DxSale Loses $7.3M in BNB After Attacker Exploits Hidden Contract Backdoor

DxSale Loses $7.3M in BNB After Attacker Exploits Hidden Contract Backdoor

N
News Editor 01
2026-07-23 00:00:14
Over 1,400 liquidity providers lost $7.3M in BNB after a hidden backdoor in DxSale's lock contract was exploited. Investigators link the attack to a privileged function and a previous ownership transfer. DeFi losses in May already top $52M.
DxSaleDeFi securityBNB Chainsmart contract hackbackdoor exploit

DxSale suffered a $7.3 million exploit on BNB Chain after an attacker exploited a hidden backdoor in a liquidity locker contract, draining BNB from more than 1,400 liquidity providers. The affected liquidity had been locked since 2021, when DxSale was widely used for token launches.

Hidden Ownership Transfer and Privileged Function Uncovered

Blockchain security firm PeckShield tracked the attacker-controlled address "0xC457" moving roughly $1.87 million worth of BNB to two primary wallets, then onward to multiple Binance deposit addresses. Analyst Tahax discovered that a contract ownership change had occurred months before the attack — over 80 transactions secretly passed control between wallets before it reached the exploiter address "0xC45."

Web3 security firm Coinsult identified a privileged "setFee" function combined with a backdated lock period, allowing locked funds to be treated as withdrawable. Tahax separately claimed a backdoor had been left in the deployer contract itself. By the time investigators mapped the attack path, some stolen funds had already moved through obfuscation layers.

DeFi Losses Surge in May After $634M April

The DxSale breach adds to a wave of DeFi security incidents. DefiLlama data shows DeFi protocols have lost about $52 million to exploits so far in May, following April's $634 million — the highest monthly total since February 2025.

Earlier this week, Stake DAO disclosed an exploit of its sdCRV token on Arbitrum, where an attacker minted over 5.4 trillion vsdCRV and began swapping for ETH. Security firm Blockaid tracked transactions across Arbitrum and Ethereum, while Stake DAO urged users not to interact with the asset. Wasabi Protocol also reported $5 million in losses after a compromised admin key allowed attackers to upgrade contracts and drain funds across Ethereum, Base, Berachain, and Blast.

OpenZeppelin Co-Founder: AI-Powered Tools Make DeFi Unsafe

OpenZeppelin co-founder Manuel Aráoz warned that advances in AI-assisted vulnerability discovery make attacks easier to execute. He now considers "all of DeFi" unsafe because attackers have access to powerful tools that identify weaknesses before developers can patch them. Cumulative crypto exploit losses have exceeded $17 billion, with $7.8 billion stolen from DeFi protocols alone, according to DefiLlama.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.