Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Crypto DAO Drained for $8.2M on BNB Chain via Access-Control Bug

An elementary access-control exploit drained $8.2M from Crypto DAO’s Pro token contract, raising questions about basic smart contract security.

Written By Divya Mistry
Published 2026-07-29·Updated 2 months ago
Make The Crypto Times preferred on GoogleGoogle
Crypto DAO Drained for $8.2M on BNB Chain via Access-Control Bug
AI Summary
Show
On July 28, Blockaid flagged the Crypto DAO exploit, which occurred when an attacker called a publicly accessible vault function, resulting in $8.2 million in USDT being transferred
The exploit is part of a larger pattern of BNB Chain exploits in 2026, including the 42DAO incident on July 22, which lost roughly $912,000 due to an oracle/price-feed issue
The incident highlights a recurring issue on BNB Chain, where basic logic and access-control failures continue to occur due to the ease and low cost of deploying unaudited contracts

The Crypto DAO exploit did not require a genius attacker or a novel zero-day vulnerability. It required a vault function anyone could call, the same class of basic access-control flaw that continues to drain BNB Chain’s long tail of protocols, one forked contract at a time.

On July 28, cybersecurity firm Blockaid flagged an active exploit draining the Pro token linked to Crypto DAO on BNB Chain. By the time the transactions settled, roughly $8.2 million in USDT was transferred into an exploiter wallet (0x427671b2C8e91034A91FE698F9B7259b2345F45D) and three connected receiving addresses holding $2.68 million, $2.69 million, and $2.78 million respectively. DeFiLlama logged the event the same day under the Protocol Logic (Solidity) loss category.

That is the entire attack. No novel zero-day, no compromised private keys, no sophisticated social engineering.

Exploited token:https://t.co/wLxneOQfmU

— Blockaid (@blockaid_) July 28, 2026

Not a Sophisticated Attack

There is a temptation, with every eight-figure exploit, to imagine a state-backed adversary or an obscure vulnerability nobody could have anticipated. This was the opposite. A publicly callable state-changing function with no access control is the first item on virtually every smart-contract security checklist. Flash loans did not create the vulnerability; they simply let an attacker with zero capital scale it to maximum effect inside a single block.

In short, the Crypto DAO vault was not defeated. It was left unlocked.

The Pattern is the Point

What elevates this above a routine incident report is that it is not isolated. It is the newest entry in a consistent 2026 pattern of BNB Chain exploits that all share the same DNA: small-to-mid-cap or newer protocols shipping contracts with missing checks, an absent access control, an unenforced cap, or a price left manipulable within one transaction, then watching a flash-loan-armed attacker walk in.

Just days earlier, on July 22, 42DAO, also on BNB Chain, lost roughly $912,000–$915,000 after an oracle/price-feed issue allowed forced liquidations and unbacked value extraction, collapsing its Balance Coin (BLC) by more than 99%. In March, Venus Protocol’s THE (Thena) market was hit for approximately $3.7 million extracted via a donation-style supply-cap bypass using flash liquidity, leaving the protocol with more than $2 million in bad debt. Similar basic logic or access-control failures have hit a long list of other BNB Chain projects this year.

These are not the exotic multi-hundred-million bridge or key-compromise exploits that dominate headlines (KelpDAO’s $292 million or Drift’s $285 million earlier in 2026). They are the “boring” bugs, and they keep happening in the same place.

Why Basic Logic Bugs Persist 

BNB Chain’s strengths, sub-cent fees, fast finality, easy token and contract deployment tools, and a vibrant fork-and-launch culture, are exactly what make it the cheapest and fastest environment for launching a DeFi protocol. That is a genuine feature for legitimate builders. It is also a structural gift to teams that skip or under-invest in security reviews. When deployment costs pennies and cloning an existing contract takes an afternoon, the friction that would otherwise force a thorough audit or formal verification is often missing.

The cumulative cost is large. Immunefi data has long put BNB Chain losses since launch (September 2020) at roughly $1.64 billion across hundreds of incidents ($1.27 billion from hacking alone). That figure is not the product of one catastrophic breach; it is the product of hundreds of smaller, preventable ones, each following the template the Pro token exploit just re-ran.

This incident also lands against the backdrop of Blockaid’s just-released H1 2026 report, showing a record 212 on-chain exploits and more than $1.1 billion lost in the first half of 2026 alone, the highest incident count on record even if dollar totals lagged the prior year’s mega-breaches.

At the time of writing, Crypto DAO had not publicly acknowledged the incident, issued a post-mortem, or outlined any recovery or remediation steps. Whatever statement eventually appears, the more durable lesson belongs to the broader BNB Chain environment: as long as deploying an unaudited or minimally reviewed contract remains this cheap and this frictionless, the next multi-million-dollar exploit of this exact class is not a distant risk. It is already on the calendar.

Also Read: PHX-WBNB Liquidity Pool Drained of Nearly $90K in BNB Chain Exploit

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BinanceCrypto HackDAO
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Kevin Warsh, Chair of the Federal Reserve of the United States
What to Expect From Today’s FOMC Meeting: Warsh’s First Fed Rate Hike Vote, Dot Plot and Bitcoin Reaction
BTC Mining Electricity Use May Have Peaked, Says ‘The Bitcoin Standard’ Author
An illuminated wall logo of the Bureau of Indian Standards with Hindi and English text
BIS Study: Bitcoin Transfer Estimates Differ by Up to Sixfold
The official emblem of India's Directorate of Enforcement (ED) featuring golden laurel leaves and the State Emblem of India
India’s ED Sharpens Crypto Crime Tracking Under New 18-Month Probe Plan
A cracked physical Bitcoin coin resting on a wet street with the U.S. Capitol building illuminated in the background
Bitcoin Price Slips in Fear as Fed Decision Nears and CLARITY Act Stalls

Find Us on Socials

You may also like

3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background

Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out

Smartphone displaying the Revolut app logo against a dark background with an illuminated Revolut wall sign behind it.

Revolut Data Breach Hits 680 Customers, UK Opens Probe as Hackers Demand 10,000 Bitcoin

A robotic metallic hand gripping a shiny 3D Ethereum coin surrounded by motion light lines

$7.8M rsETH Drained From Ethereum Safe Wallet, MEV Bot Yoink Front-Runs the Exploit

Printouts of the CLARITY Act bill and a Senate counterproposal document resting on a desk inside the U.S. Senate chamber

Binance Changes Trading Hours for Commodity TradFi Perpetuals

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information