Fact-check findings
What an automated fact-checker found when it re-read OKX DEX against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
2 claimsThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #5[disputed][awaiting moderator]in the timeline
“2023-12-12”
reviewerOKX publicly acknowledged the exploit, described the contract as abandoned, removed the proxy from the trusted list, and committed to reimbursement — on December 12, 2023.Multiple contemporaneous sources place OKX's public acknowledgment, the trusted-list removal, and the reimbursement pledge on December 13, 2023 — the day after the exploit began — not December 12. The exploit itself began Dec 12, but the page's second timeline entry conflates the acknowledgment date with the exploit start date.Proposed correction (not yet applied)2023-12-13 - #20[disputed][awaiting moderator]in section: ZachXBT and Community Flags
“OKX participated in coordinated fund-freezing efforts during the May 2026 DSJEX/BG Wealth Sharing Ponzi collapse, helping freeze approximately $30 million in laundered funds.”
reviewerOKX participated in coordinated fund-freezing efforts during the May 2026 DSJEX/BG Wealth Sharing Ponzi collapse, helping freeze approximately $30 million in laundered funds.The page conflates two different figures from its own cited reporting: ~$30 million was the amount laundered THROUGH OKX-linked addresses, while OKX's own contribution to the freeze effort was reported elsewhere as ~$3.1 million out of a ~$41.5 million total. As written, the claim overstates OKX's remediation role and understates OKX's role as a laundering conduit.Proposed correction (not yet applied)OKX participated in coordinated fund-freezing efforts during the May 2026 DSJEX/BG Wealth Sharing Ponzi collapse, after approximately $30 million in laundered funds had flowed to OKX-linked deposit addresses; OKX's specific contribution to the roughly $41.5 million total frozen was not separately disclosed by OKX.
unverifiable
1 claimNo source the reviewer could reach confirms or contradicts the claim.
- #6[unverifiable][awaiting moderator]in section: December 2023 Proxy Contract Exploit
“Security researchers at Olympix noted the fundamental architectural flaw: concentrated upgrade control without on-chain governance or multi-sig protection created a critical single point of failure in an otherwise functional system.”
reviewerSecurity researchers at Olympix noted the fundamental architectural flaw: concentrated upgrade control without on-chain governance or multi-sig protection created a critical single point of failure.The cited Medium post blocked automated access (403), so the exact wording/attribution could not be directly confirmed, though the substance (centralized admin key, no multisig) is corroborated elsewhere.
partially supported
1 claimThe cited evidence supports part of the claim but not all of it.
- #19[partially supported][awaiting moderator]in section: ZachXBT and Community Flags
“OKX funded a ZachXBT probe into the 95% RAVE token crash”
reviewerOKX funded a ZachXBT probe into the 95% RAVE token crash.Technically the pledge came from OKX's founder personally rather than a corporate treasury action, but the founder explicitly framed it as OKX's support and the cited source's own headline describes it the same way the page does; this is a minor imprecision rather than a substantive misrepresentation.
confirmed
19 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in section: December 2023 Proxy Contract Exploit
“On December 12, 2023, beginning at approximately 22:23 UTC, OKX DEX suffered an exploit resulting in approximately $2.7 million in stolen user funds.”
reviewerOn December 12, 2023 at ~22:23 UTC, OKX DEX suffered an exploit resulting in ~$2.7 million stolen, caused by a Proxy Admin Owner with sole, non-multisig authority to upgrade the DEX Proxy contract; SlowMist attributed it to a suspected private key leak.Core facts (date, time, amount, attribution to SlowMist) are corroborated by the cited primary reporting and cross-checked via independent search. - #2[confirmed][no action needed]in section: December 2023 Proxy Contract Exploit
“A second malicious upgrade was made at approximately 23:53 UTC, extending the drainage window.”
reviewerThe attacker's malicious contract could directly invoke the claimTokens function of the TokenApprove contract, and a second malicious upgrade occurred at approximately 23:53 UTC, extending the drainage window.The claimTokens exploitation mechanism is independently confirmed; the precise 23:53 UTC second-upgrade timestamp could not be independently cross-verified beyond the cited technical writeups, but nothing contradicts it. - #3[confirmed][no action needed]in section: December 2023 Proxy Contract Exploit
“PeckShield estimated total losses at $2.7 million across multiple affected wallets; CryptoTimes reported an initial figure of approximately $424,000 from 18 addresses before the full scope was confirmed.”
reviewerPeckShield estimated total losses at $2.7 million; CryptoTimes reported an initial figure of approximately $424,000 from 18 addresses before the full scope was confirmed.Both figures and their sequencing are directly confirmed by the cited article's text. - #4[confirmed][no action needed]in section: December 2023 Proxy Contract Exploit
“OKX described the affected contract as 'an abandoned OKX DEX market maker contract that is no longer in use.'”
reviewerOKX described the affected contract as 'an abandoned OKX DEX market maker contract that is no longer in use,' committed to reimburse all affected users, and removed the compromised proxy from its trusted-contract list.Substance of OKX's public statement is corroborated across multiple contemporaneous outlets. - #7[confirmed][no action needed]in section: U.S. Department of Justice Settlement — $504 Million Penalty
“On February 24, 2025, OKX's parent company Aux Cayes FinTech Co. Ltd. pleaded guilty to operating as an unlicensed money-transmitting business and settled with the U.S. Department of Justice for $504 million.”
reviewerOn February 24, 2025, Aux Cayes FinTech Co. Ltd. pleaded guilty and settled with the DOJ for $504 million ($420.3 million forfeiture + $84.4 million criminal fine) for operating an unlicensed money-transmitting business.Well-corroborated across numerous independent outlets and matches DOJ's own figures reported in press coverage. - #8[confirmed][no action needed]in section: U.S. Department of Justice Settlement — $504 Million Penalty
“The DOJ found that from approximately 2018 through early 2024, OKX knowingly served U.S. retail and institutional customers through easily circumvented geoblocks, facilitating over $1 trillion in transactions.”
reviewerOKX knowingly served U.S. customers via easily circumvented geoblocks from ~2018 through early 2024, facilitating over $1 trillion in transactions and over $5 billion in suspicious transactions/criminal proceeds.Both the $1 trillion transaction volume and $5 billion suspicious-transactions figures are independently corroborated. - #9[confirmed][no action needed]in section: U.S. Department of Justice Settlement — $504 Million Penalty
“Critically, the DOJ found that OKX did not deploy commercially available transaction-monitoring software until approximately May 2023 — years after it had onboarded high-risk U.S. customers.”
reviewerOKX did not deploy commercially available transaction-monitoring software until approximately May 2023, and lacked controls to detect sanctions exposure.Confirmed via independent search of DOJ-sourced reporting. - #10[confirmed][no action needed]in section: U.S. Department of Justice Settlement — $504 Million Penalty
“one employee told a U.S. customer 'I know you're in the US, but you could just put a random country and it should go through.'”
reviewerAn OKX employee told a U.S. customer: 'I know you're in the US, but you could just put a random country and it should go through.'Quote is an accurate, verbatim excerpt of the longer DOJ-documented statement. - #11[confirmed][no action needed]in section: U.S. Department of Justice Settlement — $504 Million Penalty
“As part of the settlement, OKX accepted a three-year compliance monitor (lasting until approximately 2027) to overhaul its AML and KYC programs.”
reviewerAs part of the settlement, OKX accepted a three-year compliance monitor (lasting until approximately 2027) to overhaul its AML and KYC programs.One AI-generated search summary briefly suggested no monitor was imposed, but this could not be traced to any primary source and was contradicted by direct retrieval of the cited sanctions.io article plus multiple other outlets; treated as a search-summarization artifact, not a genuine dispute. - #12[confirmed][no action needed]in section: U.S. Department of Justice Settlement — $504 Million Penalty
“OKX subsequently re-entered the U.S. market in a regulated capacity following the settlement.”
reviewerOKX subsequently re-entered the U.S. market in a regulated capacity following the settlement.Confirmed by cited source and corroborating independent coverage. - #13[confirmed][no action needed]in section: Lazarus Group Laundering via OKX DEX (2025)
“In March 2025, OKX's DEX aggregator was identified as a conduit used by North Korea's Lazarus Group to launder approximately $100 million of the $1.5 billion stolen from Bybit in what is considered the largest centralized exchange hack in crypto history.”
reviewerIn March 2025, OKX's DEX aggregator was used by Lazarus Group to launder approximately $100 million of the $1.5 billion stolen from Bybit, the largest crypto exchange hack in history; Bybit CEO Ben Zhou publicly confirmed this.All elements — amount laundered, attribution to Lazarus, Bybit CEO's confirmation, and 'largest hack' characterization — are independently corroborated. - #14[confirmed][no action needed]in section: Lazarus Group Laundering via OKX DEX (2025)
“The suspension followed consultations with European regulators — specifically Austrian and Croatian officials — who were examining whether OKX's Web3 platform fell under the EU's Markets in Crypto-Assets (MiCA) regulation.”
reviewerOn March 17, 2025, OKX suspended its DEX aggregator after detecting Lazarus Group misuse, following consultations with Austrian and Croatian officials examining MiCA jurisdiction.Specific detail about Austria/Croatia is corroborated by independent reporting beyond the cited sources. - #15[confirmed][no action needed]in section: Malta AML Fines and EU Regulatory Issues
“In January 2024, OKX reached a settlement with the Malta Financial Services Authority (MFSA) that included a €304,000 fine and a commitment to hire an independent third party to review its governance and compliance procedures.”
reviewerIn January 2024, OKX settled with the Malta MFSA for a €304,000 fine and committed to hiring an independent third party to review governance/compliance.Directly confirmed. - #16[confirmed][no action needed]in section: Malta AML Fines and EU Regulatory Issues
“In April 2025, Malta's Financial Intelligence Analysis Unit (FIAU) issued a second, larger fine of €1.1 million (approximately $1.2 million) after an on-site examination in April 2023 uncovered 'serious and systematic' AML breaches.”
reviewerIn April 2025, Malta's FIAU issued a second, larger €1.1 million fine after an April 2023 on-site examination uncovered 'serious and systematic' AML breaches, including inadequate risk assessment of mixers, DEXs, stablecoins and privacy coins, and that ~half of customer files lacked required risk assessments.All specific details, including the 'serious and systematic' quote and named deficiency categories, are corroborated. - #17[confirmed][no action needed]in section: Malta AML Fines and EU Regulatory Issues
“Notably, the second fine was issued despite OKX having already obtained a MiCA license in January 2025, demonstrating that the license did not shield the company from accountability for prior compliance failures.”
reviewerThe second Malta fine was issued despite OKX having already obtained a MiCA license in January 2025.Sequence and framing are accurate. - #18[confirmed][no action needed]in section: CFTC Subpoena and OKB Flash Crash
“In February 2024, OKcoin — OKX's U.S.-registered division — received a subpoena from the Commodity Futures Trading Commission (CFTC). The probe relates to suspected fraud and other unlawful conduct around digital asset transactions, and is believed to connect to the January 23, 2024 flash crash of OKB, OKX's native exchange token, which lost significant value in a sudden, unexplained price movement.”
reviewerIn February 2024, OKcoin received a CFTC subpoena related to suspected fraud, believed to connect to the January 23, 2024 OKB flash crash.Both the subpoena and the flash-crash connection are independently corroborated; the page's hedged language ('believed to connect') is appropriately cautious. - #21[confirmed][no action needed]in section: User Protections and Remediation Record
“Following the December 2023 DEX exploit, OKX stated publicly that all user losses would be fully covered.”
reviewerFollowing the December 2023 DEX exploit, OKX stated publicly that all user losses would be fully covered.Corroborated. - #22[confirmed][no action needed]in section: User Protections and Remediation Record
“Following a June 2024 SIM-swap attack that compromised two user accounts via the 2FA system, OKX again fully compensated both victims and upgraded its authentication recommendations.”
reviewerFollowing a June 2024 SIM-swap attack that compromised two user accounts via the 2FA system, OKX fully compensated both victims and upgraded its authentication recommendations.Confirmed via independent search. - #23[confirmed][no action needed]in section: User Protections and Remediation Record
“OKX received a MiCA license in January 2025, signaling an intent to operate under EU regulatory compliance frameworks going forward.”
reviewerOKX received a MiCA license in January 2025.Confirmed.