Dexlyn Vault exploited via unauthorized contract upgrade; attackers drained funds through compromised owner address, now facing 48-hour white-hat recovery demand.
Security & Exploits ·
An onchain message posted to an Ethereum address alleges that the Dexlyn Vault was exploited through an unauthorized contract upgrade that enabled unauthorized fund withdrawals. According to the message, a vault implementation was upgraded to a new contract, and subsequent transactions drained funds from the vault via a separate intermediary address. The sender claims to have traced the flow of stolen assets across multiple addresses and blockchains, linking the activity to an arbitrage infrastructure and bot network.
The message, sent from an Ethereum address, offers the suspected recipient a path to resolve the matter cooperatively. The sender proposes treating the incident as a white-hat disclosure in exchange for a 10% bounty, contingent on the return of the remaining 90% of the drained funds. The message references specific transaction hashes and contract addresses to document the alleged exploit chain.
It remains unclear whether the recipient has responded to the demand, confirmed ownership of the implicated addresses, or whether any funds have been returned. The identity of the message sender—whether an official Dexlyn representative, security researcher, or third party—is not disclosed in the available material.