The staking platform Stader updated its NEAR staking solution. The NearX smart contract was attacked. After discovering the problem, the team managed to fix the problem and protect the funds of most users. Currently, about 2.5 million NEARs pledged on the Stader DApp are safe. This attack The losses are mainly related to LP NEAR liquidity. In addition, the team has suspended any operations on the NearX contract and is investigating the issue and stress testing further with Halborn and BlockSec. The specific attack methods are as follows: 1. Stader’s smart contract on NEAR has a vulnerability related to NearX minting. The attacker (gregoshes.near) exploits this and mints 20 million NearX by transferring the NearX cycle to its own address. But no NEAR was mortgaged; 2. The attacker exchanged the minted NearX for NEAR in the Near/NearX liquidity pool of Ref Finance and Jumbo Exchange, exhausting all NEAR liquidity; 3. The team suspended the NearX smart contract and all NearX Transaction; 4. The estimated loss is 165,000 NEAR, and the specific figure is currently being determined.