ALEX Hack

TOTAL LOST $4.3M
Medium Private Key Compromised (Phishing) / Access Control stacks

Summarize with AI

Affected Chain stacks Incident surface
Recovered - No recovery reported
All-Time Rank #455 By amount stolen
Auditors 1 Prior security audit

Incident Overview

ALEXLabBTC Exploit Results in $4.3 Million Theft and Subsequent Recovery

A recent exploit targeted XLink, where the deployer at 0xb3955302…52b13b executed four upgrades on a proxy contract linked to ALEXLabBTC. Within an hour, two addresses withdrew a total of $4.3 million in digital assets, which were transferred to addresses funded by TornadoCash. This attack was enabled through compromised private keys obtained via phishing, allowing the exploiter to drain assets from the XLink bridge.

The XLink team paused smart contracts and the bridge in response. The attacker took control of XLink endpoints on BSC and Ethereum, upgrading them to a malicious contract, leading to the withdrawal of ~$4.3 million on BSC, which was later recovered with the help of a whitehat. Another $5 million, mainly LunarCrush tokens, are secured on Ethereum.

Approximately $500k remains locked but secured. aBTC assets were unaffected as they are held in a custodian account at Cobo. The XLink team is monitoring the exploiter's wallets and coordinating with security partners to resolve the situation and return to normal operations, assuring the community that all necessary steps are being taken to address the exploit and assist affected users.

Exploit Transactions:

https://bscscan.com/tx/0x94746d33…bfb416

https://bscscan.com/tx/0x47e123af…8c7357

Destination Addresses:

https://bscscan.com/address/0xa747af2a…d53188

https://bscscan.com/address/0x27055ae4…3c484e

Incident Report

Protocol / Project ALEX
Date of Incident
Affected Chain(s) stacks
Attack Technique Private Key Compromised (Phishing) / Access Control
Classification Infrastructure / Other
Primary Source View Post-Mortem

Protocol Information

Protocol Type Dexs
Official Website app.alexlab.co/
Protocol Twitter/X @ALEXLabBTC
Team Anonymous
Source Code Unverified

Market Context at Time of Hack

Token Categories
Content Creation Crowdfunding Discount Token Entertainment Video BNB Chain Ecosystem Binance Alpha Binance Alpha Airdrops

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Operational-security tradecraft (phishing, malware, leaked seed phrases, or insider access) to obtain treasury signing authority
Capital Required Minimal capital - only enough to cover gas while draining the compromised accounts
On-Chain Access Valid signing authority over the compromised wallets / multisig signers, allowing direct transfer of funds or stake authorization
Target Reconnaissance Identification of ALEX's high-value treasury accounts and the authority / multisig structure controlling them
Execution Speed Speed to drain the compromised accounts before the team detects the breach and revokes signing authority or freezes the assets
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Hard to catch — private key / OpSec failures are outside smart contract audit scope
Audited by Audit Report 1 — still lost $4.3M. Prior audits don't guarantee safety, especially after post-audit code changes.

If you're auditing a protocol with similar architecture to ALEX, these are the critical security checks that could have prevented this incident (May 2024).

  • Verify all logic paths related to Private Key Compromised (Phishing) / Access Control are guarded by proper access controls and input validation - see the Access Control Attacks attack class for patterns
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Security Audit History

Related Attack Classes

The technique used in this hack maps to these vulnerability classes in our security curriculum:

See all Access Control Attacks examples →

Sources & References

Learn to Prevent the Next ALEX

The ALEX hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial