The DeFi project 79thVault, operating on the BNB Chain, has suffered a loss of approximately $12.5 million due to a series of suspicious transactions involving the 79AU token. Experts from GoPlus Security have suggested the possibility of a compromised key or insider involvement.
According to specialists, the attacker exploited a privileged function within the 79AU contract, leading to the withdrawal of around 2.01 million tokens from the liquidity pool. This action allowed the perpetrator to obtain roughly 16,249 BNB, equivalent to $12.5 million.
Monitoring services detected unusual activity from the project's wallet. Typically, this address conducted minor transfers to the rewards pool; however, during the incident, it executed seven transactions ranging from 10,000 to 500,000 79AU each. These transfers coincided with a significant spike in the asset's price.
Suspicion Falls on Privileged Key
GoPlus reports that the 79AU contract includes a function accessible to wallets with OPERATOR_ROLE privileges, which allow for token transfers from a designated address and subsequent synchronization of pool reserves.
This role was held by an address that performed seven privileged operations during the incident. Researchers noted that mechanisms such as multi-signature and time-lock were not utilized to manage these privileges. Following the attack, the operator's privileges were revoked.
Additionally, GoPlus pointed out that the contract's source code has not been verified on BscScan, complicating users' ability to independently assess the logic of the privileged functions.
Where Are the Stolen Funds?
After selling the 79AU tokens, the obtained BNB was consolidated across several addresses. One of these addresses contained approximately 14,395 BNB, valued at $11 million. The attacker later transferred 30 BNB to the KuCoin exchange. As of the time of publication, no further movements of the majority of the funds have been recorded.
The project has also sent a message to the blockchain offering a 10% reward for the return of the stolen funds.
Hack or Insider Attack?
The definitive cause of the incident remains undetermined. The theory of a private key leak could explain the unusual activity from the operational wallet, but researchers do not discount the possibility that an individual within the project may have facilitated the access.
Further questions arise from reports of "negotiations" with the alleged attacker. GoPlus indicated that this communication was sent from the same privileged address used to withdraw the funds. While it could be an attempt to reach out to the assailant, researchers urge caution, as the message does not verify the identity of the sender.
The 79thVault team announced a "system upgrade," during which "some front-end features may be unavailable." The project has not commented on the incident, the extent of the damage, or the experts' speculations.
📢 79VAULT SYSTEM UPGRADE 🔧 Our technical team is performing system optimizations to enhance stability and performance. ⚠️ Some front-end features and asset-related operations may be temporarily affected. Services will resume after the upgrade. Thank you for your patience! 💛
— 79th Vault (@79thVault) October 8, 2026
It is important to note that in September, the crypto industry faced losses exceeding $768 million due to hacks, marking the worst figure since the beginning of the year, according to PeckShield.
Follow ForkLog on social media
Telegram (main channel) Facebook X