Panewslab DxSale Suffers $7.3M Exploit Due to BNB Chain Compatibility Issue
Article Content
- •The security incident involved a $7.3 million theft from DxSale's v1 lockup contracts.
- •Only the v1 contracts launched in 2021 were affected; v2 and later contracts are secure.
- •The exploit was enabled by a compatibility issue with BNB Chain's Atomic Transaction feature.
On May 30, 2026, DxSale reported a security incident involving a vulnerability in its v1 lockup contracts, launched in 2021, caused by a compatibility issue with BNB Chain's Atomic Transaction feature. The exploit led to the theft of approximately $7.3 million from over 1,400 liquidity pools. The affected contracts were identified, and it was confirmed that v2 and later contracts are secure and unaffected, having passed CertiK audits. The attack involved manipulating ownership through a backdoor contract, with the attacker transferring 2,958 BNB (around $1.87 million) to multiple wallets. DxSale reassured users that their funds in v2, v3, and subsequent versions remain safe. The incident has drawn significant market attention due to the scale of the theft and the nature of the vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track DxSale in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…