YFarmX

Tools Crypto Exploit Tracker exploit-0015

Exploit record

Crypto DAO Vault Drain

Loss
$52k
Attack vector
Access Control
Chain
BNB Chain
Sector
DeFi

What happened

On 28 July 2026, an attacker exploited missing access control on the vault behind Crypto DAO's Pro token, calling a state-changing exec() function that had been left publicly callable in a single flash-loan-assisted transaction. Per GoPlus Security's analysis, carried in SlowMist's database, the attacker's actual profit was about $52,000, with the contract losing around 167,200 Pro tokens.

The flaw is the elementary access-control class: a vault function anyone could call, with no permission check between the caller and the funds. An $8.2m figure circulated at the time and was carried here initially; SlowMist's own entry now states that sum was USDT held by related addresses Blockaid was monitoring, not the amount stolen, and this record was corrected on 22 August 2026 to GoPlus Security's ~$52,000 figure. SlowMist's database lists the incident against Ethereum, consistent with stolen funds moving there; contemporary reporting places the exploited contract on BNB Chain, and that is the attribution used here.

Sources

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026