OKX DEX Approval Hack

Reported loss $2.7M
Ethereum
Malicious proxy upgrade

What happened

The December 2023 OKX DEX incident targeted a legacy contract with spending access to users' previously approved tokens. Reports place the loss near $2.7 million and the malicious activity on December 12; December 13 is the date retained in this incident record. This was not a breach of OKX's centralized exchange custody.

Technical root cause

A suspected compromise of the legacy proxy administrator enabled malicious implementation upgrades that abused existing token approvals. The public reports do not establish how the administrator credential was obtained.

How it happened

The attacker-controlled implementation used the legacy approval path to transfer tokens from affected wallets. Replacing a proxy implementation changes what an approved spender can do without requiring each wallet to grant a new allowance.

The on-chain analysis documents malicious upgrades and token transfers. The suspected key leak explains the administrator access, but remains an attribution of the initial compromise rather than a publicly demonstrated credential-theft method.

For reviewers, both upgrade authority and persistent allowances belong in the threat model. A contract disappearing from the active interface does not itself revoke those permissions.

Protocol details

Classification Suspected privileged-key compromise / unsafe upgrade authority
Protocol Type CEX
Affected asset / contract OKB
Implementation language Solidity
Protocol links Website @okxweb3

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.