79thVault Hack

Reported loss $12.5M
Access Control

What happened

On October 7–8, 2026, DeFi staking protocol 79thVault on BNB Smart Chain suffered a privileged account breach resulting in approximately $12.51M to $14.35M stolen.

The incident stemmed from weak access control management and a compromised operational private key tied to the unverified 79AU token contract. The contract contained a privileged function assigned to a single OPERATOR_ROLE address without multisig or timelock safeguards, which had historically been used to pull 79AU tokens from the PancakeSwap liquidity pool for reward distribution. The attacker utilized this key to execute seven privileged transactions, moving 2.01 million 79AU tokens out of the pool without payment.

The attacker then dumped the extracted tokens back into the pool for USDT, draining the pool's dollar reserves and swapping the proceeds into 16,249 BNB. The stolen assets were consolidated into fresh addresses, primarily 0xa953...2F89 holding ~14,385 BNB, while a small test transfer of 30 BNB was deposited into KuCoin. The team revoked the operator privileges, deployed emergency contract patches, and opened on-chain white-hat bounty negotiations with the attacker.

Protocol details

Classification Yield Aggregator
Protocol Type Exploit/Access control
Protocol links Website @79thVault

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.