79th Vault (79AU) hack — October 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | October 8, 2026 |
| Target type | Token contract |
| Loss | $12,504,000Price at time of incident |
| Method | Private key compromiseThe 79AU token contract let any holder of its OPERATOR_ROLE move tokens out of the 79AU/USDT pair to any address and resync the pair's reserves; the hot wallet holding that role was used to pull 2.01 million 79AU out of the pool, which were then sold back into it for its USDT |
| Chains | BNB Chain |
| Outcome | Unresolved |
What happened
79th Vault, a project on BNB Chain built around the 79AU token, lost about $12.5 million on 7 October 2026 when the PancakeSwap pool that held most of the token's dollar liquidity was drained. The 79AU contract, whose source code is not published, has a function reserved for an OPERATOR_ROLE that moves 79AU out of a chosen address to any recipient and then forces the pool to update its recorded reserves. According to Defimon Alerts and GoPlus Security, the role was held by a single hot wallet with no multisig or timelock, which had previously made only small transfers from the pool to the project's reward pool.
Between about 07:25 and 08:19 UTC that wallet made seven calls to the function, moving 2.01 million 79AU from the 79AU/USDT pair to one address in tranches of 10,000, 100,000, 100,000, 300,000, 500,000, 500,000 and 500,000 tokens. That address sold the tokens back into the same pool in roughly 95 swaps. Defimon Alerts reported the pool's USDT reserve falling from about $15.2 million to about $3.9 million. The proceeds were converted to BNB, and at 10:10 UTC 16,249.12 BNB was sent to a consolidation address; this registry read both the first operator call and that transfer on-chain. At the CoinGecko price of about $769.50 for that hour, the BNB was worth about $12.5 million, which is the headline here; the pool's fall in USDT of about $11.3 million is kept as the lower end. CertiK, Defimon Alerts and GoPlus Security all reported the same 16,200-16,249 BNB.
The project at first described the disruption as a system upgrade. In a statement on 8 October it said an attacker had obtained an operator's private key through weaknesses in account permission management, that the affected permissions had been fixed, and that a white-hat settlement had been offered and the other side had replied. Defimon Alerts and GoPlus Security noted that 41 seconds after the BNB transfer the operator wallet sent its own 3.79 BNB to the same consolidation address, and that the settlement messages were sent from that same operator wallet, so they treat an insider as possible alongside a stolen key. The cause is recorded as a private key compromise on the project's own account, with no attribution.
On 9 October at 08:14 UTC the operator wallet sent an on-chain message asking for 15,000 BNB to be returned to a named address, with the rest kept as a bounty. When this registry read the balances later that morning, the address that had held 14,394.92 BNB, about 89% of the proceeds, held 296.81 BNB, and the named return address held 13,000 BNB. No return had been announced, and this registry could not trace the transfer between them, so nothing is recorded as recovered yet.
Sources
- 79th Vault on XPrimary · retrieved 2026-10-09
- Defimon Alerts on XSecondary · retrieved 2026-10-09
- CertiK Alert on XSecondary · retrieved 2026-10-09
- GoPlus Security on XSecondary · retrieved 2026-10-09
- The Crypto TimesSecondary · retrieved 2026-10-09
- BNB Chain transaction (first operator call), read by this registryOn-chain · retrieved 2026-10-09
- BNB Chain transaction (16,249.12 BNB consolidation), read by this registryOn-chain · retrieved 2026-10-09
- BNB Chain transaction with the 15,000 BNB settlement message, read by this registryOn-chain · retrieved 2026-10-09
Changes to this entry
- Recorded two days after the attack. Provisional: a return may have started on 9 October (balances moved towards the address named in the project's settlement message) but none has been announced, so recovered is left empty until the project or the on-chain record confirms it.
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "79th Vault (79AU) hack — October 2026", iTokenly, accessed 2026-10-09, https://itokenly.com/hacks/79th-vault-79auhttps://itokenly.com/hacks/79th-vault-79auPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.