On October 7, 2026, the 79thVault project on BNB Chain lost $12.5M. The on-chain trail is documented publicly and allows a minute-by-minute reconstruction.
Attack timeline on 79thVault: 52 minutes
- 1. 07:27 UTC.The first transfer leaves the operator wallet 0x019bd8ed – 10,000 79AU goes to the attacker's external EOA wallet. A test run.
- 2. 07:27–08:19 UTC.Six more transfers follow from the 79AU/USDT pair to the same address: 100,000, 100,000, 300,000, 500,000, 500,000, 500,000. Total haul on the attacker's wallet: 2.01M 79AU.
- 3. In parallel.The attacker begins dumping the received tokens back into the same 79AU/USDT pair through roughly 95 swaps. Fragmenting reduces slippage on each trade and extracts the maximum USDT from the pool.
- 4. By the end of the attack.The USDT reserve in the pair collapses from $15.2M to $3.9M. The attacker converts the extracted stablecoins into BNB. 16,249 BNB – around $12.5M at current prices – move to wallet 0x629b368c.
- 5. 41 seconds later.The operator wallet 0x019bd8ed transfers its own remaining 3.79 BNB to the same attacker address.
- 6. A parallel trail.Another 500,000 79AU moves to a separate wallet, 0xf219d073. After all operations, the 79thVault team revokes OPERATOR_ROLE from the compromised key.
Insider or stolen key: three clues
The on-chain data offers three signals pointing beyond a straightforward external attack.
First. The 41-second gap between the $12.5M cashout and the 3.79 BNB transfer from the same operator key to the attacker's wallet. An outside intruder with a stolen key would not linger on an empty address for three BNB – that is the behaviour of an owner clearing out what remains.
Second. The public "project team" message offering a bounty for the return of funds was sent from the same operator key. An external attacker would not write to the victim from the victim's own identity – that is the move of an insider, or someone certain the key will never resurface with the team.
Third. The design of the function itself. The privilege to move tokens directly out of a DEX pair to any address, bypassing the normal swap mechanism, is not an ordinary piece of a DeFi contract. Such a capability is embedded by someone who understands its value when liquidity is concentrated.
For outside observers, the "stolen key" and the "internal theft" scenarios look identical. Only an internal access audit can tell them apart.
