OKX‘s decentralized exchange and cross-chain bridge aggregator OKX Dex has fallen victim to a suspected hacking incident, resulting in losses exceeding $370,000. The breach raised alarms among users who noticed unauthorized transactions from wallets previously authorized on the platform.
The hacker is said to have exploited the vulnerability in OKX Dex’s authorization process as users exchange their crypto assets.
Vulnerability in the OKX Dex’s authorization process
Blockchain security firm SlowMist conducted a detailed analysis, pinpointing the vulnerability in the platform’s authorization process during user exchanges.
Specifically, users authorize the TokenApprove contract, allowing the Dex contract to transfer tokens as part of the trading process. The issue arose when the Proxy Admin Owner upgraded the Dex Proxy contract to a new implementation contract on December 12. This upgrade introduced functionality that directly called the claimTokens function of the Dex contract, enabling attackers to make unauthorized calls and pilfer tokens.
OKX Dex assured clients of reimbursement
When detecting the breach, OKX Dex promptly removed the compromised proxy address within minutes. This swift action likely prevented further losses. The exchange acknowledged that 18 addresses authorized for the contract were hacked, attributing the incident to the compromise of the management rights of an abandoned OKX Dex market maker contract.
All affected contracts were promptly deactivated, ensuring the safety of user assets.
OKX estimated the stolen funds at $370,000 and, in a bid to reassure affected users, pledged to compensate for the losses incurred.
Despite the security incident, OKX has exhibited growth in market share, as reported by on-chain analytics firm CCData’s recent exchange review. OKX, alongside Upbit and Bybit, has gained dominance in spot market share year-to-date. In the derivatives space, OKX and Bybit saw an increase in market share, while Binance experienced a decline.
The post OKX Dex losses $370K in hack, users assured reimbursement appeared first on Invezz