79thVault, a decentralized finance (DeFi) protocol on BNB Chain, saw about $12.5 million pulled from the main trading pool of its 79AU token on October 7, 2026. A wallet holding special administrative permissions over the token moved roughly 2.01 million 79AU out of the pool and sold them back into it, draining most of the pool’s dollar reserves.
Blockchain security monitors have described the incident as either a suspected private key compromise or possible insider action rather than a bug in the smart contract code.
Blockchain security firm CertiK flagged the activity as a suspected exploit carried out through a privileged function. On-chain monitoring service Defimon Alerts went further, classifying it as a private key compromise or possible insider action. A private key is the secret credential that controls a crypto wallet, and anyone holding it can sign transactions as that wallet’s owner.
How the 79AU Drain Worked
The 79AU token contract includes a function restricted to holders of an “OPERATOR_ROLE,” a permission level granted to selected addresses. According to Defimon Alerts, this function allows the operator to move any amount of 79AU out of a designated address and send it to any recipient. It then calls sync(), a command that tells the liquidity pool to update its recorded token balances.
In this case, the designated address was the 79AU/USDT trading pair on PancakeSwap, the largest decentralized exchange (DEX) on BNB Chain. A liquidity pool, or pair, holds two tokens so that traders can swap between them. Here those tokens were 79AU and Tether (USDT), a dollar-pegged stablecoin.
The operator hot wallet holding the role had previously been used only for small transfers into the protocol’s reward pool. A hot wallet is one whose keys are kept on an internet-connected device, which makes it more convenient to use but more exposed to theft.
Between about 07:25 and 08:19 Coordinated Universal Time (UTC) on October 7, the operator wallet made seven calls to that function. The calls moved 2.01 million 79AU from the pool in tranches of 10,000, 100,000, 100,000, 300,000, 500,000, 500,000, and 500,000 tokens. Every tranche went to a single externally owned account (EOA), meaning a regular wallet controlled by a private key rather than by smart contract code.
$12.5 Million Converted to 16,249 BNB
The receiving wallet then sold the 79AU back into the same PancakeSwap pair across roughly 95 swaps. Because the operator function had already removed tokens from the pool without any payment, each sale extracted real USDT from the pool. The pool’s USDT reserves fell from about $15.2 million to $3.9 million.
The proceeds were converted into 16,249 BNB, the native token of BNB Chain, worth about $12.5 million at prevailing prices. They were sent to a separate wallet. Forty-one seconds later, the operator wallet sent an additional 3.79 BNB of its own to that same destination.
Defimon Alerts said the timing of that transfer suggests that the operator key and the drained funds were controlled by the same party, or that an insider was involved. A further 500,000 79AU was moved to an address beginning 0xf219d073. The OPERATOR_ROLE permission was revoked after the transfers.
Where the Stolen Funds Are Now
Most of the BNB has not yet been widely dispersed. Web3 security firm GoPlus Security reported that about 14,394.92 BNB, worth roughly $11.03 million, was sitting at a consolidation address as of its latest review, with no further large movements observed.
That figure represents about 89% of the 16,249 BNB extracted. Separately, on-chain analytics firm PeckShield identified a 30 BNB deposit to the centralized exchange KuCoin from activity linked to the incident. KuCoin has not publicly commented on whether it has frozen those funds.
10% Bounty Offer and 79thVault’s Response
An on-chain message offering a 10% bounty for the return of the remaining funds was sent to the recipient wallet. Defimon Alerts noted that this message came from the same operator key used to carry out the transfers. The bounty offer therefore does not, on its own, confirm who currently controls that key.
79thVault’s official X account has posted a notice describing a “system upgrade” and warning that front-end features and some asset operations may be temporarily affected. As of publication, the project has not released a detailed incident report, a loss reconciliation or confirmation that the operator key was compromised.
The 79AU contract source code is not verified on BscScan, the block explorer for BNB Chain. This means outside reviewers cannot read the published code that matches what is running on chain. At the time of the transfers, the operator role sat with a single address. There was no evident multisig, a wallet that requires several keys to approve a transaction, and no timelock, a mechanism that delays sensitive actions so users can react before they take effect.
A Recurring Weakness on BNB Chain
The incident follows a string of losses on BNB Chain this year that came from weak permission controls rather than complex hacks. In July, The Crypto Times reported that a token linked to Crypto DAO was drained for about $8.2 million on BNB Chain after cybersecurity firm Blockaid flagged an active exploit on July 28, in a case tied to an access-control bug.
What Remains Unconfirmed
Every step of the 79AU drain can be viewed on the BNB Chain. What has not been publicly confirmed is how control of the operator key was obtained, whether the activity came from an outside attacker or an insider, and whether any part of the 16,249 BNB has been recovered. The Crypto Times will update this story with any response and update from official sources.
Also Read: Crypto Trader Frogman Loses Over $4M in Wallet Hack in Singapore During TOKEN2049
