T
iTokenly

DEXX hack — November 2024

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedNovember 16, 2024
Target typeWallet software or provider
Loss$21,000,000Published estimates range $21,000,000 to $30,000,000Price at time of incident
MethodPrivate key compromiseDEXX generated and custodied users' wallet private keys on its own infrastructure. SlowMist founder Yu Xian said the attackers reached DEXX's production servers and database through a vulnerability in ZenTao, a third-party project management application, and used the extracted keys to sweep user wallets. Whether the keys were stored in plaintext is disputed: users alleged plaintext storage, while DEXX's founder said the failure lay in his team's handling of security rather than in the key-management design itself.
ChainsSolana, Ethereum, BNB Chain, Base
OutcomeUnresolved

What happened

DEXX, a memecoin trading terminal that generated and custodied users' wallet private keys on its own infrastructure, was compromised on 16 November 2024. Funds were swept from user wallets across several chains, with Solana the worst affected.

Losses were initially reported at more than $21 million, the figure DEXX's founder used publicly, affecting close to 1,000 users. SlowMist, which traced the funds, later linked more than 8,620 Solana addresses to the attacker and put the total nearer $30 million as memecoin prices moved. Proceeds were largely converted into SOL, and SlowMist said it was still identifying attacker addresses on Ethereum, BNB Chain and Base. The two figures reflect different valuation points rather than a dispute about what was taken.

The custody model was the root cause: keys were generated and held centrally. Users alleged they were stored in plaintext; DEXX's founder rejected that framing, saying the theft stemmed from his team's mismanagement of security rather than from the key-management solution's design, while accepting that responsibility lay entirely with them. SlowMist founder Yu Xian later said the attackers reached DEXX's production servers and database through a vulnerability in ZenTao, a third-party project management application, and characterised the breach as external exploitation rather than insider theft while holding DEXX responsible for weak security practice. Early speculation had pointed to an insider. No individual has been named and no arrests have been announced; DEXX's founder said suspects had been identified domestically and that a case had been filed with law enforcement.

DEXX halted the platform on the day of the theft. In December 2024 DEXX announced a compensation programme funded by a share of daily platform revenue, alongside debt-to-equity conversion and token airdrops, and opened a claims portal. Users were not made whole and the stolen funds were not recovered.

Law enforcement

DEXX filed a case with law enforcement and SlowMist assisted the subsequent investigation. DEXX's founder said suspects had been identified as domestic. No arrests have been announced publicly.

Sources

  1. ChainCatcher (interview with DEXX founder Roy)Primary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. Bitcoin WorldAggregator · retrieved 2026-08-01
  4. PANewsSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "DEXX hack — November 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/dexx
https://itokenly.com/hacks/dexx

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.