← 79thVault1 decision on this page
Audit log
Every state-changing event for 79thVault: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-10-09 20:10:42ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 454,986,676
- sig
5ZMHKkDt4A6r…1ajouVofexplorer ↗- hash
D2snJdArdoj3…gY8WWxL9sha256 → base58
verifying row…full verify ↗canonical bytes (13605 B) ▸
{"actor":"system:backfill","investigation_id":"07f28fe4-3496-4892-9af6-a01fdffff0ff","kind":"publish","page_slug":"79thvault","published_at":"2026-10-09T20:10:42.406Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"79thVault","sections":[{"content":"On October 7, 2026, the primary PancakeSwap trading pool for the 79AU token on BNB Chain was drained of funds reported at between approximately $12.5 million and $14.35 million, with outlets differing on the exact figure. According to CryptoTimes, an operator-controlled wallet made seven calls to a restricted function between roughly 07:25 and 08:19 UTC, moving about 2.01 million 79AU tokens out of the pool to an externally owned account, which then sold the tokens back into the pool across approximately 95 swaps; this pushed the pool's USDT reserves down from about $15.2 million to roughly $3.9 million. CryptoSlate and TokenPost reported a higher estimate of $14.35 million, attributing the gap to an earlier estimate that omitted a second seller wallet; depending on the source, the proceeds were converted into approximately 16,249 to 17,881 BNB. 79thVault itself attributed the incident to 'weaknesses in account permission management' without further detail.","heading":"Security Incident: $12.5-14.35 Million Pool Drain (October 2026)","severity":"critical","sources":[{"credibility":2,"name":"79thVault Hack: $12.5M Drained From 79AU Pool on BNB Chain (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/10/08/79thvault-hack-12-5m-drained-from-79au-pool-on-bnb-chain/"},{"credibility":2,"name":"Locked liquidity did not stop this $14 million crypto pool drain (CryptoSlate)","type":"news_article","url":"https://cryptoslate.com/79thvaults-14-million-pool-drain-shows-why-locked-liquidity-can-fail/"},{"credibility":2,"name":"Privileged Token Permission Drained $14.35 Million From 79AU Pool (TokenPost)","type":"news_article","url":"https://www.tokenpost.com/news/technology/29083"},{"credibility":2,"name":"79thVault Loses $12.5 Million as Privileged Wallet Drains BNB Chain Liquidity Pool (Blockfence)","type":"research","url":"https://blockfence.io/79thvault-loses-12-5-million-as-privileged-wallet-drains-bnb-chain-liquidity-pool/"}]},{"content":"Reporting indicates the loss was not caused by a flaw in PancakeSwap's automated-market-maker mechanics but by a privileged function built into the 79AU token contract itself. An address holding an 'OPERATOR_ROLE' permission was reportedly able to move tokens out of the liquidity pair and call a sync() function to rewrite the pool's recorded reserves, without depositing equivalent value in return — bypassing the usual requirement that a liquidity provider redeem an LP token to withdraw funds. Blockfence and CryptoTimes reported the role was held by a single address with no multisig or timelock safeguard, and that this wallet had previously been used only for small rewards-pool transfers before being used to drain the pool. On-chain monitoring firm Defimon Alerts was cited as assessing the incident as consistent with either a private-key compromise or possible insider action rather than a bug in the contract's core logic, while CertiK was cited describing it as a suspected exploit of a privileged function. The 79AU contract's source code was reported as unverified on BscScan at the time of the incident, limiting independent review. The operator role was reportedly revoked after the attack. The attacker's identity and the precise means by which the operator key was obtained have not been independently confirmed as of the most recent reporting reviewed.","heading":"Root Cause: Privileged OPERATOR_ROLE Function and Key Management","severity":"high","sources":[{"credibility":2,"name":"79thVault Hack: $12.5M Drained From 79AU Pool on BNB Chain (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/10/08/79thvault-hack-12-5m-drained-from-79au-pool-on-bnb-chain/"},{"credibility":2,"name":"79thVault Loses $12.5 Million as Privileged Wallet Drains BNB Chain Liquidity Pool (Blockfence)","type":"research","url":"https://blockfence.io/79thvault-loses-12-5-million-as-privileged-wallet-drains-bnb-chain-liquidity-pool/"},{"credibility":2,"name":"Privileged Token Permission Drained $14.35 Million From 79AU Pool (TokenPost)","type":"news_article","url":"https://www.tokenpost.com/news/technology/29083"}]},{"content":"On October 9, 2026, 79thVault stated that the attacker had returned 15,000 BNB — worth approximately $11 million — to a wallet designated by the project team; PeckShield's on-chain monitoring corroborated the transfer, and an additional 30 BNB was reportedly deposited by the attacker to KuCoin. The project described the returned amount as roughly 92% of the 16,249 BNB it said had initially been taken, and said it planned to return the recovered BNB to the liquidity pool and permanently burn the resulting LP tokens. KuCoin's news desk reported that the team had 'proposed a white-hat settlement solution,' though no detailed terms, legal agreement, or bounty percentage were disclosed in the sources reviewed. TokenPost reported that a separate analysis found the attack generated approximately 17,881 BNB in proceeds from an estimated $14.35 million in stolen USDT, which would put the recovered share closer to 84% of total proceeds rather than 92% — implying an unrecovered balance in a range of roughly $1.5 million to $3 million depending on which total-loss figure is used. The attacker's identity has not been publicly confirmed in any source reviewed.","heading":"Fund Recovery and Disputed Settlement","severity":"medium","sources":[{"credibility":2,"name":"79thVault Recovers 15,000 BNB as Bitget Questions Full Return (TokenPost)","type":"news_article","url":"https://www.tokenpost.com/news/technology/29138"},{"credibility":2,"name":"Hacker returns 15,000 BNB to 79thVault in rare hack recovery (Cryptopolitan)","type":"news_article","url":"https://www.cryptopolitan.com/hacker-returns-bnb-to-79thvault-hack/"},{"credibility":2,"name":"79thVault hacker returns 15,000 BNB worth $11.1M (KuCoin News)","type":"news_article","url":"https://www.kucoin.com/news/flash/79thvault-hacker-returns-15-000-bnb-worth-11-1m"},{"credibility":2,"name":"79AU attackers return 15,000 BNB worth $11M to project team (KuCoin News)","type":"news_article","url":"https://www.kucoin.com/news/flash/79au-attackers-return-15-000-bnb-worth-11m-to-project-team"}]},{"content":"CryptoSlate reported that roughly 79% of the 79AU/USDT pool's liquidity-provider (LP) receipts had been burned or sent to an inaccessible address prior to the incident — a mechanism commonly presented to investors as protection against a rug pull — but that this lock did not prevent the loss, because the token contract itself retained a permission allowing tokens to leave the pool without an LP holder needing to redeem receipts. Bitquery's investigation, cited by CryptoSlate and TokenPost, found that as of an October 8, 2026 snapshot, two wallets (the contract deployer and a newly authorized address) still held pull authorization over the pool, and that read-only simulations indicated either could remove roughly 95% of the pool's remaining 79AU, suggesting the underlying exposure may not have been fully closed even after the initial attack and the reported revocation of the operator role. This case illustrates that locked or burned liquidity reduces, but does not eliminate, the risk of pool drains when a token contract contains administrative functions capable of bypassing standard AMM withdrawal mechanics.","heading":"Locked Liquidity Bypassed as a Safety Signal","severity":"medium","sources":[{"credibility":2,"name":"Locked liquidity did not stop this $14 million crypto pool drain (CryptoSlate)","type":"news_article","url":"https://cryptoslate.com/79thvaults-14-million-pool-drain-shows-why-locked-liquidity-can-fail/"},{"credibility":2,"name":"Privileged Token Permission Drained $14.35 Million From 79AU Pool (TokenPost)","type":"news_article","url":"https://www.tokenpost.com/news/technology/29083"}]},{"content":"Little independently verifiable information is available about 79thVault as an organization. A community-maintained wiki (IQ.wiki) describes '79th Vault' as a decentralized finance platform said to have launched in 2026 on BNB Smart Chain, describing it as 'chiefly anchored by gold reserves' and linked to an ecosystem referred to as 'CocoCat,' with the 79AU token used for staking, liquidity provision, and reward distribution across four pools it calls Staking, DEX Liquidity, Vanguard, and Defense. This description could not be corroborated against an official project website or any primary source identified in this investigation, and no named founders, operating company, or jurisdiction could be confirmed. Because this background relies on a single low-reliability, crowd-edited source, it should be treated as unverified and low-confidence.","heading":"Project Background","severity":"low","sources":[{"credibility":3,"name":"79th Vault (IQ.wiki)","type":"community_report","url":"https://iq.wiki/wiki/79th-vault"}]}],"sources_used":[{"credibility":2,"name":"79thVault Hack: $12.5M Drained From 79AU Pool on BNB Chain (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/10/08/79thvault-hack-12-5m-drained-from-79au-pool-on-bnb-chain/"},{"credibility":2,"name":"Locked liquidity did not stop this $14 million crypto pool drain (CryptoSlate)","type":"news_article","url":"https://cryptoslate.com/79thvaults-14-million-pool-drain-shows-why-locked-liquidity-can-fail/"},{"credibility":2,"name":"Privileged Token Permission Drained $14.35 Million From 79AU Pool (TokenPost)","type":"news_article","url":"https://www.tokenpost.com/news/technology/29083"},{"credibility":2,"name":"79thVault Loses $12.5 Million as Privileged Wallet Drains BNB Chain Liquidity Pool (Blockfence)","type":"research","url":"https://blockfence.io/79thvault-loses-12-5-million-as-privileged-wallet-drains-bnb-chain-liquidity-pool/"},{"credibility":2,"name":"79thVault Recovers 15,000 BNB as Bitget Questions Full Return (TokenPost)","type":"news_article","url":"https://www.tokenpost.com/news/technology/29138"},{"credibility":2,"name":"Hacker returns 15,000 BNB to 79thVault in rare hack recovery (Cryptopolitan)","type":"news_article","url":"https://www.cryptopolitan.com/hacker-returns-bnb-to-79thvault-hack/"},{"credibility":2,"name":"79thVault hacker returns 15,000 BNB worth $11.1M (KuCoin News)","type":"news_article","url":"https://www.kucoin.com/news/flash/79thvault-hacker-returns-15-000-bnb-worth-11-1m"},{"credibility":2,"name":"79AU attackers return 15,000 BNB worth $11M to project team (KuCoin News)","type":"news_article","url":"https://www.kucoin.com/news/flash/79au-attackers-return-15-000-bnb-worth-11m-to-project-team"},{"credibility":3,"name":"79th Vault (IQ.wiki)","type":"community_report","url":"https://iq.wiki/wiki/79th-vault"}],"summary":"79thVault is a BNB Smart Chain DeFi project behind the 79AU token. On October 7, 2026, its main PancakeSwap trading pool was drained of an estimated $12.5-14.35 million after a wallet holding a privileged OPERATOR_ROLE permission moved tokens out of the pool without depositing equivalent value, bypassing normal automated-market-maker mechanics. The project said on October 9, 2026 that the attacker had returned 15,000 BNB (about $11 million, roughly 84-92% depending on which total loss figure is used), leaving a disputed unrecovered balance; the attacker's identity and the exact cause of the key exposure remain unconfirmed.","timeline":[{"date":"2026","event":"79th Vault is reported to have launched as a DeFi platform on BNB Smart Chain, per a community wiki entry; no primary source identified in this investigation confirms a specific founding date or founding team.","source":"IQ.wiki","source_url":"https://iq.wiki/wiki/79th-vault"},{"date":"2026-10","date_evidence":"The attack began on October 7 when an operator wallet pulled 2.01 million 79AU tokens out of the project's PancakeSwap pool.","date_original":"2026-10-07","event":"An operator-controlled wallet used a privileged OPERATOR_ROLE function to pull approximately 2.01 million 79AU tokens from the PancakeSwap 79AU/USDT pool across seven transactions, selling them back into the pool in roughly 95 swaps and reducing USDT reserves from about $15.2 million to roughly $3.9 million.","source":"Cryptopolitan","source_url":"https://www.cryptopolitan.com/hacker-returns-bnb-to-79thvault-hack/"},{"date":"2026-10","date_original":"2026-10-08","event":"CryptoSlate and TokenPost reported a revised loss estimate of $14.35 million (versus an initial $12.5 million) after a Bitquery investigation identified a second seller wallet; read-only tests reportedly showed two wallets could still move roughly 95% of the pool's remaining 79AU.","source":"CryptoSlate","source_url":"https://cryptoslate.com/79thvaults-14-million-pool-drain-shows-why-locked-liquidity-can-fail/"},{"date":"2026-10","date_evidence":"The funds were sent to a wallet designated by the 79thVault team on Oct. 9, while another 30 BNB was deposited at KuCoin.","date_original":"2026-10-09","event":"The attacker returned 15,000 BNB (approximately $11 million) to a 79thVault team-designated wallet, which the project described as roughly 92% of the amount it said was taken; a competing analysis cited by TokenPost put the recovered share closer to 84% of total proceeds.","source":"TokenPost","source_url":"https://www.tokenpost.com/news/technology/29138"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 3621fe1d-0628-4dd9-9953-00c18fbf8348
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.