ALEX Hack

REPORTED LOSS $4.3M
Medium Compromised deployer key used for malicious proxy upgrades BNB Smart Chain

What happened

This $4.3 million record covers the May 14, 2024 XLink bridge endpoint incident on BNB Smart Chain, not the separate larger Stacks-side loss reported days later. A compromised deployer key enabled malicious proxy upgrades, but a whitehat front-ran the endpoint withdrawals and the affected BSC assets were restored.

Technical Root Cause

A compromised deployer private key retained proxy-upgrade authority over the bridge endpoint. That privileged authority permitted replacement of the legitimate implementation with attacker-controlled code.

Case & protocol details

Classification Access control / compromised deployer key / bridge
Protocol Type DEX
Official Website app.alexlab.co/
Protocol Twitter/X @ALEXLabBTC

How it happened

Using the compromised deployer key, the actor repeatedly upgraded the XLink BSC endpoint proxy to malicious, unverified implementations and attempted endpoint withdrawals. A whitehat front-ran the withdrawal path and moved approximately $4.3 million to a recovery-controlled wallet.

XLink paused the bridge and said the affected BSC smart-contract assets had been restored with whitehat assistance. This page deliberately does not combine that outcome with the distinct Stacks-side incident.

Funds Recovery

100.0%

Recovered

$4.3M

Net Loss

$0

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.