Skip to content

Self-Custody Gone Wrong or Hacker Shenanigans, DEXX Hack Incident Tracking | Timeline

Nov 16, 14:39
Self-Custody Gone Wrong or Hacker Shenanigans, DEXX Hack Incident Tracking | Timeline

On November 16, user assets of the on-chain transaction terminal DEXX were stolen, and several meme coins experienced a significant sell-off early this morning. Currently, the security company has not determined the specific amount stolen, but there are community rumors that the lost assets have exceeded sixteen million U.S. dollars.


DEXX founder Roy stated this morning that he will compensate users for their losses. As of now, several users have reported that their account assets have been isolated to a secure address.



DEXX Security Vulnerability


After the DEXX theft incident, the community began to examine this meme-exclusive trading platform that had been flooded with its referral links, and KOLs who had promoted DEXX were also blamed by users.


Yuan Yu, founder of the security firm SlowMist, stated, "The stolen funds are related to those who used DEXX for meme coin speculation. The private key belongs to DEXX's centralized custody, which was definitely leaked. Further investigation is needed on how the leak occurred."


The community discovered that based on the export_wallet request information in the developer tools, when exporting the DEXX private key, the private key is displayed in plaintext, indicating that users' private keys are actually on the official server. If communication is not encrypted, attackers may intercept users' private keys during transmission. Even if HTTPS is used for transmission, direct transmission of the private key may lead to privacy data leakage due to browser vulnerabilities or other security issues.


As a result, some users joked that "DEXX has redefined non-custodial wallets."



In addition, the OneKey wallet app stated that DEXX repeatedly requested "upload clipboard content" permission, which may have uploaded users' clipboard content, saying, "If you have copied your private key mnemonic phrase on your phone, transfer your assets as soon as possible."


DEXX's audit was conducted by Certik, and the audit report shows that DEXX scored 59.31 points. This failing score indicates up to 9 risks. The main risk of "centralization" remains unresolved; two out of four moderate risks have been resolved, including "attackable code"; there are also four mild risks, of which only one has been resolved.



Some users expressed that DEXX and various trading bots are all lacking in security. Without exception, project teams all hold a common mentality: "Since users don't understand or care, and there are lucky peers who are doing the same thing without being stolen, and if I cared, I would have to bear a lot of R&D costs and sacrifice user experience, then I don't have to care either."


Previously, BananaGun and Unibot have both experienced security vulnerabilities. When it comes to on-chain transactions, it is still a case of "Not Your Keys, Not Your Money".


Latest News and Investigation Progress


11-19 11:17

The official DEXX team stated on social media, "Currently, some users have reported that certain tokens are suspected to be involved in a hacker-driven market manipulation. We are analyzing the timing and addresses to determine if they belong to our users. If you notice any unusual token movements in your address or suspect that a hacker is consolidating or selling tokens, please contact us immediately on Telegram or reach out to our security team."


11-17 23:43

The official DEXX team announced on social media, "Regarding the DEXX asset theft incident, the team has made some progress internally and has applied for the judicial marking of the hacker's wallet address. We are marking the hacker's address and requesting assistance from the Solana Foundation. Once marked, the hacker will be unable to deposit funds into our trading platform or convert tokens to fiat by any means. We are currently cooperating with multiple security agencies to trace the hacker's information and have initiated investigations in various jurisdictions. Any information that can be made public in the future will be shared synchronously on X/Telegram."


11-17 16:38

DEXX founder Roy responded to concerns about being out of contact on the X platform, stating, "Due to special circumstances, we are currently unable to provide real-time updates. Please give us some time to address this issue satisfactorily. The team will share some information and solutions in the next few days. It's not a matter of being out of contact but rather being bombarded with so much information that it's impossible to keep up with. The rumors circulating on the web are outrageous, and I truly don't want to respond or engage. Most of my time is focused on resolving the issue."


11-16 14:12

According to GoPlus Security Monitoring, various phishing scams related to rights protection and compensation for DEXX theft victims, such as "Rights Protection Community," "DEXX Theft Registration," and "DEXX Compensation," targeting DEXX theft victims have been identified. Users should be cautious and avoid uploading private keys/mnemonics or connecting wallets for confirmation to prevent further harm.


11-16 14:02

SlowMist founder Cai Yunge posted an update on the DEXX incident on social media, stating that SlowMist has received nearly 500 requests related to the DEXX theft. The incident analysis is still ongoing, with preliminary estimates indicating losses in the tens of millions of dollars (due to significant price fluctuations in some meme coins). Almost every victim corresponds to a different attacker address, indicating that the attackers had planned this event meticulously. The source of the gas fee was exchanged for XMR three days ago.


11-16 13:27

Blockchain security audit firm CertiK has released a statement stating that they have recently received a large number of requests for help from users of the DEXX platform, reporting that their account assets have been drained. Upon CertiK's verification, it was confirmed that this security incident occurred on the Solana blockchain, which is not within CertiK's audit coverage.


CertiK stated that the main reason for the event was due to improper private key management by the DEXX platform, leading to the leakage of the official private key.


11-16 12:30

Firm founder Cosmos Yu responded to a screenshot circulating online stating that "DEXX users have cumulatively lost $488 million" on social media. He clarified that in the DEXX case, each victim's hacker address is different, and the stolen funds are not centralized to a single address.


meme Price Update


11-16 08:56

According to GMGN market data, influenced by the DEXX theft, Meme coins such as BAN, LUCE, PNUT experienced varying degrees of decline, including:

· BAN dropped by approximately 30% since the incident, currently priced at $0.126

· LUCE dropped by approximately 20% since the incident, currently priced at $0.211

· PNUT experienced a maximum drop of around 12.5% since the incident, currently priced at $1.72


Recommended

The Wall Street Journal: How is AI Trading Stealing the Limelight from Cryptocurrency?

Aug 15, 14:00
The Wall Street Journal: How is AI Trading Stealing the Limelight from Cryptocurrency?

Tencent Still Has a Dream

Aug 15, 11:27
Tencent Still Has a Dream

To Catch North Korean Hackers, They Set Up a Fake Project

Aug 15, 10:00
To Catch North Korean Hackers, They Set Up a Fake Project

From Litigation to Settlement: Positive Signal Released by HTX's Negotiation with FCA

Aug 14, 19:32
From Litigation to Settlement: Positive Signal Released by HTX's Negotiation with FCA

11,742 Shipping Addresses Exposed Alongside Trezor Orders

Aug 14, 19:01
11,742 Shipping Addresses Exposed Alongside Trezor Orders

Founder Interview: FOMO Creator Explains How They Added 30,000 Users in One Day and Became One of the Fastest-Growing Crypto Apps

Aug 14, 18:37
Founder Interview: FOMO Creator Explains How They Added 30,000 Users in One Day and Became One of the Fastest-Growing Crypto Apps