Skip to main content
Sign in

Audit log

Every state-changing event for Crypto DAO (BNB Chain Access-Control Exploit, July 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-07-29 17:08:35Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    FRzq6zo1cvSu…khqxzBY6sha256 → base58
    verifying row…
    canonical bytes (12608 B) ▸
    {"actor":"system:backfill","investigation_id":"f5182354-8f85-4c17-893e-eead4d4d56d2","kind":"publish","page_slug":"crypto-dao-bnb-chain-access-control-exploit-july-2026","published_at":"2026-07-29T17:08:35.435Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Crypto DAO (BNB Chain Access-Control Exploit, July 2026)","sections":[{"content":"On July 28, 2026, on-chain security firm Blockaid detected an active exploit against Crypto DAO's Pro token contract on BNB Chain. An attacker called a vault function that lacked any access-control guard, transferring approximately $8.2 million in USDT from the protocol treasury into an externally owned wallet. The exploit required no privileged credentials, no flash loan to create the vulnerability, and no sophisticated multi-step attack — the contract was, in effect, openly accessible to any caller. Funds were distributed across at least three receiving addresses controlled by the attacker, holding approximately $2.68 million, $2.69 million, and $2.78 million respectively. The primary attacker wallet identified on-chain is 0x427671b2C8e91034A91FE698F9B7259b2345F45D. DeFiLlama categorized the loss under Protocol Logic (Solidity) at time of reporting.","heading":"Exploit Summary","severity":"critical","sources":[{"credibility":2,"name":"Crypto DAO Drained for $8.2M on BNB Chain via Access-Control Bug — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-dao-drained-for-8-2m-on-bnb-chain-via-access-control-bug/"},{"credibility":2,"name":"SlowMist Hacked Database — Crypto DAO entry, July 28 2026","type":"research","url":"https://hacked.slowmist.io/"}]},{"content":"The vulnerability class is a missing access-control modifier on a state-changing vault function. In Solidity, such a modifier — typically onlyOwner, onlyRole, or a custom equivalent — restricts who may call a function. Its absence means any externally owned address can invoke the function as if it were a permissioned operator. This is among the most elementary checks on standard smart-contract security checklists and is caught by automated static-analysis tools such as Slither in routine audits. No audit report for the Crypto DAO Pro token contract has been identified. The exploit did not require a flash loan to manufacture the vulnerability; flash loans may have been used to maximize capital efficiency within the single exploiting block, but the underlying flaw was present and exploitable by any actor with any balance. The unprotected function was reportedly an exec() or equivalent vault-drain entrypoint. No contract verification or public source code has been identified at time of investigation.","heading":"Technical Vulnerability Analysis","severity":"critical","sources":[{"credibility":2,"name":"Crypto DAO Drained for $8.2M on BNB Chain via Access-Control Bug — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-dao-drained-for-8-2m-on-bnb-chain-via-access-control-bug/"},{"credibility":2,"name":"Access Control Vulnerabilities in Smart Contracts: Exploits and Fixes (2026) — Smart Contract Hacking","type":"research","url":"https://smartcontractshacking.com/attacks/access-control-attacks"}]},{"content":"As of July 29, 2026 — the date of first published reporting — Crypto DAO had issued no public acknowledgment of the exploit, no post-mortem analysis, no recovery plan, and no community update on any identified social channel. No token pause mechanism was activated. The absence of any communication following an $8.2 million loss is consistent with either project abandonment or a team unwilling or unable to respond. This investigation found no official website, verified social media account, or governance forum attributed to Crypto DAO that carried any incident-related communication.","heading":"Team Response and Transparency","severity":"critical","sources":[{"credibility":2,"name":"Crypto DAO Drained for $8.2M on BNB Chain via Access-Control Bug — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-dao-drained-for-8-2m-on-bnb-chain-via-access-control-bug/"}]},{"content":"The Crypto DAO exploit is the largest identified instance in a documented pattern of access-control and logic-vulnerability exploits targeting BNB Chain protocols in 2026. Comparable incidents include the ATM Token exploit on June 4, 2026, in which approximately $243,000 was drained via a flawed custom transferFrom() function that lacked adequate restrictions on an embedded swap mechanism, detected by CertiK. The DLMC Token exploit on June 24, 2026, resulted in approximately $222,560 in losses through flash-loan-enabled price manipulation against an inadequately protected referral-reward redemption path. Security researchers attribute the recurrence of these vulnerabilities to the low cost and minimal friction of deploying contracts on BNB Chain without undergoing formal audits. SlowMist's H1 2026 mid-year report documented 182 blockchain security incidents in the first half of 2026 totaling approximately $956 million in losses, identifying BNB Chain as the second most targeted ecosystem with roughly $36.35 million in losses. Blockaid's H1 2026 report recorded a record 212 on-chain exploits and more than $1.1 billion in total losses during the same period.","heading":"Pattern Context: BNB Chain Access-Control Exploits in 2026","severity":"high","sources":[{"credibility":2,"name":"ATM Token Exploit Drains $243K Through Hidden Swap Loophole — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/06/04/atm-token-exploit-drains-243k-through-hidden-swap-loophole/"},{"credibility":2,"name":"DLMC Token on BNB Chain Loses Approximately $222,600 in Flash Loan Exploit — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/06/25/dlmc-token-on-bnb-chain-loses-approximately-222600-in-flash-loan-exploit/"},{"credibility":2,"name":"SlowMist 2026 Mid-Year Blockchain Security and AML Report","type":"research","url":"https://slowmist.medium.com/slowmist-2026-mid-year-blockchain-security-and-aml-report-75e0862179ef"},{"credibility":2,"name":"Crypto Hacks Cross $1.1B in Record H1 2026 Losses: Blockaid — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-hacks-cross-1-1b-in-record-h1-2026-losses-blockaid/"},{"credibility":1,"name":"Crypto hacks hit record high in H1 2026 as losses top $1 billion, Blockaid says — The Block","type":"news_article","url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"}]},{"content":"No on-chain recovery transaction, white-hat negotiation, or law-enforcement referral has been identified in connection with this exploit as of the investigation date. Stolen USDT was distributed across three wallets attributed to the attacker. Tether Limited (issuer of USDT) has the technical capability to freeze specific addresses; no freeze action has been publicly confirmed. Users who held funds in the Crypto DAO Pro token vault at the time of the exploit have no identified recourse mechanism. No bug bounty, insurance fund, or restitution plan has been announced.","heading":"Fund Recovery and User Recourse","severity":"high","sources":[{"credibility":2,"name":"Crypto DAO Drained for $8.2M on BNB Chain via Access-Control Bug — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-dao-drained-for-8-2m-on-bnb-chain-via-access-control-bug/"}]},{"content":"This investigation found no verifiable evidence of: a third-party smart contract audit for any Crypto DAO contract; a public team identity or verifiable founding team; a published whitepaper or technical specification; a formal governance structure consistent with DAO claims; regulatory registration or licensing in any jurisdiction; or a bug bounty or responsible disclosure program. The combination of an unaudited vault contract, an anonymized or unidentified team, and the absence of any post-exploit communication represents a profile consistent with projects that either exit scam or are abandoned following a security failure.","heading":"Due Diligence Gaps","severity":"critical","sources":[{"credibility":2,"name":"Crypto DAO Drained for $8.2M on BNB Chain via Access-Control Bug — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-dao-drained-for-8-2m-on-bnb-chain-via-access-control-bug/"},{"credibility":2,"name":"SlowMist Hacked Database","type":"research","url":"https://hacked.slowmist.io/"}]}],"sources_used":[{"credibility":2,"name":"Crypto DAO Drained for $8.2M on BNB Chain via Access-Control Bug — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-dao-drained-for-8-2m-on-bnb-chain-via-access-control-bug/"},{"credibility":2,"name":"SlowMist Hacked Database","type":"research","url":"https://hacked.slowmist.io/"},{"credibility":2,"name":"SlowMist 2026 Mid-Year Blockchain Security and AML Report","type":"research","url":"https://slowmist.medium.com/slowmist-2026-mid-year-blockchain-security-and-aml-report-75e0862179ef"},{"credibility":1,"name":"Crypto hacks hit record high in H1 2026 as losses top $1 billion, Blockaid says — The Block","type":"news_article","url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"},{"credibility":2,"name":"Crypto Hacks Cross $1.1B in Record H1 2026 Losses: Blockaid — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-hacks-cross-1-1b-in-record-h1-2026-losses-blockaid/"},{"credibility":2,"name":"ATM Token Exploit Drains $243K Through Hidden Swap Loophole — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/06/04/atm-token-exploit-drains-243k-through-hidden-swap-loophole/"},{"credibility":2,"name":"DLMC Token on BNB Chain Loses Approximately $222,600 in Flash Loan Exploit — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/06/25/dlmc-token-on-bnb-chain-loses-approximately-222600-in-flash-loan-exploit/"},{"credibility":2,"name":"Access Control Vulnerabilities in Smart Contracts — Smart Contract Hacking","type":"research","url":"https://smartcontractshacking.com/attacks/access-control-attacks"},{"credibility":2,"name":"Biggest DeFi Hacks and Exploits of 2026 — CCN","type":"news_article","url":"https://www.ccn.com/education/crypto/defi-hacks-exploits-causes-crypto-stolen-2026/"}],"summary":"Crypto DAO is a protocol deployed on BNB Chain whose Pro token vault contract was exploited on July 28, 2026, resulting in the loss of approximately $8.2 million in USDT. The root cause was a publicly callable vault function with no access-control modifier, allowing any external actor to trigger a full treasury drain without privileged credentials. As of the date of this investigation, no team communication, recovery plan, or post-mortem had been published.","timeline":[{"date":"2026-07-28","event":"Attacker called an unguarded vault function on Crypto DAO's Pro token contract on BNB Chain, draining approximately $8.2 million in USDT. Funds were split across three wallets controlled by attacker address 0x427671b2C8e91034A91FE698F9B7259b2345F45D.","source":"CryptoTimes / Blockaid detection","source_url":"https://www.cryptotimes.io/2026/07/29/crypto-dao-drained-for-8-2m-on-bnb-chain-via-access-control-bug/"},{"date":"2026-07-28","event":"Blockaid flagged the active exploit on-chain in real time and attributed the root cause to a missing access-control modifier on the vault function.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/29/crypto-dao-drained-for-8-2m-on-bnb-chain-via-access-control-bug/"},{"date":"2026-07-29","event":"CryptoTimes published the first detailed public report of the exploit. SlowMist's Hacked database logged the incident. DeFiLlama categorized it under Protocol Logic (Solidity) losses. No team response had been issued by publication time.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/29/crypto-dao-drained-for-8-2m-on-bnb-chain-via-access-control-bug/"},{"date":"2026-07-29","event":"Blockaid released its H1 2026 security report, recording a record 212 on-chain exploits and over $1.1 billion in losses for the first half of 2026, the broader environment in which the Crypto DAO exploit occurred.","source":"The Block / CryptoTimes","source_url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 58fc6ba6-ee2a-40ff-a25f-d8522004b6e6
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.