CryptoReal
CASE FILE — Dec 13, 2023

Proxy Contract Takeover Drains $2.7M from OKX's DEX Aggregator

OKX's decentralized exchange aggregator became the latest casualty of a private key compromise, with roughly $2.7 million siphoned from users after attackers gained control of a proxy contract. The mechanism was simple in the end: the proxy was upgraded to a malicious implementation, then used to pull tokens from anyone who had previously granted it approval.

Word of the incident spread first through community reports of missing funds, flagged on Twitter, before security firm Slowmist sounded the alarm. OKX followed with an official statement confirming that the compromised contract was a deprecated version and had since been secured — leaving open the question of why a contract already marked for retirement remained live long enough to be exploited.

Although OKX operates primarily as a centralized exchange, it also runs a DEX aggregator aimed at more adventurous users chasing opportunities across on-chain markets, complete with marketing copy touting "best-in-class security".

Per Slowmist's writeup, the attacker gained control of the proxy admin governing a trusted contract that routes OKX DEX trades. Just before midnight UTC, that admin pushed an upgrade to the contract's implementation, opening the door to draining balances from any address that had approved the proxy.

How the approval chain was abused

Under normal operation, users approve a TokenApprove contract when swapping through OKX DEX; the DEX contract then moves the user's tokens by invoking TokenApprove's claimTokens function. That call path is meant to be restricted to a trusted DEX Proxy contract, and the Proxy Admin — itself controlled by a Proxy Admin Owner — holds the authority to upgrade the DEX Proxy.

Once the attacker seized control of the Proxy Admin Owner role, they swapped the DEX Proxy's implementation for a malicious version that called the DEX contract's claimTokens function directly, sidestepping the intended safeguards entirely. From there, the attacker repeatedly invoked the compromised proxy to pull tokens from wallets that had approved it.

Sums referenced in this case file

Contracts and transactions involved:

Slowmist's early estimate placed the damage at roughly $430,000, but follow-up analysis from PeckShield and Hacken put the real total closer to $2.7 million once four additional receiving addresses were factored in, together holding 800 ETH (about $1.7 million) and roughly $620,000 in stablecoins:

Private key theft of this kind tends to be the work of seasoned operators, and centralized exchanges have absorbed some of the biggest losses from it recently — Poloniex and HTX (the latter twice) among the notable examples, alongside other incidents tied to the same playbook.

Only the week before, coverage here examined current phishing tactics and noted how difficult address-poisoning scams can be to catch, even for experienced users. This episode reinforces that point in an unexpected way: investigators themselves appear to have pasted a poisoned lookalike address into their public writeup, apparently mistaking a spoofed token transfer for a genuine 300 ETH movement.

Exchanges like OKX, though, market themselves to everyday retail users rather than security specialists — which raises the question of whether ordinary customers can reasonably be expected to understand proxy trust assumptions, let alone know to revoke approvals on contracts once they're deprecated.

That, in essence, is the trade-off baked into CeDeFi: a centralized exchange's private key breach can still reach into on-chain balances.

In its response, OKX initially pledged $370,000 toward reimbursing affected users before shifting its public messaging to other matters. Whether the rest of the losses get covered remains an open question.

OKX
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.