Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Elon Musk and SpaceX composite image with the Indian flag and Bitcoin
    India vs Elon Musk: Starlink’s Global Wall of Bans, and the Crypto Thread Running Through It
    Physical gold Bitcoin (BTC) token standing in front of the US Capitol Building and the American flag
    Why Are U.S. Government Wallets Still Routing Seized Crypto to Coinbase?
    Charlie Lee, creator of Litecoin, standing in front of a blue Litecoin corporate logo wall
    Litecoin Turns 15: Original Bitcointalk Records Show How Charlie Lee Launched LTC in 2011
    Elon Musk with folded arms flanked by a giant Bitcoin coin, Tesla electric car, and SpaceX rocket launch
    Elon Musk’s Tesla and SpaceX Still Hold Over 30,000 Bitcoin: Why Is He Not Selling?
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

79thVault Hack: $12.5M Drained From 79AU Pool on BNB Chain

A privileged wallet moved 2.01 million 79AU from the PancakeSwap pool before converting the drained reserves into 16,249 BNB.

Written By Dishita Malvania
Edited by Divya Mistry
Published 54 minutes ago·Updated 22 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Laptop screen displaying 79Vault logo next to BNB coins spilling from a wallet and a phone showing a CertiK warning symbol

79thVault, a decentralized finance (DeFi) protocol on BNB Chain, saw about $12.5 million pulled from the main trading pool of its 79AU token on October 7, 2026. A wallet holding special administrative permissions over the token moved roughly 2.01 million 79AU out of the pool and sold them back into it, draining most of the pool’s dollar reserves. 

Blockchain security monitors have described the incident as either a suspected private key compromise or possible insider action rather than a bug in the smart contract code.

AI Summary
Show
About $12.5 million (16,249 BNB) drained from 79thVault’s liquidity pool, slashing USDT reserves from $15.2 M to $3.9 M.
Operator’s privileged role moved 2.01 million 79AU, enabling sales that extracted roughly $12.5 million in stablecoins.
Over 89% of the stolen BNB remains in a single consolidation address, with only a small KuCoin deposit observed.

Blockchain security firm CertiK flagged the activity as a suspected exploit carried out through a privileged function. On-chain monitoring service Defimon Alerts went further, classifying it as a private key compromise or possible insider action. A private key is the secret credential that controls a crypto wallet, and anyone holding it can sign transactions as that wallet’s owner.

How the 79AU Drain Worked

The 79AU token contract includes a function restricted to holders of an “OPERATOR_ROLE,” a permission level granted to selected addresses. According to Defimon Alerts, this function allows the operator to move any amount of 79AU out of a designated address and send it to any recipient. It then calls sync(), a command that tells the liquidity pool to update its recorded token balances.

In this case, the designated address was the 79AU/USDT trading pair on PancakeSwap, the largest decentralized exchange (DEX) on BNB Chain. A liquidity pool, or pair, holds two tokens so that traders can swap between them. Here those tokens were 79AU and Tether (USDT), a dollar-pegged stablecoin.

The operator hot wallet holding the role had previously been used only for small transfers into the protocol’s reward pool. A hot wallet is one whose keys are kept on an internet-connected device, which makes it more convenient to use but more exposed to theft.

Between about 07:25 and 08:19 Coordinated Universal Time (UTC) on October 7, the operator wallet made seven calls to that function. The calls moved 2.01 million 79AU from the pool in tranches of 10,000, 100,000, 100,000, 300,000, 500,000, 500,000, and 500,000 tokens. Every tranche went to a single externally owned account (EOA), meaning a regular wallet controlled by a private key rather than by smart contract code.

$12.5 Million Converted to 16,249 BNB

The receiving wallet then sold the 79AU back into the same PancakeSwap pair across roughly 95 swaps. Because the operator function had already removed tokens from the pool without any payment, each sale extracted real USDT from the pool. The pool’s USDT reserves fell from about $15.2 million to $3.9 million.

The proceeds were converted into 16,249 BNB, the native token of BNB Chain, worth about $12.5 million at prevailing prices. They were sent to a separate wallet. Forty-one seconds later, the operator wallet sent an additional 3.79 BNB of its own to that same destination.

Defimon Alerts said the timing of that transfer suggests that the operator key and the drained funds were controlled by the same party, or that an insider was involved. A further 500,000 79AU was moved to an address beginning 0xf219d073. The OPERATOR_ROLE permission was revoked after the transfers.

Where the Stolen Funds Are Now

Most of the BNB has not yet been widely dispersed. Web3 security firm GoPlus Security reported that about 14,394.92 BNB, worth roughly $11.03 million, was sitting at a consolidation address as of its latest review, with no further large movements observed.

That figure represents about 89% of the 16,249 BNB extracted. Separately, on-chain analytics firm PeckShield identified a 30 BNB deposit to the centralized exchange KuCoin from activity linked to the incident. KuCoin has not publicly commented on whether it has frozen those funds.

10% Bounty Offer and 79thVault’s Response

An on-chain message offering a 10% bounty for the return of the remaining funds was sent to the recipient wallet. Defimon Alerts noted that this message came from the same operator key used to carry out the transfers. The bounty offer therefore does not, on its own, confirm who currently controls that key.

79thVault’s official X account has posted a notice describing a “system upgrade” and warning that front-end features and some asset operations may be temporarily affected. As of publication, the project has not released a detailed incident report, a loss reconciliation or confirmation that the operator key was compromised.

📢 79VAULT SYSTEM UPGRADE 🔧

Our technical team is performing system optimizations to enhance stability and performance.

⚠️ Some front-end features and asset-related operations may be temporarily affected. Services will resume after the upgrade.

Thank you for your patience! 💛 pic.twitter.com/bHtdC8jXrz

— 79th Vault (@79thVault) October 8, 2026

The 79AU contract source code is not verified on BscScan, the block explorer for BNB Chain. This means outside reviewers cannot read the published code that matches what is running on chain. At the time of the transfers, the operator role sat with a single address. There was no evident multisig, a wallet that requires several keys to approve a transaction, and no timelock, a mechanism that delays sensitive actions so users can react before they take effect.

A Recurring Weakness on BNB Chain

The incident follows a string of losses on BNB Chain this year that came from weak permission controls rather than complex hacks. In July, The Crypto Times reported that a token linked to Crypto DAO was drained for about $8.2 million on BNB Chain after cybersecurity firm Blockaid flagged an active exploit on July 28, in a case tied to an access-control bug.

What Remains Unconfirmed

Every step of the 79AU drain can be viewed on the BNB Chain. What has not been publicly confirmed is how control of the operator key was obtained, whether the activity came from an outside attacker or an insider, and whether any part of the 16,249 BNB has been recovered. The Crypto Times will update this story with any response and update from official sources.

Also Read: Crypto Trader Frogman Loses Over $4M in Wallet Hack in Singapore During TOKEN2049

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BinanceCrypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Greece Lowers Proposed Crypto Tax Rate to 10% in Public Consultation
Greece Lowers Proposed Crypto Tax Rate to 10% in Public Consultation
Smartphone screen displaying the blue and green Standard Chartered logo and wordmark against a blurred corporate backdrop
Standard Chartered Plans Crypto and Stablecoin Custody in Singapore for Institutions
TOKEN2049 Singapore event backdrop on a dark stage displaying "1-2 October 2025 • Marina Bay Sands" with blue spotlights and audience silhouettes below
TOKEN2049 Singapore Day 2: Wall Street, Coinbase Global Exchange, Cardano’s Midnight, AI, 2027 Expansion
Physical Jupiter (JUP) token coin standing alongside a Solana (SOL) coin with a financial price candlestick chart in the background
Why Is Jupiter Price Up Today? JUP Jumps Over 16% as Solana Slips
Physical Hyperliquid (HYPE) token coin standing upright with the green Hyperliquid logo and text displayed on a screen in the background
Hyperliquid (HYPE) Price Holds Near $87 After Pullback From $98 Peak

Find Us on Socials

You may also like

Hooded hacker working on a laptop displaying Uranium Finance branding next to a system breach alert.

US Jury Convicts Uranium Finance Hacker Over $54 Million Crypto Theft

Gold frog memecoin medallion set against a Singapore skyline at dusk with red market charts.

Crypto Trader Frogman Loses Over $4M in Wallet Hack in Singapore During TOKEN2049

Hooded figure using a laptop near an Ethereum coin and a MakerDAO logo displaying a red warning symbol.

Dormant MakerDAO Keeper Drained of $538K, Core Remains Intact

Hooded hacker figure in a dark room monitoring on-chain data for ZachXBT's investigation into the Bybit exploit

ZachXBT Posed as a Client to Map a Chinese Syndicate Laundering Bybit Hack Funds

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram
© 2026 The Crypto Times | Protocols And Tokens Pvt Ltd.
DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information