MABOnChain
Educational content only. Nothing on this site is financial advice.
Home / DeFi / 79thVault Loses $12.5M as Compromised Operator Key Drains 79AU Liquidity Pool
DeFi

79thVault Loses $12.5M as Compromised Operator Key Drains 79AU Liquidity Pool

By MABOnChain Desk · Published · Updated · 4 min read

Editorial digital-art illustration of a massive glowing golden key melting through a cracked steel vault door while dollar stablecoins drain through a jagged crack, with security analysts inspecting a glowing blockchain chain

Published October 8, 2026, 13:20 UTC. Reporting via Defimon Alerts, CertiK, GoPlus Security, PeckShield, The Crypto Times and COINOTAG.

A DeFi protocol on BNB Chain lost an estimated $12.5 million on October 7 when a wallet holding special administrative rights over its token quietly emptied the project's main liquidity pool. The incident, made public on October 8 by the on-chain monitoring account Defimon Alerts, is being treated as a suspected private key compromise or possible insider action, not a flaw in smart contract code.

The target was 79thVault's 79AU token. Between about 07:25 and 08:19 UTC on October 7, the wallet controlling the token's OPERATOR_ROLE called a privileged function seven times, moving 2.01 million 79AU out of the 79AU/USDT trading pair on PancakeSwap, according to Defimon Alerts and The Crypto Times. The tranches were sized at 10,000, 100,000, 100,000, 300,000, 500,000, 500,000 and 500,000 tokens, all sent to a single externally owned account.

The privileged function that emptied the pool

The 79AU token contract contains a function callable only by addresses holding the OPERATOR_ROLE, a permission level granted to selected addresses. According to Defimon Alerts, the function lets the operator move any amount of 79AU out of a designated address to any recipient, then calls sync(), which tells the liquidity pool to update its recorded balances.

Under normal operations the team's hot wallet had used that function only for small internal movements, shifting tokens from the pair into a rewards pool, COINOTAG reported. On October 7 the behavior changed: the operator wallet's seven calls pulled tokens out of the PancakeSwap pair at an address beginning 0x02d50b93 and delivered them to an attacker address beginning 0xc3e90f78.

From $15.2 million to $3.9 million in USDT

The receiving wallet then sold the 79AU back into the same PancakeSwap pair across roughly 95 swaps. Because the operator function had already removed the tokens from the pool without any payment, each sale extracted real USDT from the pool's reserves. The pool's USDT holdings fell from about $15.2 million to $3.9 million, according to The Crypto Times.

The proceeds were converted into 16,249 BNB, the native token of BNB Chain, worth about $12.5 million at the prevailing BNB price near $768, and sent to a separate wallet, COINOTAG reported. Forty-one seconds later, the operator wallet sent an additional 3.79 BNB of its own to that same destination. Defimon Alerts said the timing suggests the operator key and the drained funds were controlled by the same party, or that an insider was involved. A further 500,000 79AU was moved to an address beginning 0xf219d073, and the OPERATOR_ROLE permission was revoked after the transfers.

Where the stolen BNB sits now

Most of the loot has not moved since. Web3 security firm GoPlus Security reported that about 14,394.92 BNB, worth roughly $11.03 million, was sitting at a consolidation address as of its latest review, with no further large movements observed. That is about 89 percent of the 16,249 BNB extracted.

Separately, on-chain analytics firm PeckShield identified a 30 BNB deposit to the centralized exchange KuCoin linked to the incident. KuCoin has not publicly commented on whether it has frozen those funds.

An on-chain message offering a 10 percent bounty for the return of the remaining funds was sent to the recipient wallet. Defimon Alerts noted the message came from the same operator key used to carry out the transfers, so the bounty offer does not, on its own, confirm who currently controls that key.

One key, no multisig, unverified code

The red flags were visible before the drain. The 79AU contract source code is not verified on BscScan, so outside reviewers could not read the published code matching what runs on chain. At the time of the transfers the operator role sat with a single address, with no evident multisig requiring several keys to approve a transaction and no timelock delaying sensitive actions so users could react, according to The Crypto Times.

Blockchain security firm CertiK flagged the activity as a suspected exploit carried out through a privileged function. The incident fits a pattern of losses on BNB Chain this year from weak permission controls rather than complex exploits: in July a token linked to Crypto DAO was drained for about $8.2 million after cybersecurity firm Blockaid flagged an active exploit tied to an access-control bug.

79thVault's official X account has posted a notice describing a "system upgrade" and warning that front-end features and some asset operations may be temporarily affected. As of publication the project had not released a detailed incident report, a loss reconciliation or confirmation that the operator key was compromised. What remains publicly unconfirmed is how control of the operator key was obtained, whether the activity came from an outside attacker or an insider, and whether any part of the 16,249 BNB has been recovered.

This article is news reporting and is not investment advice.

Sources

Not financial advice. This content is for information and education only. See our disclaimer, editorial policy and disclosures.

MABOnChain Daily Brief

The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.

Loading the signup form…

Prefer chat? Join us on Telegram

Keep reading

Markets

Evernorth Pushes XRPN Nasdaq Debut to October 12 After Administrative Delay

October 8, 2026 · 4 min read

Evernorth Holdings disclosed in an October 6 SEC filing that an administrative delay moved its merger with Armada Acquisition Corp. II to on or about October 9, with Class A shares beginning Nasdaq trading under ticker XRPN on or about October 12. The XRP treasury company still expects to hold about 473 million XRP at closing.

Markets

NEAR Climbs Into Crypto's Top 20 After 140% Monthly Surge

October 8, 2026 · 4 min read

NEAR entered the top 20 cryptocurrencies by market capitalization on Thursday with a $7.2 billion valuation after a 138% monthly rally, per CoinGecko. NEAR Intents has handled more than $31 billion in cumulative volume, Bitwise launched the first U.S. spot NEAR fund on September 29, and the Quantus Network launched the first post-quantum asset on the NEAR platform. NEAR Intents also recovered from a $3.8 million exploit last week, with all funds returned on October 2.

Markets

Standard Chartered Plans Crypto Custody for Institutions in Singapore

October 8, 2026 · 4 min read

Standard Chartered's Singapore unit plans to offer custody for selected crypto assets, stablecoins and tokenized real-world assets to institutional investors, subject to regulatory requirements. The move extends a custody footprint that already covers the UAE, Luxembourg and Hong Kong, and would sit alongside the bank's Financing and Securities Services business in Singapore.

Regulation

Greece Proposes 10% Tax on Crypto Gains With a 500 Euro Annual Exemption

October 8, 2026 · 4 min read

Greece's Ministry of National Economy and Finance published a draft bill on Wednesday proposing a 10% capital gains tax on individuals' cryptocurrency profits, with annual gains of up to 500 euros exempt. The proposal would let investors voluntarily declare previously realized gains without penalties, exempt crypto-to-crypto swaps, and add a flat 10% tax on staking, lending and liquidity provision returns. Public consultation closes October 22.