Skip to content

Timeline | UXLINK Suffers Hacker Attack, Plunges 70%, Will Initiate Token Swap and Implement Compensation Plan

Sep 24, 13:16
Timeline | UXLINK Suffers Hacker Attack, Plunges 70%, Will Initiate Token Swap and Implement Compensation Plan

On September 23, the decentralized social project UXLINK was suddenly hit by a hacker attack. The attacker tampered with multi-signature permissions and stole over $11 million in assets. Subsequently, they gained coin minting rights and minted an additional 1 billion UXLINK tokens on-chain. Following the announcement, UXLINK plummeted nearly 65% overnight, with a price of $0.1 at the time of writing. The UXLINK team swiftly responded to the attack, stating that most of the stolen funds had been frozen. They are currently collaborating with a security firm to track the assets and will initiate a token swap.

On September 24, the new UXLINK contract passed an audit, retaining the name "UXLINK," while eliminating the burn function. Below is a timeline of the key events and subsequent observations. BlockBeats will continue to monitor and provide real-time updates:


September 24


12:19 | UXLINK: New Token Contract Audit Passed, Significant Hacker-Related Addresses Frozen


Updates on the UXLINK hacker incident:


1. The new UXLINK smart contract has successfully passed a security audit.


2. The contract will be deployed on the Ethereum mainnet. It has eliminated the burn function and will utilize a cross-chain partner's service to maintain interoperability.


3. The token code remains "UXLINK" to ensure continuity across all platforms.


4. Today, the team will submit new contract details and migration plans to CEX partners.


5. The team is also preparing a comprehensive response to the Digital Asset Exchange Association of Korea (DAXA) inquiry and will submit it today.


6. The team has frozen numerous addresses related to the hacker attack and is collaborating with law enforcement and professional third parties to initiate the recovery process. All community losses will be handled transparently and allocated for community development and compensation.


September 23


20:17 | OKX to Delist UXLINK U Perpetual Contract


OKX announced the delisting of the UXLINK U perpetual contract at 22:00 Beijing time.


19:00 | Smart Contract Update: Fixed Supply, Abandon Cross-Chain "Mint-Burn"


UXLINK's official announcement on security updates is as follows:


1. Communication has been made with a major CEX partner regarding the planned token swap, and the major CEX has expressed full support.


2. A new smart contract has been submitted for a security audit. The contract will establish a fixed token supply to ensure no additional supply can be generated.


3. The "mint-burn" function typically used for cross-chain operations has been abandoned to safeguard the community's interests.


4. Responding to inquiries from the Korean Digital Asset Exchange Association (DAXA) and collaborating with security experts to prepare a comprehensive incident report.


11:48 | UXLINK Hacked or Subjected to Inferno Drainer Phishing Attack


SlowMist founder Cosmos Yu tweeted that UXLINK may have fallen victim to an Inferno Drainer phishing attack. "The approximately 542 million UXLINK tokens stolen earlier may have been phished by Inferno Drainer using a common authorization phishing method."


11:13 | Remediation Plan: Token Swap Initiated


The UXLINK team has detected ongoing unauthorized minting of UXLINK tokens by malicious actors. UXLINK is urgently contacting exchanges to halt token deposits and trading and initiate a token swap. More details and instructions regarding the token swap will be released soon. The team emphasizes that individual user wallets have not been affected by this incident. UXLINK commits to compensating affected users and has begun enhancing security measures, including upgrading to a multi-signature wallet mechanism and introducing hardware wallets for asset storage.


11:04 | PeckShield Security Advisory: Avoid Interaction


According to PeckShield monitoring, as today's UXLINK hacker has gained minting rights and just minted 1 billion UXLINK tokens on Arbitrum, the tokens have now been leaked. Users are reminded not to interact with UXLINK tokens.



11:01 | Exchange Risk Management: Upbit Caution & Deposit Suspension


According to an official announcement, Upbit has classified UXLINK as a trading cautionary token. Deposit services for UXLINK have been suspended, and the resumption of deposit services will be notified separately following the procedures after being designated as a trading cautionary item.


The announcement states that Upbit has identified several flaws in UXLINK that pose potential risks to users. The specific reasons are as follows: based on best practices supporting virtual asset trading, there are security events such as hacking attacks, and the issuer or operator has failed to promptly disclose essential information about virtual assets through proper electronic media. Therefore, Upbit has designated UXLINK as a trading cautionary asset to protect investors.


Transaction Alert Period: September 23, 2025, Tuesday 12:00 (Korea Standard Time) - October 17, 2025, Friday 11:59 (Korea Standard Time)



09:53|Hacker Minting Exposure: 10 Billion UXLINK


According to market reports, a hacker on-chain minted 10 billion UXLINK.



09:44|UXLINK: Freezing Progress & Compensation Plan


The official announcement stated that over the past few hours, they have been closely collaborating with major exchanges, and most of the stolen assets have been frozen, with collaboration with exchanges still ongoing.


UXLINK's top priority is to safeguard the community's assets and achieve asset recovery to the best of their ability. They have also engaged the services of Chainalysis to support the ongoing investigation and enhance recovery efforts. Currently, there are no indications of individual user wallets being compromised. The next steps involve formulating a clear plan to restore and compensate affected accounts. Protecting the community's interests remains UXLINK's highest priority, and they will continue to share verified updates.


09:08|Official Confirmation of Breach, Attempting to Freeze Suspicious Deposits and Filing a Report


In an official statement, UXLINK disclosed the discovery of a security vulnerability involving its multisig wallets, leading to a significant amount of cryptocurrency being illicitly transferred to both CEX and DEX. The team is collaborating with security experts to determine the cause and mitigate the situation. They have reached out to exchanges to freeze suspicious UXLINK deposits and have filed reports with law enforcement and relevant authorities to facilitate legal action and asset recovery.


00:49|Initial Report: Suspected Attack, Loss Exceeding $11 Million


Cyvers detected approximately $11.3 million in suspicious transactions related to UXLINK: the attacker address removed administrative permissions via delegateCall, called addOwnerWithThreshold, transferred out $4 million USDT, $500,000 USDC, 3.7 WBTC, 25 ETH; converted Ethereum side USDT/USDC to DAI, Arbitrum side USDT to ETH and cross back to Ethereum. Subsequently, the related address received 10 million UXLINK tokens (approximately $3 million) and began liquidation.



Recommended

The Wall Street Journal: How is AI Trading Stealing the Limelight from Cryptocurrency?

Aug 15, 14:00
The Wall Street Journal: How is AI Trading Stealing the Limelight from Cryptocurrency?

Tencent Still Has a Dream

Aug 15, 11:27
Tencent Still Has a Dream

To Catch North Korean Hackers, They Set Up a Fake Project

Aug 15, 10:00
To Catch North Korean Hackers, They Set Up a Fake Project

From Litigation to Settlement: Positive Signal Released by HTX's Negotiation with FCA

Aug 14, 19:32
From Litigation to Settlement: Positive Signal Released by HTX's Negotiation with FCA

11,742 Shipping Addresses Exposed Alongside Trezor Orders

Aug 14, 19:01
11,742 Shipping Addresses Exposed Alongside Trezor Orders

Founder Interview: FOMO Creator Explains How They Added 30,000 Users in One Day and Became One of the Fastest-Growing Crypto Apps

Aug 14, 18:37
Founder Interview: FOMO Creator Explains How They Added 30,000 Users in One Day and Became One of the Fastest-Growing Crypto Apps