79thVault, a project operating on BNB Chain, suffered a loss of $12.5 million after unauthorized use of a privileged admin address. The incident affected nearly 10,000 token holders, raising questions over whether the event was triggered by a hack or internal activity.
GoPlus Security details admin privileges and asset transfers
GoPlus Security analyzed the event and found that the 79AU contract included a function reserved for an OPERATOR_ROLE, which granted significant control over assets. The contract’s source remained unverified on BscScan, and the firm described the level of centralized control as high.
The OPERATOR_ROLE was assigned to address 0x019bD8ED017D11AF0eB24d28DCdd0f9930c85cA3, allowing movements of 79AU tokens from arbitrary sources to chosen recipients. During the incident, seven privileged transactions took place within a single hour, initiating from the admin address.
Notably, there were no safeguards such as multisig or timelock mechanisms securing the OPERATOR_ROLE. The absence of these protections exposed project funds to increased risk.
GoPlus Security identified that the privileged role executed seven high-level transfers between 07:25 and 08:19 UTC, moving a total of 2.01 million 79AU tokens to 0xc3E90f78A918594a605d584887b2775F4b80A099. Token amounts in each transfer ranged from 10,000 to 500,000. The rapid sequence of these transfers coincided with a spike in the 79AU token’s price, after which the OPERATOR_ROLE was revoked.
Following these movements, the tokens were converted to USDT on decentralized exchanges before further exchanging the proceeds for 16,249 BNB. The bulk of these funds, representing roughly $11.03 million, currently remain at address 0xa9537B40b02Af7Af8f1543aea3691992B2174F89. Minor outflows of 10 to 15 BNB were observed, but the vast majority remains unmoved.
Project response and transparency concerns
In the aftermath, 79thVault publicly referred to the event as a system upgrade, but declined to clarify whether a compromised operator key, insider action, or other factor was responsible. Detailed information on the key compromise or a thorough breakdown of losses has yet to be released.
GoPlus Security highlighted an unusual on-chain communication: a bounty negotiation message sent from the same admin address as the exploit. The firm remarked that initiating negotiation with an attacker from a privileged address is atypical, and the authenticity of this message remains questionable.
According to GoPlus, the project’s limited disclosure of incident details leaves uncertainty over whether affected users have received sufficient information. The firm maintains that both insider action and key compromise remain plausible explanations.
Heightened market vigilance and meme token trends
As the crypto market continues to witness rapid innovation alongside risk, market participants have become more diligent in monitoring not only price action but also the security behind project operations and fund movements. This vigilance extends into the dynamic meme token sector.
In the meme token market, viral trends can generate substantial trading volumes in a short span. Data from Fomo App recorded a notable trade involving the token “Niu Lai,” where a $99 investment ballooned to approximately $370,000. Such examples underscore the importance of closely tracking investor decisions and token launches. Fomo App aims to meet this demand by integrating token discovery and real-time trading tools with social feeds, detailed investor rankings, and instant notifications in one platform.




