Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • Indices
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Indices
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

BNB Chain DEX Router Reportedly Drained of 62 WBNB in Exploit 

A security researcher said a BNB Chain DEX router may have used existing token approvals to drain about 62 WBNB from 29 wallets.

Written By Isha Chavda
Edited by Sujha Sundararajan
Published 58 minutes ago
Make The Crypto Times preferred on GoogleGoogle
BNB Chain DEX Router Reportedly Drained of 62 WBNB in Exploit 

Key Highlights

  • Security researcher ExVul reported that a BNB Chain DEX router was exploited for approximately 62.28 WBNB.
  • The researcher said 29 wallets were affected through existing token approvals.
  • The reported attack involved a fake liquidity pool and a suspected failure to verify a Uniswap V3-style swap callback.

A DEX router on BNB Chain was reportedly exploited after an attacker found a way to use existing token approvals to withdraw assets from multiple wallets.

Security researcher ExVul reported the incident on X on September 7, saying approximately 62.28 WBNB was extracted and that 29 wallets were affected.

🚨 ALERT — Exploit on BNB Chain

An on-chain DEX aggregator/swap router was drained for ~62.28 WBNB. A no-capital attacker flash-swapped 1 WBNB from PancakeSwap for gas, deployed a fake "pool," and used the router's own approvals to steal from 29 users in a single…

— ExVul (@exvulsec) September 7, 2026

The router’s development team has not independently confirmed the claims, while the full scope of the incident, including potentially affected tokens and approvals, remains unclear.

Suspected exploit centered on router callback

According to ExVul’s analysis, the reported attack involved the router’s handling of a Uniswap V3-style swap callback.

The researcher alleged that the router’s uniswapV3SwapCallback function accepted a caller-supplied payer address and then used transferFrom() to move tokens from that address.

ExVul said the router did not sufficiently verify that the callback came from a legitimate V3 liquidity pool created through the expected factory.

The researcher also pointed to the router’s factoryV3 configuration being set to 0x0, which ExVul said prevented the expected pool verification.

If the assessment is correct, an attacker could create a contract that behaved like a V3 pool and use it to trigger the router’s callback.

The alleged mechanism would allow the attacker to use token allowances previously granted to the router without obtaining users’ private keys.

How the reported attack worked

ExVul described the transaction as a sequence of steps:

  1. The attacker obtained 1 WBNB through a PancakeSwap flash swap to cover gas costs.
  2. The attacker deployed or configured a contract designed to imitate a V3 pool.
  3. The attacker called the router’s swap function while specifying a victim address as the payer.
  4. The fake pool triggered the router’s uniswapV3SwapCallback() function.
  5. The router allegedly used the victim’s existing approval to execute transferFrom().
  6. The extracted tokens were transferred to the attacker’s address and exchanged for BNB.
  7. The initial flash-swap amount was repaid, leaving the remaining proceeds with the attacker.

ExVul said the same mechanism was used against multiple wallets and tokens during the transaction.

Existing approvals create the main user risk

The reported incident highlights the risk associated with persistent token approvals.

When users approve a DEX router to spend their tokens, that authorization can remain active until it is reduced or revoked. A flaw in the router could therefore potentially allow approved assets to be moved without compromising the wallet’s private key.

ExVul said the reported issue could affect addresses that had previously granted standing or unlimited approvals to the router.

Users who interacted with the reported contract should review their active token approvals and consider revoking permissions they no longer need while the incident is investigated.

Revoking an approval cannot recover assets that have already been transferred, but it can prevent a remaining allowance from being used in a future transaction.

No oracle or price manipulation reported

ExVul said the reported attack did not depend on several mechanisms commonly associated with DeFi exploits.

According to the researcher, the transaction did not require:

  • Price manipulation
  • Oracle manipulation
  • A compromised private key
  • Administrative access
  • A conventional flash-loan price attack

Instead, the reported mechanism centered on the router’s callback handling and previously granted token permissions.

If confirmed, the incident would involve an authorization and caller-validation issue rather than a conventional market-manipulation attack.

BNB Chain activity provides broader context

The incident occurred on a network handling substantial transaction and trading activity.

A Dune dashboard referenced in the report showed approximately 13.86 million transactions over 24 hours, more than 100.79 million over seven days, and around 431.93 million over 30 days.

BNB Chain activity

BNB Chain activity of September 7 | Source: Dune 

The dashboard also recorded approximately 2.63 million daily active accounts, 11.35 million weekly active accounts, and 35.55 million monthly active accounts.

DEX activity included PancakeSwap and Uniswap, with several trading pairs recording substantial volumes.

These figures do not establish a connection between overall BNB Chain activity and the reported exploit.

Recent BNB Chain exploits show different attack patterns

The reported router incident follows other security incidents involving BNB Chain projects.

In August, security firm TenArmor reported an approximately $907,700 loss involving the MOKE token. On-chain activity showed movements involving MOKE, WBNB, and PancakeSwap liquidity-pool contracts.

The mechanism behind that incident remained unclear because a detailed post-mortem or confirmed root cause had not been released at the time.

The two incidents involved different reported attack patterns. The MOKE case centered on suspected liquidity-related manipulation, while the latest incident described by ExVul involves router permissions and callback validation.

On-chain details

ExVul identified the following addresses in its analysis:

  • Attack transaction: 0x40eb22369da422a8275d5679054aa3a8c8906d93abc0bac3a3f2cad879389319
  • Reported attacker: 0xB929C7215c0ec8EbAD5fBf73b1Da63bccfFf1896
  • Reported router: 0xa331fde028e6F17425AB9333c39ae43722340d24
  • Reported amount extracted: approximately 62.28 WBNB
  • Reported affected wallets: 29

The transaction provides an on-chain reference for further analysis, while the technical conclusions are based primarily on ExVul’s assessment.

The Crypto Times has reached out to the teams behind the affected routers, Uniswap V3 and PancakeSwap, for clarification.

What users should check

Users who previously interacted with the reported router should review their wallet approvals associated with the contract.

They should check for:

  • Active approvals granted to the reported router
  • Unlimited or unusually large spending allowances
  • Tokens that remain approved
  • Wallets that previously interacted with the contract

Users should verify the contract address before taking action, particularly when revoking permissions or interacting with security tools.

Investigation continues

The key question is whether the router’s callback mechanism allowed previously granted spending permissions to be used for unauthorized transfers.

Further analysis of the transaction and a response from the affected project will be needed to determine the root cause, identify the full number of affected wallets, and establish whether other users remain exposed.

For now, the incident remains based primarily on ExVul’s analysis and the reported on-chain transaction.

Also Read: Coldcard Hacker Moves 45% of Wave 3 Bitcoin via THORChain and CoinJoins

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BinanceCrypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Ethereum Targets 2029 for Post-Quantum L1 Readiness 
Ethereum Targets 2029 for Post-Quantum L1 Readiness 
XRP Futures Hit 6-Month High as Trading Volume Surges 
XRP Futures Hit 6-Month High as Trading Volume Surges 
AUSTRAC Removes 45 Crypto and Remittance Firms From Registers
AUSTRAC Removes 45 Crypto and Remittance Firms From Registers
Liquid Network White Hat Returns 3,400 BTC, Retains 598.5 BTC
Liquid Network White Hat Returns 3,400 BTC, Retains 598.5 BTC
Hunter Biden Plans LAPTOP Meme Coin Launch, Targets $TRUMP Losers
Hunter Biden Plans LAPTOP Meme Coin Launch, Targets $TRUMP Losers

Find Us on Socials

You may also like

Ireland Criminal Assets Bureau Finds Crypto Keys, Cash in Private Vaults

Ireland Criminal Assets Bureau Finds Crypto Keys, Cash in Private Vaults

Illuminated 3D XRP Healthcare logo mounted on a concrete wall alongside a red digital network graphic overlay

XRP Healthcare Says About $452,000 Taken From 4,011 Wallets

Broken padlock and physical cryptocurrency coins on a desk in front of a hooded hacker, with a computer monitor displaying a red "SECURITY BREACH" warning sign

Crypto Hacks Cross $322M in September’s First Week as Liquid Network Alone Loses $320M

Individual in a dark hooded sweatshirt sitting in front of a laptop computer, silhouetted against an illuminated German state flag of Berlin

Berlin Hit by 30 Bitcoin Ransom Demand Over Stolen State Data

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information