skip to Main Content
bitcoin
Bitcoin (BTC) $ 76,418.47 0.51%
ethereum
Ethereum (ETH) $ 2,988.62 2.57%
tether
Tether (USDT) $ 1.00 0.04%
solana
Solana (SOL) $ 199.38 0.22%
bnb
BNB (BNB) $ 622.11 3.28%
usd-coin
USDC (USDC) $ 0.999853 0.00%
xrp
XRP (XRP) $ 0.54974 0.87%
dogecoin
Dogecoin (DOGE) $ 0.199837 3.55%
staked-ether
Lido Staked Ether (STETH) $ 2,985.42 2.53%
cardano
Cardano (ADA) $ 0.436591 5.73%

OKX DEX suffers $2.7M exploit after proxy admin contract upgrade

The OKX DEX suffered an exploit resulting in a loss of around $2.7 million in cryptocurrencies after a proxy admin upgraded a contract that allowed a hacker to compromise the private key.

OKX DEX suffers $2.7M exploit after proxy admin contract upgrade

OKX decentralized exchange (DEX) suffered a $2.7 million hack on Dec. 13 after the private key of the proxy admin owner was reported to be leaked. 

On Dec. 13, the blockchain security firm SlowMist Zone posted on X (formerly Twitter) that OKX DEX “encountered an issue.” According to the report, the issue began on Dec. 12, 2023, at approximately 10:23 pm after the proxy admin owner upgraded the DEX proxy contract to a new implementation contract and the user began to steal tokens.

SlowMist Security Alert: OKX DEX Proxy Admin Owner’s Private Key Suspected to be Leaked

According to information from SlowMist Zone, the OKX DEX contract appears to have encountered an issue. After SlowMist’s analysis, it was found that when users exchange, they authorize…

— SlowMist (@SlowMist_Team) December 13, 2023

Then, at approximately 11:53 pm, the proxy admin owner made another upgrade to the contract, and the user continued to exploit tokens. SlowMist’s analysis at the time said the attack “may be” the result of the key of the proxy admin owner being leaked.

The DEX proxy was subsequently removed from the platform’s trusted list.

Scopescan, an on-chain analysis firm, also reported the attack, saying users were reporting the event. It reported that after contacting the DEX, it was told that an old abandoned contract was attacked but has been located and stopped. 

Additionally the OKX DEX said any user losses affected by the hack will be “fully borne.”

Users reported an exploit event on the #OKX DEX contract.

We have contacted them and got the following response:

“The old abandoned MM contract was attacked, and the attack has been located and stopped.

The losses of the users involved will be fully borne.”

Exploiters… https://t.co/psuz4WcjGl pic.twitter.com/GrKUdrnGVk

— Scopescan (@0xScopescan) December 13, 2023

Related: Aerodrome and Velodrome DeFi platforms experience front-end hacks

According to a post from the blockchain security company PeckShield, the total loss of the OKX DEX attack was around $2.7 million in various cryptocurrencies. PeckShield advised users to “please revoke allowances” if there are any. 

In light of the hack, one X user posted a reminder that just because something is “decentralized” doesn’t mean that assets are necessarily safe: 

People say they want decentralization, so builders give them DEXs.

Just because its decentralized, folks think we won’t lose our assets. No you are wrong, you can still get hacked, and today’s unfort episode with OKX DEX is a reminder of “be careful of what you wish for”.

— Eugene Ng (I’m Hiring) (@Eug_Ng) December 13, 2023

Prior to September 2023, research shows that this year the industry has suffered $1.5 billion in losses at the hands of crypto hacks, exploits and scams. 

In the following fourth quarter, Poloniex faced an exploit that saw more than $100 million in digital asset losses, along with more than $80 million in losses on the HECO Chain bridge hack.

Magazine: This is your brain on crypto: Substance abuse grows among crypto traders

Loading data ...
Comparison
View chart compare
View table compare
Back To Top