Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Did Craig Wright file his latest COPA appeal from China?

    May 29, 2026

    Weak demand could push LTC below $90

    May 29, 2026

    Mashinsky targets FTX and rewrites Celsius narrative

    May 29, 2026
    Facebook X (Twitter) Instagram
    Block Buzz News
    • Bitcoin
    • Coinbase
      • Litecoin
      • Altcoins
    • Blockchain
    • Crypto
    • Ethereum
    • Lithosphere News Releases
    Facebook X (Twitter) Instagram YouTube
    Block Buzz News
    Home » DxSale exploit drains $7.3M in BNB through hidden contract backdoor
    Crypto

    DxSale exploit drains $7.3M in BNB through hidden contract backdoor

    James WilsonBy James WilsonMay 29, 2026No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    DxSale has suffered a $7.3 million exploit after an attacker allegedly used a hidden backdoor in a liquidity locker contract to withdraw BNB locked by more than 1,400 liquidity providers on the BNB Chain.

    Summary

    • DxSale lost $7.3 million in a BNB Chain exploit affecting roughly 1,400 liquidity providers.
    • Researchers linked the attack to a hidden contract backdoor and a previously undisclosed ownership transfer.
    • The incident follows a wave of DeFi exploits, with protocols losing $52 million to hacks so far in May.

    According to blockchain security firm PeckShield, the attacker-controlled address “0xC457” moved approximately $1.87 million worth of BNB into two primary wallets before sending the funds to multiple deposit addresses associated with Binance.

    The incident affected liquidity that had remained locked in DxSale contracts since the platform was widely used for token launches on BNB Chain in 2021.

    Early findings from blockchain analyst Tahax suggest the exploit may have originated from a contract ownership change that took place months before the attack.

    “Here’s how the exploit unfolded. 269 days ago, the DxSale deployer quietly transferred ownership of the locker to a new wallet…No announcement, no migration notice, just a silent handoff.”

    Tracing the ownership history further, Tahax said more than 80 additional transactions were used to pass control between wallets before it eventually reached the address identified as “0xC45,” which later executed the large-scale BNB withdrawals.

    The analyst also noted that the exploiter wallet was newly created and initially funded through crypto exchange Bybit.

    Researchers point to contract-level weakness

    Additional analysis from Web3 security firm Coinsult linked the exploit to a privileged contract function and a manipulated lock period. According to Coinsult, the combination allowed funds that were supposed to remain locked to be treated as withdrawable balances.

    ❗ About that DxSale locker ‘backdoor’, we have analysed it on-chain. Here is our take:

    The drainer: 0xc2efbd94…01e4718, unverified, solc 0.8.33, deployed ~9h ago by 0xC4574DD…aaFA69. It hardcodes the victim locker as an immutable + WBNB for routing, and gates every function… https://t.co/POq7z2C8Pp

    — Coinsult – Audits & Development (@CoinsultAudits) May 28, 2026

    The security firm said a privileged “setFee” mechanism, combined with a backdated lock configuration, enabled repeated withdrawal actions that ultimately drained the BNB reserves. Tahax separately alleged that a backdoor had been left in the deployer contract, creating conditions for the exploit.

    By the time investigators identified the attack path, some of the stolen funds had already moved through infrastructure that may complicate tracking efforts, according to Tahax.

    DeFi security concerns grow after recent attacks 

    The latest breach arrives as decentralized finance platforms continue to face security incidents across multiple networks.

    Data from DefiLlama shows DeFi protocols have lost about $52 million to exploits so far in May, following roughly $634 million in losses recorded during April, the highest monthly total since February 2025.

    Security concerns intensified this week after Stake DAO disclosed an exploit involving its vote-boosted sdCRV token on Arbitrum. Blockchain security company Blockaid reported that an attacker minted more than 5.4 trillion vsdCRV tokens and began exchanging them for ETH, while Stake DAO urged users not to interact with the asset as investigators tracked transactions across Arbitrum and Ethereum.

    Elsewhere, Wasabi Protocol reported losses exceeding $5 million after a compromised administrative key allowed attackers to upgrade contracts and drain funds across Ethereum, Base, Berachain, and Blast.

    Amid the recent string of incidents, OpenZeppelin co-founder Manuel Aráoz warned that advances in AI-assisted vulnerability discovery are making attacks easier to execute.

    In comments cited earlier by crypto.news, Aráoz said he now considers “all of DeFi” unsafe because attackers increasingly have access to powerful tools that can identify software weaknesses before developers can patch them.

    According to DefiLlama, crypto exploits have resulted in more than $17 billion in cumulative losses, including roughly $7.8 billion stolen from DeFi protocols alone.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    James Wilson

    Related Posts

    Mashinsky targets FTX and rewrites Celsius narrative

    May 29, 2026

    What led to Mark Cuban’s viral Bitcoin dump?

    May 29, 2026

    Bitcoin price at crossroads as bearish setup points to more losses

    May 29, 2026

    Trump vows to push pro-Bitcoin policies; SHRMiner cloud mining’s $7,000 passive income opportunity draws attention

    May 29, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    CHART: Gold gained twice the market cap of BTC in three days

    March 30, 2026

    CORE price crashes 48% as volume tops market cap in violent unwind

    March 30, 2026

    Fusaka Update – Information for Blob users

    March 30, 2026

    CZ cries FUD as anti-Binance posts flood X

    March 30, 2026
    Don't Miss
    Coinbase

    Did Craig Wright file his latest COPA appeal from China?

    By John SmithMay 29, 2026

    Craig Wright’s whereabouts have been a mystery since the conclusion of his UK court battle…

    Weak demand could push LTC below $90

    May 29, 2026

    Mashinsky targets FTX and rewrites Celsius narrative

    May 29, 2026

    Who is behind World Liberty Financial, Trump’s new crypto?

    May 29, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us

    BlockBuzzNews: Your daily dose of the latest in cryptocurrency trends, insights, and updates!

    Our Picks

    Did Craig Wright file his latest COPA appeal from China?

    May 29, 2026

    Weak demand could push LTC below $90

    May 29, 2026

    Mashinsky targets FTX and rewrites Celsius narrative

    May 29, 2026
    Most Popular

    CHART: Gold gained twice the market cap of BTC in three days

    March 30, 2026

    CORE price crashes 48% as volume tops market cap in violent unwind

    March 30, 2026

    Fusaka Update – Information for Blob users

    March 30, 2026

    Type above and press Enter to search. Press Esc to cancel.