ALEX Hack
What happened
This $4.3 million record covers the May 14, 2024 XLink bridge endpoint incident on BNB Smart Chain, not the separate larger Stacks-side loss reported days later. A compromised deployer key enabled malicious proxy upgrades, but a whitehat front-ran the endpoint withdrawals and the affected BSC assets were restored.
A compromised deployer private key retained proxy-upgrade authority over the bridge endpoint. That privileged authority permitted replacement of the legitimate implementation with attacker-controlled code.
Case & protocol details
How it happened
Using the compromised deployer key, the actor repeatedly upgraded the XLink BSC endpoint proxy to malicious, unverified implementations and attempted endpoint withdrawals. A whitehat front-ran the withdrawal path and moved approximately $4.3 million to a recovery-controlled wallet.
XLink paused the bridge and said the affected BSC smart-contract assets had been restored with whitehat assistance. This page deliberately does not combine that outcome with the distinct Stacks-side incident.
Funds Recovery
Recovered
$4.3M
Net Loss
$0
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Post-mortem rekt.news
- report ALEX Incident rekt.news
- report ALEX Lab Exploit Analysis medium.com
- transaction ALEX Bridge BSC Withdrawal Recovery Transaction bscscan.com
- analysis Website reference x.com
- analysis Website reference x.com
- analysis ALEX Incident Analysis certik.com
- analysis XLink BSC Asset Recovery Confirmation coinness.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.