SECURITY ALERT
Nobody bought the tokens.
They were sold anyway.
About $12.5 million was drained from 79thVault’s 79AU/USDT pool on PancakeSwap, BNB Chain, between about 07:25 and 08:19 UTC on 7 Oct, according to security monitors. The figure is an estimate. The cause is unconfirmed.
Post by @DefimonAlerts on X: https://x.com/DefimonAlerts/status/2108100434942431441
Defimon Alerts says the 79AU token has a function, open only to an OPERATOR_ROLE address, that moves any amount of 79AU out of the pool and then resyncs the pool’s balances.
Seven such calls moved 2.01 million 79AU to one wallet, which sold them back into the same pool, The Crypto Times reported. USDT reserves fell from about $15.2 million to $3.9 million.
The proceeds became 16,249 BNB.
Defimon classifies the incident as a private-key compromise. CertiK flagged a suspected exploit through a privileged function. How control of the operator key was obtained has not been established.
Related: What a private key is
GoPlus reported about 14,395 BNB sitting at one consolidation address. PeckShield traced 30 BNB to KuCoin.
The operator role was revoked after the transfers. An on-chain message offering a 10% bounty came from the same operator key.
79thVault has posted only a “system upgrade” notice. No incident report yet.
Who held the key at 07:25?
Protect yourself
- Check whether a token’s admin roles can move pool funds, and whether a multisig or timelock guards them.
- Treat unverified contract source code as a risk.
- Check a pool’s depth, not just its quoted price, before trading a thin token.
Corrections and new evidence: [email protected]
Produced by the Crypto Watch Desk newsroom using AI tools. This article is for information only and is not investment advice.
