat - Week 25, 2022 - by Peter Kacherginsky] (Mar 18, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;peckshieldtwitter-13228&amp;quot;&amp;gt;[https://twitter.com/peckshield/status/1541047171453034501 @peckshield Twitter] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-13229&amp;quot;&amp;gt;[https://etherscan.io/tx/0xd365248aeab9e3200d07464ca1268ed4aa6cd5cc1fa6c5b33dfce158a758212b https://etherscan.io/tx/0xd365248aeab9e3200d07464ca1268ed4aa6cd5cc1fa6c5b33dfce158a758212b] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-13230&amp;quot;&amp;gt;[https://etherscan.io/txs?a=0xb7cbb4d43f1e08327a90b32a8417688c9d0b800a https://etherscan.io/txs?a=0xb7cbb4d43f1e08327a90b32a8417688c9d0b800a] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;xcarnivallabtwitter-13231&amp;quot;&amp;gt;[https://twitter.com/xcarnival_lab/status/1541226298399653888 @xcarnival_lab Twitter] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cryptotimes-13232&amp;quot;&amp;gt;[https://www.cryptotimes.io/2022/06/27/xcarnival-retrieves-50-of-stolen-eth-after-exploit/ XCarnival Retrieves 50% of Stolen ETH After Exploit | The Crypto Times] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;xcarnivallabmedium-13233&amp;quot;&amp;gt;[https://xcarnival-lab.medium.com/xcarnival-has-got-1-467-eth-back-the-security-agencies-have-tentatively-determined-the-hackers-3ea05ad134ae XCarnival has got 1,467 ETH back, the security agencies have tentatively determined the hacker’s geographic location | by XCarnival | Medium] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cryptonomist-13234&amp;quot;&amp;gt;[https://en.cryptonomist.ch/2022/06/28/xcarnival-hacker-reward/ XCarnival hacker accepts reward - The Cryptonomist] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;xcarnivallabtwitter-13235&amp;quot;&amp;gt;[https://twitter.com/XCarnival_Lab @XCarnival_Lab Twitter] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;xcarnivalfi-13236&amp;quot;&amp;gt;[https://xcarnival.fi/Home XCarnival] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;mexcblog-13237&amp;quot;&amp;gt;[https://blog.mexc.com/what-is-xcarnival-xcv/ What is XCarnival (XCV) • MEXC Blog] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;mexc-13238&amp;quot;&amp;gt;[https://www.mexc.com/tokens/XCV XCV | XCV Crypto Asset Introduction | MEXC Exchange] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;talbeerysectwitter-13239&amp;quot;&amp;gt;[https://twitter.com/TalBeerySec/status/1541329941203226624 @TalBeerySec Twitter] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-13240&amp;quot;&amp;gt;[https://etherscan.io/idm?addresses=0xc087629431256745e6e3d87b3ec14e8b42d47e48,0xb7cbb4d43f1e08327a90b32a8417688c9d0b800a&amp;amp;type=1 https://etherscan.io/idm?addresses=0xc087629431256745e6e3d87b3ec14e8b42d47e48,0xb7cbb4d43f1e08327a90b32a8417688c9d0b800a&amp;amp;type=1] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-13241&amp;quot;&amp;gt;[https://etherscan.io/tx/0x16bb7799cf4e919bcb81f3ed531743ea6a6857e9a5121500fa1e3619bb2b82cf https://etherscan.io/tx/0x16bb7799cf4e919bcb81f3ed531743ea6a6857e9a5121500fa1e3619bb2b82cf] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-13242&amp;quot;&amp;gt;[https://etherscan.io/token/0xbc4ca0eda7647a8ab7c2061c2e118a18a936f13d?a=0xb7cbb4d43f1e08327a90b32a8417688c9d0b800a https://etherscan.io/token/0xbc4ca0eda7647a8ab7c2061c2e118a18a936f13d?a=0xb7cbb4d43f1e08327a90b32a8417688c9d0b800a] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-13243&amp;quot;&amp;gt;[https://etherscan.io/tx/0x51cbfd46f21afb44da4fa971f220bd28a14530e1d5da5009cfbdfee012e57e35 https://etherscan.io/tx/0x51cbfd46f21afb44da4fa971f220bd28a14530e1d5da5009cfbdfee012e57e35] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-13244&amp;quot;&amp;gt;[https://etherscan.io/address/0xb7cbb4d43f1e08327a90b32a8417688c9d0b800a https://etherscan.io/address/0xb7cbb4d43f1e08327a90b32a8417688c9d0b800a] (Apr 8, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>