DEXX Hack - November 16, 2024
Overview
On November 16, 2024, memecoin trading terminal DEXX fell victim to a security exploit, resulting in losses impacting at least 900 unique users. The total loss from the incident was initially reported at $21 million, the second-largest hack in November behind the $25.5 million Thala hack (Thala recovered all lost assets). The total loss is later estimated to be within $30 million.
Scale of the Attack
Crypto security firm SlowMist released a document identifying more than 8,620 Solana addresses suspected of being linked to the DEXX hacker. Most victims lost less than $10,000 amid a private key leak, though one individual lost more than $1 million.
Root Cause
This incident was traced back to a private key leak within a centralized custody model, which exposed vulnerabilities in how the platform manages user assets.
Response
DEXX has partnered with SlowMist and law enforcement to investigate the attack and has committed to compensating affected users. The platform also offered a bug bounty and token reward if the stolen assets were returned within 24 hours.
Sources