Dexlyn Vault exploited via unauthorized contract upgrade; attacker granted 48-hour white-hat bounty opportunity (10% of stolen funds) before escalation.
Security & Exploits ·
An exploit targeting the Dexlyn Vault has been disclosed through an onchain message sent to an address allegedly linked to the attacker. According to the disclosure, an unauthorized contract upgrade enabled the vault's owner address to withdraw funds, with the implementation replaced at a new contract address and subsequent withdrawals routed through additional addresses.
The message indicates that investigators traced the activity across multiple addresses and chains to an arbitrage infrastructure and bot network. The disclosure attributes the exploit to automated exploitation of a vulnerability in the Dexlyn Vault contract, rather than manual theft. The investigators have documented the transaction trail, funding sources, and cross-chain movements.
The disclosure offers a settlement: a 10% bounty if the funds are returned voluntarily within 48 hours, with the remaining 90% to be restored to the vault. If the attacker does not comply within that window, the matter would presumably escalate beyond the white-hat framework. It remains unclear whether the funds have been returned, whether the attacker will respond to the offer, or what enforcement mechanisms may follow.