At the beginning of October 2026, the hot wallet 79thVault operated by the 79AU project was suddenly pulled into an on-chain security incident: the operational wallet's permissions were breached, and funds were quickly transferred out of the hot wallet. At the time of the incident, publicly available information regarding the total amount stolen and the specific technical causes remained in a state of "to be disclosed." Shortly after the attack, on-chain monitoring agencies began closely tracking relevant address trajectories. According to PeckShield's disclosure, the attacker not only deposited 30 BNB into the centralized exchange KuCoin but also made an unusual "reverse action" on October 9—returning 15,000 BNB to a wallet address specified by the 79AU team, equivalent to approximately 11 million dollars at that time. This significantly large return, amidst the still unclear overall loss situation, appeared both as a negotiating chip thrown by the attacker and as a renewed questioning of the project's security boundaries: the partial return of funds raised the question of whether it meant a temporary bleeding stop or the formal opening of a long-term game regarding responsibility, negotiation, and subsequent risk control.
Hot Wallet Breached: Funds Stolen from 79thVault
Before the attacker returned 15,000 BNB, the starting point of the story was actually simple yet fatal: the hot wallet 79thVault used for daily operations by 79AU encountered an attack at the beginning of October 2026, and it was confirmed that funds were unusually transferred out of the wallet. As one of the most critical inflow and outflow hubs for project operations, this address, which should have been responsible for distributing rewards, paying operational costs, and interfacing with contracts, quickly transformed from a "flow hub" into a "loss carrier." However, the specific total scale of the stolen funds has yet to be publicly confirmed from multiple sources, casting a layer of uncertainty over the risk assessment of the entire incident.
As of October 9, the technical details surrounding this attack remain blank: there are no publicly available contract call path descriptions, nor any authoritative disclosures regarding reasons such as permission management or key exposure. What is clear is that this was an on-chain security incident occurring on the project's operational hot wallet, and hot wallets are naturally positioned at the front line of high-frequency signing, online custody, and intensive automated script operations. Once a loophole appears in the defense line, the attacker has the opportunity to directly access the project's operational funds. The damage to 79thVault turned this structural risk from an abstract lesson into a concrete case, forcing all projects relying on hot wallet operations to reconsider: while pursuing efficiency and convenience, whether operational-level key management, permission isolation, and fund stratification can truly withstand the test of a sudden attack.
On-chain Tracking: PeckShield Locks onto Attacker's Movements
After the attack was exposed, the first thing captured on-chain was not the project's statement but rather the movements monitored by third-party agencies. PeckShield quickly identified the funding paths associated with 79thVault following the incident, marking and alerting assets transferred from the attacked hot wallet one by one. Several reports later cited its data, transforming the attacker's on-chain trajectory from technical details into risk signals understandable by the public. Monitoring shows that the attacker did not merely horizontally disperse funds on-chain; one path clearly fell into the centralized exchange scenario—at least 30 BNB were deposited into a KuCoin address. This seemingly small amount became a key action in the attempt to "cross" the visible boundaries of on-chain funds.
Once the centralized exchange appeared in the funding path, the narrative of tracking changed immediately. The on-chain world can still see how assets transferred from 79thVault entered the exchange deposit addresses, but whether they were quickly exchanged, mixed, or recognized and frozen in compliance processes afterward is no longer entirely under the control of on-chain monitoring tools. As of October 9, publicly available information has not disclosed whether KuCoin has intervened to freeze or cooperate with investigations, and PeckShield's role remains more at the level of "pointing out paths" and "providing evidence." This turns the subsequent financial battle from merely an on-chain address game to a contest of information and response speed among the project parties, tracking agencies, and centralized trading platforms.
15000 BNB Return: A White Hat Negotiation Game
Just after the attacker's funding path stretched from on-chain to KuCoin, another reversal action occurred on-chain. On October 9, 2026, according to PeckShield monitoring, the attacker returned 15,000 BNB in a one-time transfer from their controlled address to a wallet address designated by the 79AU project team, amounting to approximately 11 million dollars at that time. This return was not a scattered repayment, but a concentrated large transfer, marking a hard reversal of the originally unidirectional "extraction" attack path, leaving behind a clear and traceable return trajectory on-chain.
It was this return of 15,000 BNB that was quickly packaged by market opinion into a "white hat negotiation" story: some are willing to believe that both sides reached some agreement off-chain, with the attacker returning part of the assets under certain conditions. However, according to publicly available reports, there is currently no multi-source confirmation to prove the existence of a formal white hat negotiation agreement, and the specific amount and disposal arrangements for the remaining unreturned funds have not been publicly disclosed yet. Thus, in this game, the project party alleviated the most direct financial pressure with the return but still faced an opaque loss gap, while the attacker maintained potential influence over the event's pace by retaining undisclosed portions of chips, making the statement "15,000 BNB has already been returned" feel more like a mid-game interlude rather than a final answer to the security incident.
Undisclosed Loss Scale and Technical Cause Risks
From the multi-source confirmed fragments on-chain, we only know that 79thVault encountered malicious operations in early October, with part of the funds stolen, and subsequently, 15,000 BNB flowed back to the project party's designated address. However, the total scale of the stolen funds and the complete balance changes of the hot wallet before and after the attack still lack consistently publicly available data, with even the specific attack dates differing slightly between reports. This means that the outside world can only build narratives around a few exposed transaction records but cannot outline a full asset panorama with clear profit and loss boundaries; how badly the project was "hurt" remains an unsolved equation at the level of public information.
What's more challenging is that the technical causes are also in a state of verification. Explanations surrounding weak contract permission functions and operational account permission management have begun circulating in the community, but as of October 9, these claims lack authoritative detailed disclosures, and there are no unified technical review documents available to address them specifically. For participants attempting to assess risks, one side presents the unclear amounts and handling plans of unreturned remaining funds, while the other side has not publicly clarified the attack paths and the aspects where permissions were misused. The result is an inability to gauge whether such risks have been blocked and difficult to make reasoned judgments about the team's security capabilities, causing community sentiment to oscillate between "seeing some return" and "not seeing the overall damage," while the shadow of the security incident is passively extended during the information gap period.
On-chain Security and Post-Incident Games from This Event
79thVault encountered an attack at the beginning of October, with operational hot wallet funds maliciously transferred out. Then the attacker split and transferred on-chain while also depositing 30 BNB into KuCoin, leading to the return of 15,000 BNB to the project's designated address on October 9. This path from theft to partial return itself serves as a sample of on-chain security and post-incident negotiations: as an operational hub, once the permissions of a hot wallet are breached, losses occur not only at the moment of the attack but will also continue to reflect throughout the lengthy processes of fund tracking and negotiation; third-party monitoring agencies like PeckShield promptly capture abnormal transfers and replay paths, which have become critical signals for market judgment of risk conditions; while centralized trading platforms like KuCoin being named in the funding path makes "on-chain evidence + exchange nodes" a potential scene for accountability and negotiations. Moving forward, it will be crucial to continue observing the project party's formal explanations of loss scale and technical causes, the on-chain state of remaining funds aside from the returns, and whether a multi-source confirmed, clearly defined white hat collaboration framework emerges. Because whether these publicly available details and subsequent on-chain actions can fill in the currently missing security narrative closure will directly determine whether this event is categorized in participants' memories as a well-digested lesson or as a long-standing unresolved risk.
Join our community to discuss and grow stronger together!
AiCoin Exclusive Hyperliquid Benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin Exclusive Aster Benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram Community: https://t.me/AiCoinWhaleData
On-chain Community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin On-chain Twitter: https://x.com/aicoinwhaledata
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。



