Close Menu

    Subscribe to Updates

    What's Hot

    Sui price prediction 2026-2030: beyond USDsui

    May 29, 2026

    Examples of Digital Assets in Real Life

    May 29, 2026

    DxSale exploit drains $7.3M in BNB through hidden contract backdoor

    May 29, 2026
    Facebook X (Twitter) Instagram
    laicryptolaicrypto
    Demo
    • Ethereum
    • Crypto
    • Altcoins
    • Blockchain
    • Bitcoin
    • Lithosphere News Releases
    laicryptolaicrypto
    Home DxSale exploit drains $7.3M in BNB through hidden contract backdoor
    Crypto

    DxSale exploit drains $7.3M in BNB through hidden contract backdoor

    John SmithBy John SmithMay 29, 2026No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    DxSale has suffered a $7.3 million exploit after an attacker allegedly used a hidden backdoor in a liquidity locker contract to withdraw BNB locked by more than 1,400 liquidity providers on the BNB Chain.

    Summary

    • DxSale lost $7.3 million in a BNB Chain exploit affecting roughly 1,400 liquidity providers.
    • Researchers linked the attack to a hidden contract backdoor and a previously undisclosed ownership transfer.
    • The incident follows a wave of DeFi exploits, with protocols losing $52 million to hacks so far in May.

    According to blockchain security firm PeckShield, the attacker-controlled address “0xC457” moved approximately $1.87 million worth of BNB into two primary wallets before sending the funds to multiple deposit addresses associated with Binance.

    The incident affected liquidity that had remained locked in DxSale contracts since the platform was widely used for token launches on BNB Chain in 2021.

    Early findings from blockchain analyst Tahax suggest the exploit may have originated from a contract ownership change that took place months before the attack.

    Tracing the ownership history further, Tahax said more than 80 additional transactions were used to pass control between wallets before it eventually reached the address identified as “0xC45,” which later executed the large-scale BNB withdrawals.

    The analyst also noted that the exploiter wallet was newly created and initially funded through crypto exchange Bybit.

    Researchers point to contract-level weakness

    Additional analysis from Web3 security firm Coinsult linked the exploit to a privileged contract function and a manipulated lock period. According to Coinsult, the combination allowed funds that were supposed to remain locked to be treated as withdrawable balances.

    ❗ About that DxSale locker ‘backdoor’, we have analysed it on-chain. Here is our take:

    The drainer: 0xc2efbd94…01e4718, unverified, solc 0.8.33, deployed ~9h ago by 0xC4574DD…aaFA69. It hardcodes the victim locker as an immutable + WBNB for routing, and gates every function… https://t.co/POq7z2C8Pp

    — Coinsult – Audits & Development (@CoinsultAudits) May 28, 2026

    The security firm said a privileged “setFee” mechanism, combined with a backdated lock configuration, enabled repeated withdrawal actions that ultimately drained the BNB reserves. Tahax separately alleged that a backdoor had been left in the deployer contract, creating conditions for the exploit.

    By the time investigators identified the attack path, some of the stolen funds had already moved through infrastructure that may complicate tracking efforts, according to Tahax.

    DeFi security concerns grow after recent attacks 

    The latest breach arrives as decentralized finance platforms continue to face security incidents across multiple networks.

    Data from DefiLlama shows DeFi protocols have lost about $52 million to exploits so far in May, following roughly $634 million in losses recorded during April, the highest monthly total since February 2025.

    Security concerns intensified this week after Stake DAO disclosed an exploit involving its vote-boosted sdCRV token on Arbitrum. Blockchain security company Blockaid reported that an attacker minted more than 5.4 trillion vsdCRV tokens and began exchanging them for ETH, while Stake DAO urged users not to interact with the asset as investigators tracked transactions across Arbitrum and Ethereum.

    Elsewhere, Wasabi Protocol reported losses exceeding $5 million after a compromised administrative key allowed attackers to upgrade contracts and drain funds across Ethereum, Base, Berachain, and Blast.

    Amid the recent string of incidents, OpenZeppelin co-founder Manuel Aráoz warned that advances in AI-assisted vulnerability discovery are making attacks easier to execute.

    In comments cited earlier by crypto.news, Aráoz said he now considers “all of DeFi” unsafe because attackers increasingly have access to powerful tools that can identify software weaknesses before developers can patch them.

    According to DefiLlama, crypto exploits have resulted in more than $17 billion in cumulative losses, including roughly $7.8 billion stolen from DeFi protocols alone.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    John Smith

    Related Posts

    Sui price prediction 2026-2030: beyond USDsui

    May 29, 2026

    South Korea’s DAXA targets crypto API keys after 30% warning

    May 29, 2026

    Bessent calls for CLARITY Act passage, says no CBDC under Trump

    May 29, 2026
    Leave A Reply Cancel Reply

    Demo
    Don't Miss
    Crypto

    Sui price prediction 2026-2030: beyond USDsui

    By John SmithMay 29, 20260

    Sui (SUI) trades between $1.06 and $1.24 in late May 2026, recovering from a winter…

    Examples of Digital Assets in Real Life

    May 29, 2026

    DxSale exploit drains $7.3M in BNB through hidden contract backdoor

    May 29, 2026

    South Korea’s DAXA targets crypto API keys after 30% warning

    May 29, 2026

    LAI Crypto is a user-friendly platform that empowers individuals to navigate the world of cryptocurrency trading and investment with ease and confidence.

    Our Posts
    • Altcoins (16)
    • Blockchain (23)
    • Crypto (713)
    • Ethereum (231)
    • Lithosphere News Releases (23)

    Subscribe to Updates

    • Twitter
    • Instagram
    • YouTube
    • LinkedIn

    Type above and press Enter to search. Press Esc to cancel.