ApolloX Hack

TOTAL LOST $2.2M
Medium Other bsc

What happened

ApolloX has been exploited for ~$2.1M. The attacker took advantage of the vulnerability of the claim() function. When attacker received about 53 Million $APX tokens from the contract, then swapped them via PancakeSwap for $BUSD.

Exploiter address: https://bscscan.com/address/0xd2419bcc…ba9a49

Victim address: https://bscscan.com/address/0xe2e912f0…06cd99

Exploiter contracts:

  1. Address
  2. Address
  3. Address
  4. Address
  5. Address
  6. Address

Exploit transactions:

  1. Tx
  2. Tx
  3. Tx
  4. Tx
  5. Tx
  6. Tx
  7. Tx
  8. Tx
  9. Tx
  10. Tx
  11. Tx
  12. Tx

Tokens swapped to ZAP bridge:

  1. Tx
  2. Tx 0x07e44384…8b1d28
  3. Tx 0x25ee8fc7…5b64f2

Then tokens were transferred to https://etherscan.io/address/0x9e532b19…68f261#tokentxns

Case & protocol details

Classification Exchange (DEX) / Input Validation
Protocol Type Exploit/Other
Affected asset / contract APX
Smart Contract Language Solidity
Official Website www.apollox.com/en
Protocol Twitter/X @ApolloX_com

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.