T
iTokenly

ALEX Lab (XLink bridge) hack — May 2024

Verified — 6 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedMay 15, 2024
Target typeCross-chain bridge
Loss$4,300,000Published estimates range $4,300,000 to $27,400,000Price at time of incident
MethodPrivate key compromiseA private key controlling ALEX Lab's XLink bridge was compromised — CertiK attributed the compromise to a phishing attack aimed at the deployer wallets. The attacker pushed three successive upgrades of the Bridge Endpoint proxy (0xb3955302E58FFFdf2da247E999Cd9755f652b13b) on BNB Chain to a malicious implementation, and separately used vault key access to move STX out on the Stacks side. The malicious implementation left the withdrawal function open to anyone, which allowed a white-hat to front-run the drain on the BNB leg.
ChainsBNB Chain, Ethereum, Other
Attributed toLazarus Group (North Korea)Suspected
OutcomePartially recovered

What happened

In mid-May 2024 an attacker holding a private key that controlled ALEX Lab's XLink bridge pushed three successive upgrades of the Bridge Endpoint proxy on BNB Chain to a malicious implementation. CertiK, whose monitoring flagged the incident, dates it 14 May; CoinDesk and Taylor Monahan's research compilation date it 15 May. CertiK attributed the key compromise to a phishing attack on the deployer wallets.

The reported size varies widely because the attack ran across three chains and much of it was reversed. The figure CoinDesk used, which ALEX itself repeated, is $4.3 million on BNB Chain: roughly $3.3 million in stablecoins, over $300,000 in bitcoin and about $75,000 in Sugar Kingdom tokens. That leg largely failed. The attacker's malicious implementation left the withdrawal function open to anyone, and a white-hat front-ran the drain, taking about $4.4 million and later returning it under a negotiated 10% bounty. ALEX said around $4.5 million of a further $5 million exposed on Ethereum was recovered or secured.

The larger movement was on Stacks, where about 13.7 million STX left a bridge vault. Taylor Monahan's Lazarus research compilation values that at about $27.4 million. Cointelegraph, reporting ALEX's own published spreadsheet, described roughly $13.7 million in Stacks tokens exploited, with about $3 million sent to centralised exchanges, $9.6 million left in wallets under the attacker's direct control and $3.7 million identified as held at exchanges. CertiK put the Stacks leg at only about $2 million. No combined cross-chain USD total was ever published by ALEX.

ALEX froze more than $3.9 million at exchanges, recovering full balances of 17 tokens, and offered a 10% bounty valid until 18 May with a promise not to prosecute. On 25 June 2024 it said forensic work assisted by ZachXBT produced transaction evidence linking the attack to the Lazarus Group.

Law enforcement

ALEX Lab said in May 2024 that it was preparing a police report to be filed if the attacker did not negotiate; no public confirmation of a filing, charges or indictment has been identified.

Sources

  1. CoinDeskSecondary · retrieved 2026-08-01
  2. CertiKSecondary · retrieved 2026-08-01
  3. CointelegraphSecondary · retrieved 2026-08-01
  4. Taylor Monahan, lazarus-bluenoroff-researchSecondary · retrieved 2026-08-01
  5. CoinspeakerSecondary · retrieved 2026-08-01
  6. Web3 is Going Just GreatSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "ALEX Lab (XLink bridge) hack — May 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/alex-lab-xlink-bridge
https://itokenly.com/hacks/alex-lab-xlink-bridge

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.