Telegram (AI) YouTube Facebook X
Ру
OKX DEX loses $430,000 in hack

OKX DEX loses $430,000 in hack

The OKX decentralized exchange (DEX) was exploited for $430,000 following an alleged leak of the proxy server administrator’s private key.

Update:

According to PeckShield analysts, the amount of damage rose to approximately $2.76 million.

According to SlowMist’s analysis, during an exchange on the platform users authorize the TokenApprove contract, which then transfers the user’s tokens. 

The ClaimTokens function enables a trusted proxy server of the DEX to call it. The servers are managed by administrators who can independently modify the smart contract. 

On December 12, the owner of one of the servers updated it, enabling direct calls to ClaimTokens to transfer users’ tokens. The attacker exploited this vulnerability. 

According to DeBank, the hacker’s address holds tokens worth $430,000.

Experts Scopescan contacted OKX representatives, who stressed that the attack targeted an “old abandoned market-maker contract.” In their words, the exploit has been detected and stopped.

Later, on the platform’s official X page, a statement was posted. The exchange said it revoked permissions for the attacked server. 

We are working with the relevant authorities to locate the stolen funds. We will reimburse the losses to those affected. An extensive review is currently underway to prevent similar incidents. We apologise for the inconvenience caused,

Earlier Immunefi researchers calculated that since the start of 2023 the crypto industry has faced 296 incidents of hacks and fraud, and losses from such incidents have surpassed $343 million.

Earlier in November, the hacker withdrew assets from KyberSwap’s liquidity pool worth $47 million. Later he demanded full control over the project.

Подписывайтесь на ForkLog в социальных сетях

Telegram (основной канал) Facebook X
Нашли ошибку в тексте? Выделите ее и нажмите CTRL+ENTER

Рассылки ForkLog: держите руку на пульсе биткоин-индустрии!

We use cookies to improve the quality of our service.

By using this website, you agree to the Privacy policy.

OK