The suspected 79thVault exploit has proven significantly larger than first reported, with updated onchain reconstruction putting total extracted liquidity at approximately $14.35 million in USDT. Initial security alerts had identified seven transfers moving 2.01 million 79AU and generating about $12.5 million in proceeds. However, Bitquery’s transaction-level analysis later identified nine privileged withdrawals involving three recipient wallets, including a second seller that waited about five hours before converting an additional 500,000 79AU.
The upgraded figure reflects a more complete view of how privileged transactions removed 2.52 million 79AU from the project’s PancakeSwap liquidity pool. The first sequence began at 07:25 UTC on October 7, when an operational 79thVault wallet used a privileged token function to remove 79AU directly from the pool without purchasing the tokens. The largest recipient, referred to as Seller A, progressively sold those tokens back into the same pool, extracting roughly $12.6 million in USDT and reducing the pool’s stablecoin reserves from about $15.2 million to $3.89 million. A separate 500,000-79AU batch sent to a second wallet at 07:41 UTC was sold around 12:48 UTC, extracting another $1.75 million.
About 17,881 BNB connected to the sales remained in three wallets at 12:53 UTC on Thursday, although some additional funds had entered a cross-chain swap service. The incident does not resemble an ordinary token dump or a conventional flash-loan exploit because the sold tokens were first removed from the liquidity pool through an administrative capability. 79thVault removed the operational wallet’s relevant permission shortly after the final suspicious pull, but the project has not yet published a full technical postmortem. Its public communication Thursday referred instead to a “system upgrade” affecting some front-end and asset-related functions.
Recovery negotiations have moved onchain. The project offered the recipient a 10% bounty in return for the remaining assets, while the wallet holding much of the BNB replied with a counterproposal seeking to retain 25% and requesting that legal action be dropped. No substantial return had been identified when the latest reconstruction was completed. The broader security concern is that the privileged token function had been used hundreds of thousands of times since June, primarily toward contracts associated with the project’s reward system. The unresolved question is whether the operational hot-wallet key was stolen or accessed by someone already authorized to use it.
Separately, BitBay is grappling with a much smaller but symbolically similar vault exploit. According to an alert from the commentator @SlowMist_Team, BitBay lost approximately $14,000 because its vault’s withdrawal function did not limit payouts during zero liquidity, allowing an attacker to drain funds by manipulating the liquidity state. The BitBay incident reinforces ongoing worries about security practices across DeFi platforms, even as the 79thVault case draws more attention because of its larger scale and privileged-access design.