T
iTokenly

DxSale hack — May 2026

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeInfrastructure provider
Loss$7,300,000Price at time of incident
MethodAccess control flawOwnership of a legacy BNB Chain liquidity-locker contract was transferred to an attacker-controlled address after passing through roughly 80 intermediate wallets. Using owner privileges the attacker cut the lock-modification fee to near zero through a privileged setFee mechanism and backdated lock expiry timestamps, then exploited an unlockToken() function that paid out the stored LP amount without consuming the lock record, so the same lock index could be withdrawn repeatedly across more than 1,400 positions.
ChainsBNB Chain
OutcomeUnresolved

What happened

On 29 May 2026 an attacker drained roughly $7.3 million from legacy liquidity-locker contracts operated by DxSale, a BNB Chain token-launch and liquidity-locking service, hitting more than 1,400 legacy liquidity-provider positions. Control of the locker came first. On-chain analyst Tahax found that DxSale's deployer had silently transferred ownership of the legacy locker around August 2025, roughly nine months earlier, with no public announcement, and that admin rights then moved through roughly 80 intermediate wallets before reaching the address that executed the drain. Security research firm DARKNAVY dates the final transferOwnership call to 26 May 2026 at 01:08:56 UTC, executed using EIP-7702-style delegated code, and names the vulnerable locker and the attacker account. Coinsult identified a privileged setFee mechanism, which let the attacker reduce the lock-modification fee to near zero, combined with a backdated lock configuration. The attacker then called unlockToken() repeatedly: the function transferred the stored LP amount without consuming the lock record, so the same lock index could be reused. DARKNAVY counted 667,465 unlock events across 1,362 transactions and 45 LP token contracts, with a single transaction calling the function 500 times against one LP token. The attacker-controlled address moved roughly $1.87 million worth of BNB into two consolidation wallets and on to multiple Binance deposit addresses; other proceeds were swapped to BNB and routed through bridge and mixer services. PeckShield and Coinsult flagged the drain, and DxSale posted a notice on its X account hours later confirming an exploit was under investigation, without publishing affected contracts or transaction detail. On-chain investigators, including the account Eyeonchain, have argued the trail points to insider involvement or a leaked team key, citing an August 2025 offer circulating on DxSale's Telegram channel to unlock old DxSale LP positions in exchange for a share of the proceeds. That claim is unproven, no charges have been reported, DARKNAVY traces the ownership chain to a previously legitimate owner address rather than to collusion, and DxSale has not addressed it.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Attacker addresses

  • 0xeb3a9c56d963b971d320f889be2fb8b59853e449
  • 0xc4574DDEF299e7E563971e200433e592EeaaFA69

Sources

  1. DARKNAVYSecondary · retrieved 2026-08-01
  2. The DefiantSecondary · retrieved 2026-08-01
  3. crypto.newsSecondary · retrieved 2026-08-01
  4. CryptoPotatoSecondary · retrieved 2026-08-01
  5. AMBCryptoSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "DxSale hack — May 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/dxsale
https://itokenly.com/hacks/dxsale

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.