Crypto DAO (BNB Chain Access-Control Exploit, July 2026)
Summary
Crypto DAO is a protocol deployed on BNB Chain whose Pro token vault contract was exploited on July 28, 2026, resulting in the loss of approximately $8.2 million in USDT. The root cause was a publicly callable vault function with no access-control modifier, allowing any external actor to trigger a full treasury drain without privileged credentials. As of the date of this investigation, no team communication, recovery plan, or post-mortem had been published.
Connected Entities
1 entities · 10 linked investigationsTimeline(4 events)
2026-07-28
Attacker called an unguarded vault function on Crypto DAO's Pro token contract on BNB Chain, draining approximately $8.2 million in USDT. Funds were split across three wallets controlled by attacker address 0x427671b2C8e91034A91FE698F9B7259b2345F45D.
CryptoTimes / Blockaid detection2026-07-28
Blockaid flagged the active exploit on-chain in real time and attributed the root cause to a missing access-control modifier on the vault function.
CryptoTimes2026-07-29
CryptoTimes published the first detailed public report of the exploit. SlowMist's Hacked database logged the incident. DeFiLlama categorized it under Protocol Logic (Solidity) losses. No team response had been issued by publication time.
CryptoTimes2026-07-29
Blockaid released its H1 2026 security report, recording a record 212 on-chain exploits and over $1.1 billion in losses for the first half of 2026, the broader environment in which the Crypto DAO exploit occurred.
The Block / CryptoTimesDecision Log
- #1publish⛓ pending7/29/2026, 5:08:35 PMhash: FRzq6zo1cvSudHSkxxjh9FECZw8o5pmV3zP8khqxzBY6
7 of 9 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 7/29/2026, 5:08:27 PM
last updated: 7/29/2026, 8:29:08 PM
avoid.net — verified advice for a post-truth world