79AU lost $14.35M to a switch built into the token. Two keys can still flip it
For four months a switch inside the 79AU token moved coins out of its trading pool to pay rewards. Then someone else got hold of it and walked off with the pool's dollars. We went through the token's full record on BNB Chain to see how the switch worked and who can still use it.
- $14.35M
- 251,986
- $22.73
- 79%
- 17,881 BNB
- 95%
01 · An hour on 7 OctoberThe coins being sold had never been bought
If you held 79AU on 7 October, half its value was gone in about an hour. Nobody had bought a big bag and dumped it. The coins being sold had been taken from the same place they were sold into, and nobody paid for them.
Early that morning a brand new wallet started receiving the coins. Bigger batches followed every few minutes, and the wallet sold each one as it landed. By the time it stopped, most of the dollars that backed the price were gone.
79AU is the coin of 79thVault, a staking project on BNB Chain that started in May. Users paid in USDT and earned rewards in the project's coin. Their dollars sat in a liquidity pool on PancakeSwap, a decentralized exchange on BNB Chain. A liquidity pool is a shared pot of the coin and USDT that anyone can trade against. When you sell the coin, the pool pays you from that pot.
The pool held about $15.2M of USDT until the first sale. An hour later it held a quarter of that.
The drain was flagged on X by security firms and by the researcher 0xasen, and news sites put the loss at $12.5 million. Bitquery indexes every transaction on BNB Chain, so we went through the token's whole record, down to every transfer and every change to who was allowed to pull from the pool. Our count is $14.35M, because a second wallet sold later in the day. The coins came out through a switch the project built into its own token and used every day to pay rewards. A second key to that switch was never taken away, and the day after the drain the team handed the switch to a third.
02 · How 79thVault workedThe users' dollars sat in one PancakeSwap pool
79thVault calls itself a treasury-backed project anchored to gold, with a staking pool, a reward pool and a defense pool. On the chain the money took a shorter route: users sent USDT to the project, and the USDT ended up in the 79AU pool on PancakeSwap.
One of the project's contracts alone took payments from 8,460 wallets over the summer. Close to 100,000 addresses have received the coin at least once, a count you can pull from Bitquery's token holder data. The team's own message after the drain speaks of nearly 60,000 retail users.
A pool's price is just a ratio. Divide the dollars in the pot by the tokens in the pot, and you have the price. Buyers add dollars and take tokens out, so the price rises. Sellers do the opposite.
When you add money to a pool, it hands you a receipt called an LP token. Whoever holds the receipt can take that share of the pool back out. In the 79AU pool, 79% of those receipts were sent to a dead address, one nobody controls, which means that part of the money can never be withdrawn. In crypto this is called burned or locked liquidity, and it is meant to show that the team can't withdraw the pool. The remaining 21% sits with a wallet that helped seed the pool at launch.
The price ran from 2 cents at launch to a closing high above $10 in July. The biggest addition came in August, when the project's deployer wallet, the one that created the token, moved $15.2M of users' deposits into the pool and burned the receipts.
03 · The switchThe token could take coins out of the pool without paying
Most tokens move only when their owner sends them or allows it. 79AU has an extra switch. A wallet holding a special permission, a kind of admin key written into the token's code, could move 79AU straight out of the pool and send it anywhere, without paying a cent. The pool then updates its price as if a buyer had come along.
The quickest way to see it is in two pulls the thief made a few seconds apart. Before them, the coin cost $8.15. Each pull took half a million coins, and neither took a dollar out of the pool. Afterwards the price read $22.73. Those coins were then sold back in for real dollars.
The dollar side of the pool never moved. Only the coin side shrank, and the price climbed with every pull.
The project used this switch every day. Its hot wallet, a wallet whose key sits on a server so a bot can sign for it, pulled from the pool 251,986 times between June and the morning of the drain. Over those four months it took out about twice as many coins as the pool held on a typical day. Nine in ten went to two of the project's contracts, and one of those pays the rewards. You can trace calls like these with Bitquery's smart contract data.
Each routine pull took coins off the market for free and nudged the price up, and rewards were paid out of the contracts those pulls filled. We found no published copy of the token's code, so the switch shows only through what it did. Its function has no name in the public signature lists we checked.
Two wallets held the permission. The deployer, the wallet that created the token, got it at launch. The hot wallet got it the next day.
04 · The theftNine pulls in 54 minutes
The project's bot rarely rested for long. On the night before the drain it worked through the evening, then went silent for 5 hours and 52 minutes. Since its routine pulls began on 10 June, it had stopped for longer only once.
When the bot woke up, it sent a burst of routine pulls. Five minutes in, a different kind of transaction appeared from the same wallet. It sent a small first batch to a fresh wallet we call Seller A, which had got its first gas money that morning. That first pull carried a round gas limit the bot had never used in more than 350,000 earlier transactions.
The next pulls paid 200 times the gas price the bot was paying that morning, the way someone pays extra to jump the queue. They came every few minutes, and they grew.
| Time, UTC | 79AU pulled | Sent to | Transaction |
|---|---|---|---|
| 07:25:23 | 10,000 | Seller A | 0x18bc…d0cc |
| 07:30:41 | 100,000 | Seller A | 0xcc22…4910 |
| 07:34:33 | 100,000 | Seller A | 0x577f…e4f3 |
| 07:36:18 | 300,000 | Seller A | 0x66e2…a9be |
| 07:38:40 | 500,000 | Seller A | 0xd3d5…bcff |
| 07:41:04 | 500,000 | Seller B | 0x93a9…eaaf |
| 07:41:08 | 500,000 | Seller A | 0xf737…a7d6 |
| 08:07:29 | 10,000 | Third wallet | 0xfffa…5b68 |
| 08:18:59 | 500,000 | Seller A | 0x6846…5877 |
| Total | 2,520,000 |
The bot stopped soon after the first of the big pulls. The thief kept going. One pull went to a second wallet, Seller B, and seconds later another went to Seller A. A small one went to a third wallet, and the last came 54 minutes after the first.
About five minutes after the last pull, the team took the permission away from the hot wallet. The token's admin is a multisig that needs two signers, so one proposed the change and a second approved it. By then an hour had passed since the first pull. By the afternoon the team had stripped the same wallet's rights on 8 contracts.
| Time, UTC | What happened |
|---|---|
| 6 Oct, evening | The bot works through its routine pulls |
| 7 Oct, 01:28 | The bot goes silent for 5 hours and 52 minutes |
| 05:50 | Seller A gets its first gas money from the wallet that funded Seller B in August |
| 07:20 | The bot wakes up and sends 420 routine pulls in 19 minutes |
| 07:25 | First pull to Seller A, 10,000 79AU |
| 07:28 | Seller A starts selling |
| 07:39 | The bot's last routine pull |
| 07:41 | Pulls to Seller B and Seller A, 4 seconds apart |
| 08:18 | Last pull |
| 08:24 | The team's multisig removes the hot wallet's right to pull |
| 08:29 | Seller A's last sale. The pool is down to $3.89M |
| 10:10 | Seller A sends 16,249 BNB to the collection wallet |
| 12:48 to 12:59 | Seller B sells for $1.75M |
| 16:13 | The hot wallet has lost its right on all 8 contracts |
| 8 Oct, 03:54 | A team signer sends the hot wallet gas money |
| 8 Oct, 05:15 | The team's message to the thief, signed by the hot wallet's key: keep 10%, return the rest |
| 8 Oct, 11:49 | The thief replies from the wallet holding the BNB: wants to keep 25% and have legal action dropped |
| 8 Oct, 12:37 to 12:40 | The team's multisig gives the pull right to a new wallet on all 8 contracts |
Seller A sold for an hour, a little at a time. It took $12.60M in USDT out of the pool and cut the price in half.
05 · The second sellerA wallet waited 5 hours, then sold another $1.75M
Seller B got its coins in the same minute as one of Seller A's biggest batches, and then did nothing with them for 5 hours. Early in the afternoon it started selling, and within a quarter of an hour it had taken $1.75M more out of the pool. It still holds the proceeds in BNB.
Taking the permission away at 08:24 could not stop this. The tokens had already left the pool and were Seller B's to sell.
| First reports | What the chain shows | |
|---|---|---|
| USDT taken from the pool | $12.5M | $14.35M, by 2 wallets |
| Pulls from the pool | 7 | 9, to 3 wallets |
| 79AU pulled | 2 million | 2.52 million |
| Wallets that could pull on 7 Oct | 1 hot wallet | 2 |
| Wallets that can pull now | 2: the deployer and a new wallet |
The difference is Seller B, which sold five hours after the first wallet.
The small batch sent to the third wallet is harder to explain. That wallet had collected the project's rewards since June, like thousands of other users. It passed the coins to another wallet within the next two hours. We can't tell why it was picked.
06 · Where the money is17,881 BNB still sits in three wallets
Seller A sold into USDT and swapped straight on into BNB. Less than two hours later it sent all of it to one collection wallet. Forty-one seconds after that, the hot wallet sent its own last few BNB to the same place. Whoever sent that second transfer was holding the project's key.
From the collection wallet, most of the BNB went to a single new wallet that afternoon, and nearly all of it is still there. A smaller share went to a second wallet that has kept most of it. The rest, along with a little from the second wallet, left in 36 small pieces. Most of those went into a cross-chain swap service whose router we met in our NEAR Intents hack investigation. That service pays its orders out on other chains, so this part has probably left BNB Chain.
At midday on 8 October about $13.6M in BNB was still in those three wallets. Nothing had gone to the address the team asked for it to be returned to.
The thief's wallets drew scammers too. Within minutes, address-poisoning bots were sending worthless transfers from look-alike addresses to the thief's wallets, hoping for a careless copy and paste.
07 · Who had the keyThe hot wallet's key was in two places
That one key signed all nine pulls. Whether an outsider stole that key or someone on the inside used it, the chain can't say, and the record fits both.
Some facts point to planning. Seller B was funded in August, six weeks before the drain, by the same wallet that paid Seller A's gas on the morning of the attack. The bot fell silent for almost six hours, and the first pull came five minutes after it woke up. That fits a server break-in, like the server-held keys behind the drain in our LootBot investigation. It also fits someone who could switch the bot off.
And the key was in two places at once. The thief used it to sweep the wallet's leftover gas money. The next day one of the team's signers sent the same hot wallet a little BNB, and an hour later it carried the team's message to the thief. The message offered a 10% bounty, asked for the rest back, and named one of the team's own signer wallets as the refund address.
The thief answered at 11:49 UTC on 8 October, from the wallet holding most of the BNB. It sent the hot wallet 0.1 BNB with a short note. The note apologised for "unintentionally launching this attack" and called it a white-hat act. It asked to keep 25% instead of 10%, to have the warning flag on its address removed, and for the team to drop legal action. No money had come back when we last checked.
The gas wallet behind both sellers is busy. It has paid USDT to thousands of addresses this year, so it may be an over-the-counter desk rather than the thief. Our labels show it received $1.78M from a KuCoin hot wallet, so KuCoin may know who owns it.
08 · The keys leftTwo wallets can still pull 95% of what is left
When the team took the permission away from the hot wallet, it left the other holder alone. The deployer wallet has had the same right since launch, and the token still says yes when asked whether it holds it.
We tested it without sending anything. A dry run of the switch from the deployer wallet, asking for almost every coin in the pool, comes back as allowed. Sold back in, those coins would take most of the $4.63M of USDT that is left.
Then the list of keys grew. Less than an hour after the thief's reply, the team's multisig gave the same pull right to a brand-new wallet on all eight contracts, the token included. A team signer had sent that wallet its first gas money early that morning. It had sent no transactions when we checked. A dry run from it is allowed too. It looks like a replacement for the hot wallet.
The chart also shows the pool's other exit. The wallet holding 21% of the receipts can withdraw its share whenever it likes, as any liquidity provider can.
The deployer key is in active use. It sent thousands of transactions in two days in September, which means a script was signing for it. In August it was the wallet that moved users' money into the pool. Removing its permission takes the same two signatures the team gave eight times on the day of the drain.
09 · What to checkBurned liquidity is not the same as a safe pool
79AU passed one common safety check. Most of its liquidity receipts were burned, so nobody could withdraw the pool. That made it look safe from the classic rug pull, where a team pulls the liquidity and walks away.
Burned receipts only stop a withdrawal. They do nothing about a token that can move coins out of the pool by itself, and that is the door the thief used. Before trusting a pool, the useful questions are who can move the token without its owner, and whether anyone can read the code that decides.
So could it happen again? With the settings the token had on 8 October, yes. If you still hold 79AU, the pool you would sell into has 30% of the dollars it had before the drain, and two keys that can empty it are in place, one of them added the day after the drain.
10 · How we did itMethod
We read every call to the 79AU token on BNB Chain since it launched, picked out each use of the pull switch, and followed every coin that left the pool on 7 October to where it rests. Dollar figures for the drain are the USDT that left the pool in the sellers' own transactions. Balances, the pool and the permission checks were read again at 12:53 UTC on 8 October. BNB is valued at $761. The full history of BNB Chain transfers is also sold as files on the Bitquery Data Store.
To follow wallets like these yourself, ask the Bitquery MCP. If you need a case traced for you, that is what our investigations team does.
11 · The recordAddresses and transactions behind this story
| What | Address or transaction |
|---|---|
| 79AU token | 0xc35e…a9ca |
| 79AU/USDT pool, PancakeSwap | 0x02d5…da09 |
| Hot wallet, key misused | 0x019b…5ca3 |
| Deployer, still has the right | 0xe45c…40bc |
| Team multisig | 0xca8a…f2df |
| Seller A | 0xc3e9…a099 |
| Seller B | 0xf219…0938 |
| Gas wallet for both sellers | 0xe6af…f5a0 |
| Collection wallet | 0x629b368c…6231 |
| Holds 14,385 BNB | 0xa953…4f89 |
| Holds 1,212 BNB | 0x1e2a…16a3 |
| Refund address named by the team | 0x2bfc…b7b2 |
| Team removes the hot wallet's right | 0x1310…439d |
| Seller A sends 16,249 BNB on | 0xee0e…b0df |
| Team's message to the thief | 0x09f0…2344 |
| Thief's reply | 0x2a7a…a678 |
| New wallet with the pull right | 0x205b…dd07 |
| Team gives it the right on the token | 0xe3b4…3187 |
FAQ
What happened to 79AU?
On 7 October someone used the 79thVault hot wallet's key to pull the coin straight out of its PancakeSwap pool without paying, then sold the coins back into the pool for USDT. The price halved within an hour.
How much was taken in the 79AU hack?
About $14.35M in USDT left the pool through two wallets. One sold over the next hour, and the other sold about five hours later. Early reports counted only the first wallet.
Was the 79AU hack a rug pull?
The record does not show who did it. The pulls were signed by the project's own hot wallet key, and the same key later carried the team's message to the thief, so the key was in more than one set of hands. Whether that was a stolen key or an inside job is not something the chain can settle.
Does burned liquidity make a token safe?
No. Burning the liquidity receipts stops anyone from withdrawing the pool. It does not stop a token that has a built-in way to move coins out of the pool, which is what happened to 79AU.
Has the 79AU thief returned the money?
Not yet. The team offered a 10% bounty on 8 October. A few hours later the thief replied on-chain, asking to keep 25% and for legal action to be dropped. By midday on 8 October nothing had been returned.
Where is the stolen money now?
Most of it is BNB, held in three wallets on BNB Chain. A small part went into a cross-chain swap service and has probably left BNB Chain.
Can the 79AU pool be drained again?
Yes. Two wallets hold the permission the hot wallet lost: the deployer, which never lost it, and a new wallet the team gave it to the day after the drain. A dry run from either one showed it could still pull almost every coin left in the pool.
Balances, pool reserves and permissions were read at 12:53 UTC on 8 October. The wallets can move at any time.
Dollar figures for the drain are the USDT that left the pool inside the sellers' own transactions. BNB balances are valued at $761, the PancakeSwap price at the same time.
The pull switch is identified by what it does on the chain. We found no published source code for the token, so its name and any other conditions in it are not known.
The dry run of the switch from the deployer wallet was a read-only call against the current state of BNB Chain. It moved nothing and shows only that the call would be allowed.
The KuCoin hot wallet is identified by Bitquery's address labels. A payment from an exchange shows where money came from. It does not show who owns the receiving wallet.
The 475 BNB sent into the cross-chain swap service were not matched to payouts on other chains.
The new wallet's pull right was read from the role grants the team's multisig executed on 8 October and from a live role check. Calling it a replacement for the hot wallet is our reading of its timing and funding.
This article is provided for informational and educational purposes only and reflects analysis of publicly available on-chain data as of the dates indicated. It does not constitute legal, financial, compliance, or investment advice, and nothing in it is a recommendation to buy, sell, or hold any token or asset.
The findings describe transfers, swaps, pool balances and permission changes observed on BNB Chain between 30 May and 8 October 2026. Attributions come from Bitquery's address labels and from on-chain behaviour; they may be incomplete or incorrect and may be revised as more data becomes available.
References to 79thVault, 79AU, PancakeSwap, KuCoin or any other named company or protocol describe what the record shows about addresses and transactions linked to them. They are not statements about any party's security practices, compliance, solvency or conduct, and nothing here asserts that any party acted unlawfully or negligently. The wallets that received the drained funds are described by their behaviour and attributed to nobody.
Nothing herein should be relied upon as a definitive determination of fact. Readers should conduct their own independent verification before taking any action. The authors and publisher accept no liability for any loss or damage arising from reliance on this material. All trademarks and company names are the property of their respective owners.
Reported by Gaurav Agarwal for Bitquery Research, with AI tools; every figure was checked against the raw data.
Ask these questions in plain English
Every transfer, pool balance and permission change in this story comes from Bitquery's BNB Chain data. The Bitquery MCP server puts that data behind an AI assistant, so you can ask who can move a token, where a wallet's money went, or what labels an address carries, without writing the query yourself. The full history of BNB Chain transfers is also sold as files on theBitquery Data Store.