OKX DEX aggregator hack — December 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | December 13, 2023 |
| Target type | Decentralised exchange |
| Loss | $2,700,000Published estimates range $370,000 to $2,760,000Price at time of incident |
| Method | Private key compromiseThe private key of the proxy admin owner of an OKX DEX contract was compromised. The attacker upgraded the DEX proxy implementation to malicious code and called claimTokens directly, pulling tokens from wallets that had granted allowances to OKX's TokenApprove contract. Eighteen addresses tied to a deprecated market-making contract were drained; SlowMist reported the attacker performed a second upgrade and continued taking tokens afterwards. |
| Chains | Ethereum |
| Outcome | Users reimbursed |
What happened
The OKX DEX aggregator was drained on 12 December 2023 after the private key controlling the proxy admin of one of its contracts was compromised. Reports place the first malicious transaction at 22:23 UTC.
SlowMist, which published the first technical account, said the proxy admin owner's key appeared to have been leaked. With it, the attacker upgraded the DEX proxy implementation to malicious code and called claimTokens directly, moving tokens out of wallets that had granted allowances to OKX's TokenApprove contract. Assets were taken from eighteen addresses tied to a deprecated market-making contract; reported tokens included WETH, USDC, USDT, SHIB, ELON and BTT. SlowMist noted the attacker upgraded the contract a second time and continued draining afterwards.
The size of the loss is disputed. PeckShield put it at more than $2.7 million, and that is the figure carried by most coverage. OKX's own assessment, reported through its Chinese-language channels, was far lower, around $370,000 and in any case under $400,000. Neither side published a reconciliation and the gap has never been explained; the two figures may be measuring different things, such as total outflows from all affected addresses versus the subset OKX regarded as its own liability.
OKX described the incident as the theft of management rights over an abandoned market-maker contract no longer in use, said it had secured user funds and revoked the contract's permissions, and committed to reimbursing affected users while working with authorities on recovery. Arkham Intelligence linked the same actor to exploits of LunaFi, Uno Re and RVLT and offered a 5,000 ARKM bounty for identifying information. No arrest or formal attribution has been reported.
Sources
- The BlockSecondary · retrieved 2026-08-01
- Crypto BriefingSecondary · retrieved 2026-08-01
- CoinpaperSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "OKX DEX aggregator hack — December 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/okx-dexhttps://itokenly.com/hacks/okx-dexPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.