TLDR:
- A $12.5M loss hit 79thVault after an admin address was used without authorization on BNB Chain.
- One address held OPERATOR_ROLE with no multisig or timelock and made seven privileged calls in an hour.
- Proceeds became 16,249 BNB, and 14,394.92 BNB, about $11.03M, sits unmoved at a single address.
- The project called it a system upgrade and has not detailed the key compromise or the loss breakdown.
The 79thVault incident raises a central question: was it a hack or an insider action? The BNB Chain project lost about $12.5 million after a privileged admin address was used without authorization.
Close to 10,000 holders are affected. Security firm GoPlus Security reviewed the case on-chain. Its analysis leaves two explanations open, a leaked operator key or insider activity. The project has not confirmed either, and its public statement mentioned only a system upgrade.
What the On-Chain Data Shows About the Operator Role
GoPlus Security outlined the case in a post on X. It was titled “Hack or insider? Security analysis of the $12.5M loss at 79thVault.”
The firm said the 79AU contract has a function restricted to OPERATOR_ROLE. The source is unverified on BscScan. GoPlus stated that “centralized-control risk was high.”
On-chain calls show the function can move 79AU from a chosen address to any recipient. Here, it pulled tokens from the 79AU/USDT pair. It then called sync() to update the pair’s recorded reserves. The firm wrote that the “effect is backdoor-like.”
The role was held by address 0x019bD8ED017D11AF0eB24d28DCdd0f9930c85cA3. On the missing safeguards, GoPlus wrote, “No multisig. No timelock.”
Between 07:25 and 08:19 UTC, that address executed seven privileged calls. The firm listed a leaked operator key and an insider as the two possible sources.
Those calls moved 2.01 million 79AU to 0xc3E90f78A918594a605d584887b2775F4b80A099. Transfers ranged from 10,000 to 500,000 tokens each. They coincided with a sharp rise in the 79AU price. The role was revoked after the incident.
Why the Hack or Insider Question Remains Open
GoPlus traced the full path from the pair to the final wallets. The receiving address sold the 79AU into the pool and drained the USDT.
It then converted the proceeds into 16,249 BNB. Those funds were consolidated at 0x629B368c6BF1a9f190e38f21235033FEcE8A6231.
Several smaller transfers of 10 to 15 BNB each followed, and their purpose is unclear. Most funds now sit at 0xa9537B40b02Af7Af8f1543aea3691992B2174F89.
That address holds 14,394.92 BNB, worth about $11.03 million. GoPlus reported that no further movement has occurred yet.
The on-chain bounty negotiation message adds another question. It was sent from the same privileged address used in the incident.
According to GoPlus, using that address to talk to an attacker “would be unusual.” The firm added that the message’s authenticity “is still in question.”
Meanwhile, the project’s X post called the event a system upgrade. GoPlus described the wording as a “vague” one.
The project has not shared details on the suspected key compromise, the role-revocation transaction, or the loss breakdown. GoPlus said this limited disclosure “leaves open whether users have been given enough information.”
The post Is 79thVault Hack or Insider Job? GoPlus Examines $12.5M BNB Chain Loss appeared first on Blockonomi.

4 hours ago
6
Hack or insider? Security analysis of the $12.5M loss at 79thVault
(@GoPlusSecurity) 







English (US) ·