Latest News

79thVault Loss Rises to $14.35M as Second 79AU Seller…

The suspected 79thVault exploit was larger than initially reported, with updated onchain analysis showing that privileged transactions removed 2.52 million 79AU from the project’s PancakeSwap liquidity pool and ultimately extracted approximately $14.35 million in USDT.Initial security alerts identified seven transfers totaling 2.01 million 79AU and approximately $12.5 million in proceeds. A transaction-level reconstruction by Bitquery later identified nine privileged withdrawals involving three recipient wallets, including a second seller that waited about five hours before converting another 500,000 79AU.

The revised analysis puts the total liquidity extracted by the two seller wallets at $14.35 million. About 17,881 BNB connected to the sales remained in three wallets at 12:53 UTC on Thursday, although some additional funds had entered a cross-chain swap service.

How Did the $12.5 Million Loss Become $14.35 Million?

The first sequence began at 07:25 UTC on October 7 when an operational 79thVault wallet used a privileged token function to remove 79AU directly from its PancakeSwap pool without purchasing the tokens.

The largest recipient, referred to in the analysis as Seller A, progressively sold those tokens back into the same pool. It extracted approximately $12.6 million in USDT and reduced the pool’s stablecoin reserves from about $15.2 million to $3.89 million.

Early reports largely stopped there. However, one 500,000-79AU batch had been sent to a second wallet at 07:41 UTC. That address waited until roughly 12:48 UTC before selling, extracting another $1.75 million.

Together, the sellers account for approximately $14.35 million in USDT removed from the pool. The episode therefore resembles neither an ordinary token dump nor a conventional flash-loan exploit: the tokens being sold had first been removed from the liquidity pool through an administrative capability.

Investor Takeaway

The revised loss matters because remaining holders face a much thinner USDT exit pool, making quoted 79AU prices less meaningful without corresponding liquidity depth.

Was the Operator Key Stolen?

That remains unresolved. All nine suspicious withdrawals were signed using 79thVault’s operational hot-wallet key, but blockchain records cannot determine whether an external attacker stole the credential or someone already able to access it initiated the transactions.

That distinction changes the technical diagnosis. A stolen credential would make this primarily a key-management failure rather than a contract vulnerability. A similar distinction mattered when Wasabi Protocol lost more than $5 million after an administrator key was compromised.

Conversely, a valid signature does not always prove a private key itself was stolen. The recent Bitget investigation showed how compromised authorization infrastructure can produce apparently valid transactions without exposing signing keys.

79thVault removed the operational wallet’s relevant permission shortly after the final suspicious pull. The project has not yet published a technical postmortem identifying how control was obtained. Its public communication Thursday referred instead to a “system upgrade” affecting some front-end and asset-related functions.

Why Does the Privileged Function Matter?

Onchain analysis indicates that the same mechanism was not an obscure emergency function. The operational wallet had used it hundreds of thousands of times since June to move 79AU from the trading pool, primarily toward contracts associated with the project’s reward system.

That creates a structural security issue for a protocol that markets its treasury architecture as automated and decentralized. Burning liquidity-provider tokens may prevent administrators from directly withdrawing conventional liquidity, but that protection is incomplete if a privileged token function can remove one side of the trading pair independently.

Bitquery also found that removing the compromised operational wallet did not eliminate the capability entirely. The original deployer retained equivalent permission, while 79thVault’s multisignature administration granted the role to a new wallet on October 8.

Private-key and infrastructure compromises have become a major source of crypto losses in 2026. Several of the largest first-half exploits originated from compromised keys or trusted infrastructure rather than Solidity flaws.

Investor Takeaway

79AU’s central risk is now permission design: whoever controls the privileged role can potentially alter the economics of a supposedly locked liquidity pool.

Can 79thVault Recover the Funds?

Recovery negotiations have already moved onchain. The project offered the recipient a 10% bounty in return for the remaining assets. The wallet holding much of the BNB subsequently replied with a counterproposal seeking to retain 25% and requesting that legal action be dropped.

No substantial return had been identified when the latest reconstruction was completed. The concentration of much of the BNB in traceable wallets may improve recovery prospects, but it does not guarantee that the assets will remain there.

The more immediate requirement is a full postmortem. 79thVault still needs to establish how the operational credential was accessed, which parties controlled it, whether other privileged roles were exposed and what safeguards now prevent another authorized wallet from repeating the same liquidity-removal sequence.

Until those questions are answered, the blockchain establishes the movement of the assets but not the identity or method of the person behind the signatures. What is clearer after the latest reconstruction is that the damage was larger than the first alerts suggested — and that the privileged mechanism at the center of the incident remains part of 79AU’s security model.

You may also like