OKX DEX Approval Hack
What happened
The December 2023 OKX DEX incident targeted a legacy contract with spending access to users' previously approved tokens. Reports place the loss near $2.7 million and the malicious activity on December 12; December 13 is the date retained in this incident record. This was not a breach of OKX's centralized exchange custody.
A suspected compromise of the legacy proxy administrator enabled malicious implementation upgrades that abused existing token approvals. The public reports do not establish how the administrator credential was obtained.
How it happened
The attacker-controlled implementation used the legacy approval path to transfer tokens from affected wallets. Replacing a proxy implementation changes what an approved spender can do without requiring each wallet to grant a new allowance.
The on-chain analysis documents malicious upgrades and token transfers. The suspected key leak explains the administrator access, but remains an attribution of the initial compromise rather than a publicly demonstrated credential-theft method.
For reviewers, both upgrade authority and persistent allowances belong in the threat model. A contract disappearing from the active interface does not itself revoke those permissions.
Protocol details
Evidence
- report @TheBlock__ incident report twitter.com
- report @okxweb3 incident report twitter.com
- analysis Web Archive archive.ph
- analysis DeFiLlama defillama.com
- analysis Analysis of the OKX DEX Attack Incident sharkteam.org
- analysis OKX DEX suffers apparent $2.7 million exploit following suspected private key leak theblock.co
- analysis OKX DEX $2.7M exploit analysis olympix.security
- analysis SharkTeam: OKX DEX on-chain analysis sharkteam.org
- analysis OKX DEX suffers $2.7M exploit after proxy admin contract upgrade cointelegraph.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.