Proxy Contract Takeover Drains $2.7M from OKX's DEX Aggregator
OKX's decentralized exchange aggregator became the latest casualty of a private key compromise, with roughly $2.7 million siphoned from users after attackers gained control of a proxy contract. The mechanism was simple in the end: the proxy was upgraded to a malicious implementation, then used to pull tokens from anyone who had previously granted it approval.
Word of the incident spread first through community reports of missing funds, flagged on Twitter, before security firm Slowmist sounded the alarm. OKX followed with an official statement confirming that the compromised contract was a deprecated version and had since been secured — leaving open the question of why a contract already marked for retirement remained live long enough to be exploited.

Although OKX operates primarily as a centralized exchange, it also runs a DEX aggregator aimed at more adventurous users chasing opportunities across on-chain markets, complete with marketing copy touting "best-in-class security".
Per Slowmist's writeup, the attacker gained control of the proxy admin governing a trusted contract that routes OKX DEX trades. Just before midnight UTC, that admin pushed an upgrade to the contract's implementation, opening the door to draining balances from any address that had approved the proxy.
How the approval chain was abused
Under normal operation, users approve a TokenApprove contract when swapping through OKX DEX; the DEX contract then moves the user's tokens by invoking TokenApprove's claimTokens function. That call path is meant to be restricted to a trusted DEX Proxy contract, and the Proxy Admin — itself controlled by a Proxy Admin Owner — holds the authority to upgrade the DEX Proxy.
Once the attacker seized control of the Proxy Admin Owner role, they swapped the DEX Proxy's implementation for a malicious version that called the DEX contract's claimTokens function directly, sidestepping the intended safeguards entirely. From there, the attacker repeatedly invoked the compromised proxy to pull tokens from wallets that had approved it.
Contracts and transactions involved:
- DEX contract: 0x70cbb871e8f30fc8ce23609e9e0ea87b6b222f58
- OKX DEX TokenApprove contract: 0x40aa958dd87fc8305b97f2ba922cddca374bcd7f
- DEX Proxy: 0x55b35bf627944396f9950dd6bddadb5218110c76
- Proxy Admin: 0x3c18F8554362c3F07Dc5476C3bBeB9Fdd6F6a500
- Proxy Admin Owner: 0xc82Ea2afE1Fd1D61C4A12f5CeB3D7000f564F5C6
- Upgrade transactions: 0xc6a5a7bc… and 0x22ebd2…
- Suspected attacker address funded via Tornado Cash: 0xFacf375Af906f55453537ca31fFA99053A010239
- Profit address holding $430k: 0x1F14E38666cDd8e8975f9acC09e24E9a28fbC42d
Slowmist's early estimate placed the damage at roughly $430,000, but follow-up analysis from PeckShield and Hacken put the real total closer to $2.7 million once four additional receiving addresses were factored in, together holding 800 ETH (about $1.7 million) and roughly $620,000 in stablecoins:
- 0xa15fe801dd5fd31a684c444b6980dbaf0c78d5ad
- 0x22a2931cb2a7b782d65b2b5562829e84d941b0f0
- 0xfe55502a57f388a69602b2780071b759a520468f
- 0x48e3712c473364814ac8d87a2a70a9004a42e9a3
Private key theft of this kind tends to be the work of seasoned operators, and centralized exchanges have absorbed some of the biggest losses from it recently — Poloniex and HTX (the latter twice) among the notable examples, alongside other incidents tied to the same playbook.

Only the week before, coverage here examined current phishing tactics and noted how difficult address-poisoning scams can be to catch, even for experienced users. This episode reinforces that point in an unexpected way: investigators themselves appear to have pasted a poisoned lookalike address into their public writeup, apparently mistaking a spoofed token transfer for a genuine 300 ETH movement.
Exchanges like OKX, though, market themselves to everyday retail users rather than security specialists — which raises the question of whether ordinary customers can reasonably be expected to understand proxy trust assumptions, let alone know to revoke approvals on contracts once they're deprecated.
That, in essence, is the trade-off baked into CeDeFi: a centralized exchange's private key breach can still reach into on-chain balances.
In its response, OKX initially pledged $370,000 toward reimbursing affected users before shifting its public messaging to other matters. Whether the rest of the losses get covered remains an open question.
Get new scam files the moment we publish them — usually 2–3 emails a week.