InvestReports disagree2 publishers2 min readPublished
Attacker returns 15,000 of the 16,249 BNB drained through 79thVault's own operator role
79thVault's 79AU pool on PancakeSwap was drained on October 7 through a permission inside the project's own token. Cryptopolitan reported that the attacker has returned 15,000 of the 16,249 BNB, and the team plans to re-seed the pool behind burned LP tokens, the same lock Bitquery found on 79% of receipts when it was drained.
The Investor · Invest desk

What happened
- An operator wallet pulled 2.01 million 79AU tokens out of the pool in seven transactions between 07:25 and 08:25 UTC, then sold them for BNB in about 95 trades.
- Bitquery, in an investigation published October 8, put the pool's loss at $14.35 million in USDT, taken through two selling wallets.
- In an October 8 statement, 79thVault blamed the hack on "weaknesses in account permission management."
- Defimon Alerts flagged the drain as a suspected private-key compromise or insider activity tied to the contract's operator role.
- Bitget chief executive Gracy Chen said she is "not very optimistic" about recovering the $388 million stolen from the exchange last month.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- contradiction Valued at the sale price, the 15,000 returned BNB are worth about $11.5 million, roughly 80% of the $14.35 million Bitquery says left the pool, so the 92% figure holds only when the loss is counted in coins.
- exposure One wallet can still withdraw about a fifth of the pool's liquidity by ordinary redemption, per Bitquery's snapshot, so traders counting on the burned-LP lock are counting on 79% of receipts at most.
- precedent This month's returns set no expectation for state-linked thefts, where the Bybit record is about $52 million frozen out of roughly $1.5 billion.
The attacker kept 1,249 BNB [18]. That is about 7.7% of the proceeds [20], or roughly $960,000 at the $769 a coin implied by Cryptopolitan's valuation of the sale [15][21]. 79thVault linked the on-chain transaction for the coins it got back in its post on X [3]. How big the original loss was depends on whose figure you use. Cryptopolitan values the BNB at about $12.5 million and reports the pool's USDT reserves falling from about $15.2 million to $3.9 million [22], a drop of $11.3 million [27]. Bitquery counts $14.35 million [24]. The sources do not reconcile the three figures.
Cryptopolitan puts the return beside NEAR Intents. That attacker sent back the full $3.8 million about a day after general manager Alex Shevchenko posted the wallet addresses and a 48-hour ultimatum [7]. "We have identified you, sir," Shevchenko wrote [8]. The outlet's explanation for both cases is that the attacker could be identified and pressured [13].
Here the access came from inside the contract. The key may have been stolen, or used by someone who already held it. Either way, the largest risk to a holder of a pool built like this is whoever controls the privileged wallet. Reports cited by Cryptopolitan say 79AU carried an OPERATOR_ROLE able to move tokens out of the pool and rewrite its reserves [23].
The two accounts of that permission point in different directions. If the role was revoked, as those same reports say [23], the BNB going back in is out of reach of this route. If Bitquery's snapshot at 12:53 UTC on October 8 still describes the contract, the deployer and a newly authorized wallet both hold pull rights [25]. In read-only simulations that moved no funds, either could remove about 95% of the pool's remaining 79AU [25]. Both accounts can be true if the revocation came after the snapshot, and CryptoSlate says only a fresh check of the transfer permission can establish whether the exposure has ended [26].
I think the recovery tells 79AU holders less than that check would. Or rather, the recovery raises the stakes of the check, since every returned coin put back into the pool sits behind whatever permission survives. The team plans to put the BNB back and burn the new LP tokens [4]. Burning receipts restricts redemption without revoking any privileged address's token permissions [11]. Putting 15,000 BNB into pool depth (the coins, not a dollar figure anyone agrees on) is a bet that the role is gone. The view is wrong if an on-chain read shows no address left with pull rights on 79AU before the coins go back in.
What to watch
- A fresh on-chain read of 79AU's transfer permissions showing whether the deployer and the newly authorized wallet Bitquery flagged still hold pull rights before the BNB is re-deposited.
- Whether the 1,249 BNB the attacker kept moves on-chain, or 79thVault says it agreed to let the attacker keep it.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives50
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On October 7 an operator wallet pulled 2.01 million 79AU tokens out of the project's PancakeSwap pool in seven transactions between 07:25 and 08:25 UTC, then sold them for BNB through roughly 95 trades.
- [2]
79thVault recovered 15,000 of the 16,249 BNB, about 92%, stolen when its 79AU PancakeSwap pool was drained on October 7.
- [3]
The 79thVault team confirmed on X that the hacker returned 15,000 BNB, linking an on-chain transaction for the recovered coins.
- [4]
79thVault plans to put the BNB back into its liquidity pool and permanently burn the LP tokens that result.
- [5]
79thVault blamed the hack on "weaknesses in account permission management" in its October 8 statement.
- [6]
Defimon Alerts flagged the incident as a suspected private-key compromise or insider activity tied to a since-revoked OPERATOR_ROLE function.
- [7]
The NEAR Intents attacker sent back the entire $3.8 million stolen about a day after general manager Alex Shevchenko posted the attacker's wallet addresses and a 48-hour ultimatum.
- [9]
Bitget CEO Gracy Chen said she is "not very optimistic" about recovering the $388 million stolen from her exchange last month, and said North Korea may be behind the breach.
- [10]
Bitquery found that 79% of the pool's liquidity-provider receipts had been burned, but a permission inside 79AU let tokens leave the pool without payment, and those tokens were sold back for USDT.
- [11]
Burning LP receipts prevents their redemption but does not disable swaps, rewrite the token contracts' balance rules or revoke a privileged address's token permissions.
- [12]
The same Bitquery snapshot showed one wallet holding the unburned 21% of LP receipts, with ordinary redemption rights over that share.
- [13]
Cryptopolitan wrote that two incidents similar to the 79thVault refund occurred in two weeks, showing that when the attacker can be identified and pressured, the money can be recovered.
- [14]
Chen referred to the February 2025 Bybit hack, where only about 3.5% of roughly $1.5 billion was ever frozen.
- [15]
The sale implied a price of about $769 per BNB.
- [16]
The 15,000 returned BNB are worth about $11.5 million at the sale-implied price.
- [17]
In dollars, the returned BNB cover about 80% of the $14.35 million loss Bitquery reported.
- [19]
About $52 million of the roughly $1.5 billion Bybit hack was frozen.
- [20]
The retained BNB is about 7.7% of the BNB taken.
- [21]
The retained 1,249 BNB is worth roughly $960,000 at the sale-implied price.
- [22]
The pool's USDT reserves dropped from about $15.2 million to $3.9 million. The sale of the 2.01 million tokens generated about 16,249 BNB, worth around $12.5 million.
- [23]
Reports state that the 79AU contract held an OPERATOR_ROLE function capable of moving tokens from the pool and rewriting its reserves, and that the permission was later revoked.
- [24]
According to a Bitquery investigation published October 8, the PancakeSwap pool for 79AU lost $14.35 million in USDT on October 7 through two selling wallets.
- [25]
At 12:53 UTC on October 8, Bitquery identified two pull-authorized addresses, the deployer and a newly authorized wallet. Read-only simulations from either allowed removal of about 95% of the pool's remaining 79AU; the tests moved no funds.
- [26]
Establishing whether 79AU's reported exposure has ended requires a fresh check of that transfer permission.
- [27]
The pool's USDT reserves fell by about $11.3 million, according to Cryptopolitan's figures.
Sources
2 independent publishers whose own reporting we read for this story.
- cryptopolitan.com79thVault claws back 92% of stolen BNB as Bitget doubts $388M return
1 article · October 9, 2026
- cryptoslate.comLocked liquidity did not stop this $14 million crypto pool drain
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Liquidity locks and LP burnsFollow
- DeFi SecurityFollow
- Crypto hack recoveryFollow
Entities
- NEAR IntentsFollow
- BNBFollow
- Defimon AlertsFollow
- Gracy ChenFollow
- BybitFollow
- 79AUFollow
- BitqueryFollow
- Alex ShevchenkoFollow
- PancakeSwapFollow
- 79thVaultFollow
- BitgetFollow