Research · DXSALE◅ Read in ES

Anatomy of the DxSale Locker Exploit: Ownership Capture, a Self-Call Drain, and a Two-Chain Laundering Trail

FORENSIC REPORT2026-07-12Standard: OCS-FIS-V1findings sha256 · cf131e7e…b45cec
Contents

On May 27, 2026, an attacker address began draining a DxSale liquidity locker on BNB Smart Chain about an hour and forty minutes after being funded — the opening move of a batch drain campaign that ran for multiple days — then distributed proceeds across two chains — one leg blunt and KYC-exposed, the other routed through a bridge, DEX swaps, and a mixer. This is the full on-chain reconstruction, every claim backed by sealed, reproducible evidence.

How to read this report. Each finding carries an explicit confidence level under my forensic standard (OCS-FIS-V1):

  • Confidence: High (evidence) — directly observable on-chain and sealed under chain of custody from at least two independent sources.
  • Confidence: Medium (hypothesis) — a reasoned interpretation the sealed evidence supports but does not prove. Stated as a hypothesis, never as fact.

Every transaction hash, address, and block is reproducible by any third party against the public chains. I name on-chain entity labels surfaced by block explorers (e.g. “DxSale Exploiter 1”, “Binance 51”) as attributed observations — not as proven real-world identities. No natural person is named or attributed in this report.


Updated 2026-07-15 — correction log. This report was materially corrected and extended after new evidence was sealed under custody. What changed: (1) the ownership capture (F-01) was undercounted — at least six lockers were captured, not three, over a ~9-minute window; (2) the funder’s exchange attribution (F-02) gained a sealed second source (Arkham Intelligence labels the funder Bybit: Hot Wallet); (3) the drain (F-04) is now documented as a sealed batch campaign — at least 19 transactions, 3,576 LP transfers, 17 distinct pools; (4) the distributor outflow set (F-05) was proven complete via consensus-enforced account nonces — floor language upgraded to exact totals; (5) a new finding (F-11) records that of the captured lockers only the Legacy locker has a sealed drain. Full transaction annexes with explorer links were added to F-01, F-04, F-05, F-07, and F-08, and the findings-file hash pin in this page’s front matter was updated accordingly.

Updated 2026-07-19 — editorial revision. The prose of this report was revised from the corporate plural to the first-person singular: OnChainSurfer is one independent forensic investigator and signs accordingly. A one-line summary was added to the front matter for listing cards and meta description. No finding, figure, confidence level, or sealed artifact changed; the findings-file hash pin is unchanged.

Executive summary

# Finding Confidence
F-01 At least six locker contracts had ownership transferred to a single address in a ~9-minute window High · evidence
F-02 The attacker address received 104.1473 BNB from a Bybit-labeled wallet ~1h40m before the drain High · evidence
F-03 A self-call transaction moved liquidity-locker LP tokens to the attacker address High · evidence
F-04 The drain abused privileged locker functions unlocked by the ownership capture Medium · hypothesis
F-05 The proceeds fanned out through two distributors to exactly 30 receiving wallets (2,965.28 BNB) — outbound set proven complete by account nonce High · evidence
F-06 Five sampled receiving wallets all swept to a single “Binance 51” hot wallet High · evidence
F-07 24 BSC transactions bridged value to three distinct Solana destinations via Relay.link High · evidence
F-08 On Solana the funds were swapped to USDT and 1,107.45 SOL was deposited into a “Privacy Cash” mixer High · evidence
F-09 The attacker address operated a large-scale EIP-7702 delegation apparatus High · evidence
F-10 The two chains show two different opsec postures — over commingled, not DxSale-specific, funds Medium · hypothesis
F-11 Of the at-least-six captured lockers, only the Legacy locker has a sealed drain — the other five show no observed drain to the attacker Medium · hypothesis

One caveat governs the entire laundering half of this report, and I put it up front: the attacker address is a serial operator, and the funds it moved are commingled proceeds of its broader activity. My sealed evidence does not establish that the specific BNB and SOL laundered here came from the DxSale locker drain. What ties the laundering to the DxSale exploit is the shared attacker address, not a sealed value-trace from the drained liquidity. I claim no DxSale-specific dollar figure for the laundered funds.


1. Ownership capture High · evidence

On 2026-05-26, within a ~9-minute window spanning blocks 100449023–100450184 (01:08:21Z to 01:17:04Z), deployer address 0x47BAcf935066b802EAA0067eC14AB035B24eB78b sent at least six successful BSC transactions, each invoking transferOwnership (selector 0xf2fde38b, value 0 BNB) against a different locker contract:

In all six, the newOwner argument was 0xC4574DDEF299e7E563971e200433e592EeaaFA69 — the address block explorers label DxSale Exploiter 1. Each transaction succeeded and emitted an OwnershipTransferred event from the target locker itself. Control of every listed locker moved to that single address in one batch. Six is a floor, not an exhaustive count — the set is sampled from the deployer’s transaction history.

Correction (2026-07-15): an earlier version of this report stated three transfers over a window ending at block 100449822. Both figures were undercounts; three additional captures were sealed and the window extends to block 100450184.

Transaction annex (F-01):

What I do not claim: on-chain data alone cannot distinguish a malicious insider from a compromised deployer key, and a benign internal migration is logically possible — but it is weakened by the subsequent drain of the Legacy locker and the absence of any official DxSale migration announcement.


2. Pre-attack funding High · evidence

In transaction 0xffc7b601d90f6bc5584a9880693eb41f41ad62619e863e97b5d72477f5e4b72a (block 100798786, 2026-05-27T20:57:54Z, success), address 0x318d2aAe4C99c2e74F7B5949fa1C34DF837789B8 sent exactly 104.1473 BNB to the attacker address as a plain transfer (call data 0x, no method). The sealed BscScan transaction page shows the sender tagged Bybit 17 and the receiver tagged DxSale Exploiter 1 (the raw RPC capture, sealed alongside it, carries no entity labels).

This inbound funding precedes the drain by 1h 39m 51s (relative to the drain’s separately sealed timestamp in F-03).

Honest limits:

  • The exchange attribution rests on two independent third-party labelers, both sealed: the BscScan Bybit 17 tag and the sender’s Arkham Intelligence entity page, which explicitly labels it Bybit: Hot Wallet (alongside Bybit Proof of Reserves and Centralized Exchange) and shows the same 104.147 BNB outflow to the attacker on 2026-05-27. The “hot wallet” characterization is stated by Arkham’s label — no longer my inference. Neither labeler’s process is audited first-hand by me; the transfer facts (amount, addresses, block, success) are high-confidence independently of the labels.
  • A plain transfer from an exchange-labeled wallet is consistent with an ordinary customer withdrawal. It does not, by itself, establish that the exchange directed funds toward the drain, nor prove intent.

3. The drain, as observed on-chain High · evidence

At block 100812090 (2026-05-27T22:37:45Z), transaction 0xb107f19af1a8ff90d19cbb40d935f8be5d79f5fb9b497824e4ed28b9e7555fe9 executed with status success as a self-callfrom and to are both the attacker address 0xC4574DDEF299e7E563971e200433e592EeaaFA69. It carried 0 BNB and invoked custom, unverified selector 0x11b432b4.

I re-derived the effect first-hand from the sealed getTransactionReceipt (public RPC), not just from the explorer’s decode. The receipt carries 10 raw event logs:

The transaction is displayed with an EIP-7702 Delegated Address 0x74Ad1Ef17Fbb3e494c31c72F7ec730A27FEf0310.

Scope note: the “5” is the Transfer-event count, not the total log count (10). This finding records observable facts only. Whether any control was bypassed, and by what mechanism, is out of scope here — see F-04.


4. Drain mechanism Medium · hypothesis

What is sealed fact — the batch campaign. The drain was not a single transaction. At least 19 sealed transactions — each a self-call (from and to both the attacker) invoking the same custom selector 0x11b432b4 with 0 BNB — moved Cake-LP pool tokens from the Legacy locker to the attacker across blocks 100812090 → 101536778, in at least 3,576 Transfer events covering at least 17 distinct pool-token contracts (all re-derived first-hand from each sealed getTransactionReceipt). These figures are floors over the sealed sample: read-only enumeration surfaced a materially larger campaign across May 27–31, which I assert only as a read-only observation, not a sealed count.

Transaction annex (F-04):

# Block Batch transaction (self-call, 0x11b432b4) LP Transfer events → attacker Distinct pools
1 100812090 0xb107f19af1a8ff90d19cbb40d935f8be5d79f5fb9b497824e4ed28b9e7555fe9 5 1
2 100813269 0xdbd71d000ee58726ef3e06e4caa9ee046335613c043676cb83a99471bfdf7c79 500 1
3 100814490 0x801147fe2c853e64db95d2b5409811190b6f33e6041bd8f7360af1aac3b736f9 221 1
4 101263917 0x77617c7b485dc461a49b2ed177e6cd43b3feb107285246b004da166432e83369 169 1
5 101264226 0x886c033d84e593d6779a99f0f94f79ea8fde71f47981957a2feb0df13432cc53 153 1
6 101325015 0x43dbcd55ab7460cae920246db611a3252d227fd57f7149765100b8e1c08efd96 294 1
7 101328509 0x3865076483ec8b34089ffd4f460aa54414e3106dceb0a9338e569bfffb13cae2 8 1
8 101328838 0xfb6258ba71b88f624e5515aeb1fba0508926dcfeceee8483bd611776dde6d87d 8 1
9 101329516 0x6681a15f96b491d045a4f511e916b7d0804665b7b7211a24bed35a60ecd24178 8 1
10 101334985 0x27f932c0d7315e8bb8745185b796995a87e3017d731d8719ea6952d0c208e667 5 1
11 101335276 0x759526fd463e32abbbf4b1c46513065ece0738f49101830b81be97cad029d4ac 5 1
12 101336023 0x164c96e2b4b083a57a8e0f883fcdc4609773c0e4166a3843d05bb92b0bf624c2 5 1
13 101336963 0x9ac1617676258e0b1eb19ff0c9b1703a2f9d2c7e683263970ae803a0e3501c97 5 1
14 101495374 0x5e050d14c0e04da7162584cf3084424bd682b7fb6702ad6725e06652ad5db45f 500 1
15 101529590 0x9297d5b3607e73c9ff6dbc4083f6f2884dcfc6f5d4126dc3db2c8c36bc96976a 377 1
16 101533646 0x0b9cde686748d8cbe9e655556a4635d5c7c1ff12f70f9fd9528a34b8f1000223 412 1
17 101536421 0x1b46db24bd393ee87904e6d4c58a6596649d29a161d08f81b28aee293a7102ff 500 1
18 101536747 0x71675fb5b6344eb4833be1a23c6068b3281c6e6dec4d30bfb47f1767d8a6ea77 399 1
19 101536778 0x4b8813180c1a5e188d97e1c02ee4dc50cf0f7986be291193a6f9f9aa7a821d19 2 1

What remains hypothesis — the mechanism. The proposed reading: the drain abused privileged locker functions that became reachable after the ownership capture in F-01 (an OSINT attribution consistent with public write-ups). The sealed facts support this reading but do not prove it.

The exact bypass path remains open because:

  • Selector 0x11b432b4 is custom and unverified — I have not decompiled or ABI-resolved the called code, so I cannot confirm it is an owner-only locker withdrawal rather than a generic multicall/router/aggregation path.
  • The auxiliary contract at the EIP-7702 delegate 0x74Ad1Ef17Fbb3e494c31c72F7ec730A27FEf0310 has unread bytecode — the delegation may implement the transfer logic itself, making the locker’s own function possibly not the vector.
  • Ownership capture as the enabling precondition is inferred and timing-correlated, not causally proven within this transaction.

Resolving the mechanism requires deconstructing the locker and auxiliary contracts — deferred.


5. Distribution across BSC High · evidence

Between BSC blocks 100869981 and 100977493 (every transaction sealed individually as a getTransactionByHash JSON):

  • Funding the distributors: the attacker address sent 1,542.285 BNB to distributor DIST-01 0xb71c1C2A0cD7A88f1317f9A996e4d121E7db5E92 (4 tx) and 1,438.285 BNB to distributor DIST-02 0x4c5ee9703653C8e7725C65593bff372655e0453C (4 tx).
  • Distribution: 22 sealed DIST-01 outflows to 22 distinct wallets sum to 1,527.28 BNB; 8 sealed DIST-02 outflows to 8 distinct wallets sum to 1,438 BNB — in aggregate 2,965.28 BNB to exactly 30 distinct receiving wallets.
  • Early returns: before distributing anything, DIST-01’s first three transactions (nonces 0–2, blocks 100873674–100913254) sent 15.001 BNB back to the attacker — a pattern consistent with path-test transfers, though intent is not asserted.

The outbound set is complete — proven by account nonce. Both distributors are EOAs (their sealed eth_getProof responses report the code hash of empty code). An account’s nonce is the consensus-enforced exact count of transactions it has ever sent, and it reads 25 for DIST-01 and 8 for DIST-02 — attested by two independent providers — exactly matching the sealed transaction sets, which occupy the contiguous nonce ranges 0–24 and 0–7 with no gaps. Every nonce slot these addresses ever consumed maps to a sealed plain transfer (none is an EIP-7702 authorization, which would also consume a slot). The 30 receiving wallets plus the attacker are therefore the only addresses that have ever received value from these distributors, as of block 110205789. Sealed end-balances (0.00397732929 and 0.2849957925 BNB) corroborate near-empty distributors. What this does not cover: inflow completeness is not claimed (dust-level unsealed inflows provably exist and are immaterial), and the exchange attribution of the 30 wallets is addressed separately (F-06) — though Arkham Intelligence independently labels the distributors’ outflow recipients Binance Deposit and reports Exchange Usage of 100% Binance for both distributors ($935.59K DIST-01 / $910K DIST-02, sealed pages), as third-party corroboration.

Transaction annex (F-05):

Funding (attacker → distributors, 8 tx):

DIST-01 early returns to attacker (nonces 0–2, 3 tx):

DIST-01 distribution outflows (nonces 3–24, 22 tx):

Nonce Block Transaction Recipient BNB
3 100914844 0x58249d6fffd62fb835280219ed5eb6633209347e8df0cffb4da10ae136972d66 0xF5F237a90b0D6F2833673b267D9B17425fd93a1C 50
4 100915591 0x6d64052e257d1f35805787d4c252b4b6f0e4e1b72fe9a4bd54e371690c4731a9 0xE06AcCf50D4F34a5bcA2750D24f943b4F6f7e53B 150
5 100916421 0x36150e5d28114008f7791d1fa0c6221bd8cdc08a2172e33a0728a635d946d129 0x18Dfd8278de50e4A6f3BF1606bA77371451D8602 150
6 100922175 0x6f4607a447bc17f764615b4904a449d8aaac5df72aeff3dd449ee9dd7f734c48 0x519eD00dd7Be16040Cfe14dDd7D43Db4D77A4A61 150
7 100924003 0xd576ab733e031f7fe8072fdebd723b20c671a91d3f8f8938ccb7547f5242ae3a 0x323A1155aA67Aa92CE9306F7c73f8C223568F24d 150
8 100928690 0xf65b8bc90721544e815a98dd4102947f87d197e29ad307a15275c8173c4949d6 0xAc69F86C4a43D93f1b7d0B57aEfE6a1b7B9a6773 150
9 100944764 0xafedfb246d0cae90bec6e40e6342912e295d724bca041389892ed3fa3cbc9673 0xb39274583Ba7De8b50334A1BA12e7d6a0046C580 20
10 100945511 0xf8c21e04cefab8123be1ff0fcf5237c351e346297863065757ce97df84faa286 0xC21C0BC9C911B86dfb659718762806ec409A3dc4 50
11 100946098 0xd5e86558e7ca457f9d6e5f624ab7fad933c27ee120a1caf089616a7076f58384 0x74aB3F7593881d051F1e6993Ae893F58c9FCb103 50
12 100946691 0xcf5b9bdd54d08ae01c33f64b6a99c30d92678706daba2470c4341a8a5b57880e 0x67741069FD99B56B5E92C356FE876Efb23658069 50
13 100949592 0x9364ce2d7be2792645f555c6da8ca0f4e93d2b597e808c690ec39a9053f1764f 0x045F605740Cb1E9954DBB9E174596a59e926a183 50
14 100951600 0x41cae4b017d9a901288b9a0daf07134f10d6195e1b3f26ca9f8598007c8f78e4 0x944D82abc234884f822Ec9E695D4Da91e8e1327A 50
15 100953772 0x935c72a03b44db6e5c59272cd3f253ac572f096e7c99224fdf28a8543b4c18b4 0xc87eC86a089C9A15Ce6191444ADBB6f04fCE88D8 50
16 100954298 0x9390444673ed31d642392e90c95e93dbc33d45eba73cd46af2c7418fda91c058 0x78Fc689Ccc109be4D8663e353700E1f7e9bD5A6D 50
17 100954986 0x2e57c43bce4452731474c8d7b89b0e59af531dab31af0faa1e4e1ae363b7b0e8 0x582A8eF74c49F5a7435aDD214Cf144f4af7A2aED 50
18 100955661 0x81e70353b73784bdca4e04f8c16414c0792f5875fcdf158978755cb99a1de1c5 0x8eAFD73a26785948d05E89684273304B29a3c0a0 50
19 100956440 0x5326a823227d18543ddccdb691aad60a2152212087e7b8f42e8f03ea3506d4a8 0x6c10C8Af2ec570F0adb2E342116d6D5De485dB89 50
20 100956608 0xd8244f373e7249951f99b57ced1ddaa938669dab95b601846fbcab3f93efc41c 0xbC6006638388C8837515fD3d173e44C597564C07 50
21 100957005 0x7f7fa9e376cea8e9a6cb4a832cdf4b1c539990d96af1e21be2983e3b1c0db3f4 0x8243e20CecafA6D3dDDcF15D5Ac9726dD28F7afD 50
22 100957381 0x030576c13fd16a8b3e64ad4f2777b29241affde6019f85ff3cfae9499388dbba 0x391c5756A9b1924f6C206cC029315CF154B95Eca 50
23 100957802 0xaf55d4ef2bccda1bd07a44ddfa2dc213d2373cc048df4529c05ae1359689dd2e 0xDd57F5eA9C7CA2C16e243627cA9CAd9F7c2CB3CB 50
24 100977493 0xf876cfc63e89e5b938c62d31c83cd5c15bfa0be270cb01369f4b1519566ea579 0xA2297C94124afB7cd5f097df5C6b9c29D8b54C3c 7.28

DIST-02 distribution outflows (nonces 0–7, 8 tx):


6. Consolidation to a single exchange wallet High · evidence

I sampled 5 of the 30 receiving wallets and sealed their onward hops. All five forwarded the BNB they received to the same address 0x8894E0a0c962CB723c1976a4421c95949bE2D4E3, which the sealed explorer pages label Binance 51:

Every hop is sealed with two independent sources — the public-RPC getTransactionByHash JSON and the explorer transaction-page screenshot. Sweep cadence is fast and uniform: between each wallet’s deposit and its outbound hop, 210 to 1,506 blocks (roughly 95 seconds to ~11 minutes). Worked example, fully from 0xAc69F86C…’s own sealed page: deposit at block 100928690 (13:13:41 UTC), hop at block 100929535 (13:20:02 UTC) — 845 blocks in 381 seconds (~0.45 s/block), consistent with automated sweeping. At least one sampled wallet shows FUNDED BY: Binance: Deposit Funder and repeat deposit-and-sweep cycles before and after the exploit window.

What I do not claim: I assert on-chain consolidation for the 5 sampled wallets only. The statement “all 30 wallets consolidate to Binance” is deliberately not made as an on-chain claim — the remaining 25 wallets’ hops were not sealed. Independently, Arkham labels the distributors’ outflow recipients Binance Deposit and reports both distributors’ Exchange Usage as 100% Binance (sealed pages) — third-party corroboration extending the Binance-destination attribution to the full set, though only the 5-wallet sample carries sealed on-chain hop evidence. Binance 51 is an explorer label, not an on-chain-proven identity.


24 successful BSC transactions moved value from three relay wallets into the Relay.link bridge. Each crossing is attested end-to-end by three sealed artifacts: (a) the BSC origin transaction, (b) the bridge operator’s own public status record mapping that exact origin hash to a Solana fill signature + destination + USD valuation, and (c) the Solana fill transaction itself, independently sealed.

Relay wallet Crossings Solana destination Operator-valued On-chain arrivals
0xe746afE35B51f6fF3266c247c0Ed6D04DB9c80Bb (RELAY-01) 15 A6uMgTcFeFeoQtooZKanWoWP9uP1EgJRzVvBsFQSYnfZ $883,032.46 10,725.368648115 SOL
0xCAaBBd3dffD30bDa2F7DC2a9d6Fb2D0b4476D86E (RELAY-02) 6 2dQg9JnDpH6tiQdqQEeXggPdkimLoNurgxKP7WjAmMYK $83,676.62 1,020.654515582 SOL
0x656d2BBc4b54c3d4999A8F7f8d18775050225aF3 (RELAY-03) 3 8E6SHPRJaAUGTsFdLRkCD9CoMu1n79ocAiw9KG9bpfFg $384,188.84 4,631.921448802 SOL

The three destination accounts are pairwise distinct — the bridged funds did not converge on a single Solana account. On the BSC side, RELAY-02’s inputs totaled 8,809.826078 BUSD + 9,885.496711 USDT + 90.840809 WBNB (sealed receipts).

Transaction annex (F-07) — each crossing with its three sealed artifacts:

# Relay wallet (a) BSC origin tx (b) Operator record (c) Solana fill USD (operator)
1 RELAY-03 0x33833775911ede9e0dc73b0bd6a2a3c3133207215e63391b00f366987f87ea2c record 4i977MTKsdvQeQPYgtQ7ZLgajNghXEefrmsire5TjC4MK8oay2VVk8riHj9u3C6XzWf6o8MPUa45Yx29br5nn9B9 $203,504.20
2 RELAY-03 0xa4d96865c1a16fdc9319b8c4fbd83a420e0a7159f5028a588401f1dd42bd4555 record 2zeASRXa7rVo23qjNPsk2JR7g6VBoEEhdp55YsypMyGs4YMeug9ButM3eUXDcQwSSo9Ef2oesAPfLvmUjD6oBhyd $179,964.80
3 RELAY-03 0xf01c444d501e75eff823b810ec1c10add175e6225b36d3cd0f531418c3e4e7bc record 3u5J4cfSjSuG2eFtuUrdvXdUdtbMcq4FAsMHpjhkHc6GnqPc9b41Y3t68nTZLjq9sUSHkspywhuxSA5r84TB1Cdv $719.84
4 RELAY-02 0x03bb7658d15e2bad02f919b6f6d67efed37e0a9240c0c5c6a6ab537c183ab5d8 record 4mMQMFVvnA8SsiTdttVzYjzkDuAMTfAVdGR1TGcmjjagA8GpKi5GAhTaxPZrNQoUu6oM2iA8ZjEvY51JSuqK2fJH $17,869.76
5 RELAY-02 0x3b6c47fb279c3813a9e7ab89fe77eb8d672c12ba154a1aa8b4ff6214531cc6c0 record 5LTeqhBwHZE7HADnEkwHVGGwwVwEi4Ts1UsafhURxsSCj8bu1pq8o665QUdmQkdGVj6V2axLCchi3exbAjoW5YC4 $9,881.99
6 RELAY-02 0x3f5d0b5dfa230f552f40b8f41bcf53978a8f5b6f142d52e9ef136521b8b0e11e record 2M6BHy2GfApRDvAYFiVjfxfoMp3vm8fcnVTs7jkkknmC8XPihAAuuwzomtbsP73WaBf4SzbtpTpAfisUyfJpJHqt $17,869.76
7 RELAY-02 0x83519f00fb0ed19fb4bb1cca8e859bb93957b16394015e546e2cf24faa2ff107 record 5vyccqWax32cS3di6dQ4u5jEy6cwJKvvu9qitVtWLcynVtXG3mtobfytQrQ9ZoyDAtdWXwQKy3gXsiwJs3ACYSbZ $8,827.45
8 RELAY-02 0xccfca8da65b8ab179132b9feb9fc8ab0b2af44c8c11b2cecbc9d162fbbd8ca09 record 6766dZE8mFiCmYcQvJg2oHfYTVehLjhT6NywiUfQuzcd1bHz8rJwzpmPa8X1XREbC4MHTujsANV6ficmQaSjk16m $716.00
9 RELAY-02 0xdd5e4d27a5f2b51c30be8790b6f91839b5b9e5e2492ed395cd9e6120565a2b33 record e6xJ5K37561qc5vrWbcwBdd2gRgwsm3EDnugqPdTJznS7haDMEy8qSqd7pr3ohpWFX7yzeo39aTvECPSJCdNwnF $28,511.68
10 RELAY-01 0x0ca371842345cb3439a3040678698881b903cc847f835c2554c04330fc2706c7 record 317c1yzCSMr9GLG73TBR9iX3my8nFyPyzF9erd4D2Wnuyk66DSC4kALKWxssnhrGGqgXkeEX76zQg2Yh6vCSWtr9 $63,874.39
11 RELAY-01 0x0f5d60207a794edd0082ca365ebbc87a051c061a7af3bf034b3efec805237b89 record 64HpkL4sQcvkG44cjzTUkU9zgXC5q9mV7GrCz6AriEdNsguDx6u2Qm4HcfuFRAMSuXZhir7HMSRxp3oiNoEpQyaB $63,874.39
12 RELAY-01 0x180291944407170c6acef4a24409327038aaf5fa8d153f6bb1c8f8f7f1688971 record 4qnFigdrGfEoJKXgskbQjFN4r42N84sfN1grZJkX649tUA72GAs3cE4VeGiuvuSTrTRBLcmybSBtwpZ9GrGcknWT $63,953.00
13 RELAY-01 0x1f441c475e0723ac866e302e5322bbe64f095ebcaee54db58a5b7bd32e739b93 record 3U7G28TuZYRKkL9HZMmBz79PKeTPZDGJpFgEMm8oP8vt9rRMA2KaaCSHMuVvN4u6ZoJ9yo2HkoKR96PEdyFa5XwV $51,806.22
14 RELAY-01 0x316e9747d684bff886adf96a1ecb8618567dab6cd4b98332ea5bb37c59d080d1 record 4CCWXemgWKpR76t2SJYDqT6aGGTqqr8353Bn3DGYbMbHDkZpyFaW1jkJ8hTqnVHFAihYpruwZQq4apq4Dn26EvBS $63,883.24
15 RELAY-01 0x3e035e0efaba0c3bd3baad68ceb699788ddce35fed62dac92f6ffa488126ab97 record 2n5YiAp4oCAkbt4UzYNTrE1dmfnSjYG8gBGYmHLuXi2PpBX9ccnF1PQM6ajLrApYWwQHSXQDfKKPL4Hdx91JC3Bp $63,876.45
16 RELAY-01 0x49f36005735750488b3dfe943933fa27e5816714aaeaa945db44462ad8d9b250 record 2vEf1EwP3rGtJboKt1xjCmPWNur75onWjhNDcmHZ2GkqJfpSp657VdHAkz4hL28L9vM8hQrZ5xC5k8usdx2rHvMV $63,874.39
17 RELAY-01 0x4a31e7da61fd7bfc2077baf9bded5a75c63f2fb023249cd96563dd9d042523c1 record 3tu5SiX6Xe7FbuVwHUJN1tVtstL81XxeVTyJg5bugNq5q1SC1PHgNUYQLB1eQtcjmYGKzJw6UVyusbSdDyV5hSxA $63,846.01
18 RELAY-01 0x5f11249fe9505ad0a73fb5d2754dabd91463eb612e5dfcc932a2af82feb3cb87 record Qz39XNkJ9HPiJHSXRbK8WT5Lj5BETLVhcYgcbPXQjiNN3HwDnNS1kohA4uJmb3X1rZEGvMVaDVqymTFWptJ12Mh $63,876.45
19 RELAY-01 0xa4a8020cdea147e1cc935b327f9a338b5be6b63c083cf1d0486d9da6c5775f9e record 4ADUqCprHbCVmUTmcjdUgPxFKQQU5p4PBM1Uc6MEjyUfxXdG9kBGEawLiuA5bekyuoZFtJxV2L6KqrnEqWepdeuT $63,876.45
20 RELAY-01 0xb51f4e90f29d0b40e00f1ea552501322ea3602f2c6e0e1ce1cbb9d5f104bab5e record 32pphTTKVMM9drUvKsHmnhnPh9wLrxoajhQwXYr3FHYsN6PKjDqd4QLHsZ1XKu9bf1ToXmTDCrbEhPeVZLkra1UB $63,932.65
21 RELAY-01 0xcf4e9ecf08398d03de166ce18725bc810b0e4e2a30df51079a95d4d2057601e9 record 8qjd3mgjEzW8M15RrCYUqEYQ3DfJRaSCTWv5JPFuoQbWCaqVsuVWtVZTpah83X7gon9VvoAUutcWVXUAwiqb11R $63,883.24
22 RELAY-01 0xd642295f4251b6d406bf41047e75866fe9721697cd7700726c08ca6a08ab29ac record 38aS1ypE28EwcsJTusvU3M6aVshSWti9aAh3iN3uA1A2YFvDcBTYkYaz8mRPCQiKh21sLdQtMcr194ifvUrX16Gi $639.33
23 RELAY-01 0xed14776dece50c56894968453baabe06ae00bf1c018ea5c7408fbc1e8e492324 record 2yCmKaNnPMMJRaYk7m6uByrc2qupcqUErbvXUzSSs4LR2bmSNZyAMcVequzhkYPwVPgjAUP12vMzo8Ss8oxXhR1j $63,883.24
24 RELAY-01 0xf557b314c93f11bb899b04f6c006fef08d2e3f0a4face00b487bce9fd873ddbd record d66WMiFPGZERQhmNwmgQURpSZjZQQ7i6YZiKrfngWb2etGGjFJVzz5udJKGWWLqY432ATdr3ENrRZP91BvTGNLg $63,953.00

Honest limits: the operator’s status records are an independent second source but not chain consensus; this is mitigated by (c), each fill independently retrieved from a public Solana RPC. USD figures are the operator’s valuations at request time — cited as attributed, not my own pricing. Per my confidence standard, cross-chain linkage starts from a confidence ceiling I fixed in advance — before looking at the data — because no transaction hash is shared across a bridge; here the two independent sources meet on exact transaction identifiers, which lifts it to high.


8. Swaps and the mixer boundary High · evidence

Downstream on Solana (all quantities are balance deltas from sealed getTransaction JSONs; the Solana RPC does enumerate an account’s signatures, so per-transaction deltas are high-confidence, but set completeness rests on that enumeration — counts are floors):

  • Handoffs: 2dQg9J… forwarded 1,020.653 SOL to AgnEKmN1XHBduneu9bFu1bfp69GRVUuCyNpQjAHSJ6do (2 tx); 8E6SHPRJ… forwarded 4,631.92 SOL to 3vy9hoGMq382E48EEyGuEYTeP8Raya8WRVRgbrvCGxKY (2 tx). (Abbreviated forms of these two accounts are used below after this first full mention.)
  • DEX swaps to USDT (2026-06-02): A6uMgTcF… converted 5,300.156953 SOL → 400,000 USDT (its swap output equals its later single 400,000 USDT outflow — the balance closes); 3vy9hoGM… converted 2,324.482379 SOL → 173,500.88 USDT; AgnEKmN1… converted 513.30551 SOL → 38,305 USDT.
  • One path ends at a KYC-exposed exchange deposit: AgnEKmN1… sent 38,276 USDT to B3KoJ9TETMmEiAUPMXzeCJsTvHh2rn1mawj3NZMi1zrf (2026-06-08), an account whose sealed Solscan page shows the literal tags #Binance Exchange and #Deposit Address — the single KYC-exposed endpoint observed on the Solana side, and the thread that ties this leg back to a subpoena-serviceable exchange (≈$38K of an operator-valued ≈$1.35M bridged tranche; the majority path ends at the mixer and non-enumerated fan-out). Separately, the pool 4AV2Qzp3N4c9RfzyEbNZs2wqWfW4EwKnnxFAZCndvfGh — Solscan public name Privacy Cash Pool, owner Privacy Cash — was credited 1,107.4496944 SOL across 6 sealed deposits (183.5 SOL from AgnEKmN1…; 923.9496944 SOL from 3vy9hoGM…).

Transaction annex (F-08) — the 35 sealed Solana transactions behind this section:

# Slot UTC Signature
1 423875503 2026-06-02T19:45:33Z 23qqUUyJKarwi9kXff2Fdqzy9Kg3MNasvKNqMDU2b5TMy6hwvH7ukmCj9remAmk7GkAmP1KDK3Mr6NCwYERiuFac
2 423875793 2026-06-02T19:47:28Z 28nMUo2dq3rv6QnZvK9w8NYC8n5prubvdaMF7vEjB1492oFffxQ6SMs9KGt8dixUVJKTDWw94ZtsYUpoQhphDbuq
3 423876329 2026-06-02T19:51:02Z 2TQ8MKExNiEDfXBQ8uGXggwWJuRchKahFXXKejNSs4A7ZukFZQyRbxG2D1vuJU3GVdxeP4RLqfrB3rqdX9qB2x3B
4 423876451 2026-06-02T19:51:52Z 2WJLQif91G1xfPynzi9D9WPjTodENRfmayD5XqrmXZ8bkLMXjiVYWCrovbFA8ZjsyoR8qMAVsvhALN8JV5uJSBPg
5 423876622 2026-06-02T19:53:02Z 2cKmSGbk6ue5tTdVrd69CnYCUCXGSyKCzEDCh1FLC72gZF1qvyjm4en1H26JJ9P7bNeArtnX26ArwZsXQ93uZKGa
6 425078466 2026-06-08T08:53:51Z 2s95LAHfKkBZhXbjyxN5AdW7NNBFrCsH3gCK7H6i89856jEqRRR9ej766kUdGgDM1JLJsC1MaYcDEdHnXHCYxkxa
7 423882410 2026-06-02T20:31:36Z 2wDZhoUUbmojSCZtbXgfyDXRX8XqE2iJ48fAxi9qxA8nmAk1iXkrQDK2Zv66S73NozA4t3jpRiHb1QihSeApCzXp
8 423876600 2026-06-02T19:52:53Z 34LKXPSbgJyfY6YtactAF3GLNpC6Zt4oDWJdmUw8rbbWpVmxPjdTHoQpvjzFYSt1rQWDKXv79gRsPeCzMze6JGRb
9 423333431 2026-05-31T07:58:11Z 38jpBDf3G9WrWkPDTLujvWvidXJZp7qpwn7Nmd8Y7g3KJqsNibfL2G328ocpjPgqj362RKNkWCytbAK9GzTXPT1P
10 425829255 2026-06-11T19:43:01Z 3RhNMMFPdoqarMEauCfetujEknycZNA8idtJowgSrmEAr4fhWjDWpAhj1ZHWifk1wqK9aaekHFiESFWdQAjusu3v
11 424333045 2026-06-04T22:22:22Z 3UPw93BeZYGYjDxor5KFmg9V69nXDAawngMZ8nYrMoqWsVUAPxXGKoe3NkRxENucDjUwX8p7egRLUYQijJEbQ8gS
12 423875621 2026-06-02T19:46:20Z 3bCQ2wndBHub16ak6nBV5i89F2HTmdwwnYZVjqtyMpJkgNdLgzTeJjzkBfqvW65vQFYERZmQZTXGcELWhUXqrAW5
13 425492728 2026-06-10T06:38:41Z 3bxxMm2QBQawNze19dc3aEGyaXQdNUqn96FZQSGB9AQ1MoEoPaXsGw4ovcb5cJnLvShC9QXaivQ9qG6tGJEFv3tr
14 423423425 2026-05-31T17:53:11Z 3x24wUmdR9BDU7fRdTorzuUHgZEXeboeoMVsvr1DBrJLD821Mo6rUHsWK55bZn4eu3kmfUryQQhFevr4RDgoigkd
15 423882457 2026-06-02T20:31:55Z 4J2jhQqqrMb1baYqTvMta918fkHKuMn3Cqz8ChfcSr2teSRuyUiDJ1uB212nmsYmc1T9uE67jjexW2bczKcY34Bt
16 423882518 2026-06-02T20:32:20Z 4M7cmjFTmUte7fb29dbDwv116ndCZQBQeV9UCdwDfQnsa3ipTwpJLYA37dwgjXrPYE1LUgQfVo47d1EhJNRfK8Tt
17 425098318 2026-06-08T11:05:45Z 4PBkGKrCCF2h6eQ13RQrawGbM3XGFdyuBqDcnGiQRRFcmgcCrKfPdZnA9d8RZCcqrq4m3WhLCvtLJEv63fjdMUrA
18 423876308 2026-06-02T19:50:53Z 4d7wx4ViZHnZd7UvJTo6GMHBUsRyq28oyeQ5eqJkLEAV8o8GZtC4CyEFhqwfsBatx4xKkbemMURcMRMkApM4ojPB
19 423876515 2026-06-02T19:52:17Z 4isiKUvv9jyBfvSetq7FBMgdF5mmXSL9UEU5ZYLRHw5x46Tc8ppAwSjcosaJi2bpu5hdA66rquxgycNaAXGSrcoU
20 425100614 2026-06-08T11:21:01Z 4xhwhakJQanoEfxyi8JgY2JDy8VawchDNkAnyrWKFauN6TR7pYEqX2cjoRz4Rwz2FDo7oddGefnocexAgasLTgdg
21 423876242 2026-06-02T19:50:27Z 53odQp9h7mVT9Hm3pWHwWHvSqGVMEwQzydKrYh96iBgziJDimpu1WKsU2bF1d4BWiDMQoNZVswgoyEucn3q5cpxz
22 423882792 2026-06-02T20:34:09Z 58Y8CrdC6B5zbsCjNYnxurn4cGzWzEJoM166LS82KpsTUv5fHJVRz6sAd4U6p6f6NnR8t6qKdRmwLhPmrkVHpJVy
23 423882648 2026-06-02T20:33:11Z 5G423EjGDz8bqnyaBjKwPkXUyNWxS3Z6Vfvdevh6rirnTmRpWw7qWUGq6TpeE5yc9RAPPyuvpcPZR9wS71dA3udr
24 423423513 2026-05-31T17:53:46Z 5cz1dRokhyATWycXvMYn9MciLkTJF4omnfG2jkbL6mXMbihpTduCcAT7HtzsfsXuJ6GLr42k7kD73dXNifUXKb48
25 425736246 2026-06-11T09:28:34Z 5eFB88wU8A7odFVtM9FFwVy3PHsqx92u4a3dCrwMkL1AU67RT8M7CTwRpHNHzskpe59Pzaj6SjJfn4JpSSM3qiF
26 424468976 2026-06-05T13:25:52Z 5oCDRLMke4HAsnMPAqJV71xnzg8R7DbSTSAsWqjUXfVysSHq8pZA6E379Nqi3xi1eEz2Y56tjmrPbKMX7t1kqkPM
27 423961865 2026-06-03T05:18:42Z 8T5m6Vt88F8jMyWEAd1r7N56ZoKSLtXYrKuvEPgSA7jrFd4tSczDi3RxBsqwTHK7donYpJNTnN2J4Bft8znNCxH
28 423882545 2026-06-02T20:32:30Z RaxWbfRxb7z7Bm3TJUtgDEkgexR6Y9AsiKbTnSgK7jhVrczhaUgsHuguixNQCA36XP2BDnmAhrpYVK2VoHXGaMa
29 425492801 2026-06-10T06:39:09Z Zh4WYYPRAntPoSnvoNHaDNiHYWpH4iwuy3dgxwtU5PoXo23GHnAc7jqnssoMr9jNRC4cumXatFNFcQvm2Fg9Zg5
30 423876428 2026-06-02T19:51:43Z aR55T44WqE9FayRHnwDVFkYA5K2r8xaYeRrrNPB1M28UAv3NvE5gNUH8MoKaNFm7zNPmY3A8FP8yXR1Miaiwnfq
31 423876842 2026-06-02T19:54:31Z bTdzWLgrDZiLsMtSooBPMKcgXWG9Ld3ux2K5jkCsH956Jj8yr7KUpz2kgDzBF4VhC3JNxY5ajStRmmwogfJ11eU
32 423876572 2026-06-02T19:52:41Z cWsMFpUje7s9gU9QEsJu2hv53CimWYigY3V9Z3WAxwmPAPXEgTaVLEEAyNxfSXcK6KjQRAsyE18GxiPKEMYimb7
33 423876359 2026-06-02T19:51:14Z iutVibV4VScTa58dabccrPBaJTecth5N9ppG4akfNSQz5Mq4ysdSnUjzWYtbjCCvopuuDU7MteHV35b56czYh9E
34 423876655 2026-06-02T19:53:15Z w3V6hhaYMnw91mbdqPFniHdZeDGcFBKKgHpT3NFn3trprNqwfkonqbNXtS88yq87nPqZpXiSArVW15meMeBDtfZ
35 423333325 2026-05-31T07:57:29Z yXcwgyH9BcuHJZ99exPEjYB4KZzpiVq2MXRrbquZzS4BbqTMd94PqcnHfsdE9MGL5MWJtc91hT4WQKQEVRBJJg7

The honest stop: material outflows (400,000 USDT + 5,424.15 SOL from the RELAY-01 destination, and further outflows from 3vy9hoGM…) went to accounts I did not enumerate. The mixer is a hard visibility boundary — deposits are observable, withdrawals are unlinkable on-chain. I therefore claim no terminal attribution of the Solana leg and no statement about where the majority of its value ultimately landed.


9. An EIP-7702 apparatus High · evidence

The attacker address operated under EIP-7702 (transaction type 0x4) delegation on BSC. Sealed on-chain: transaction 0x6f83d59da4de3ac68c9cb941530daa2d75d33c6e43497ee0dc6a8efbc171e211 (block 101536427) delegates the attacker’s account authority to 0x44BCb3eAeE1C15f5D669A2B5e628d42c1ec19A18 on chainId 0x38. Sealed explorer pages display: over 10,000,000 EIP-7702 authorizations, authority nonce values up to 123,429 by 2026-05-31, and — on the delegate contract page — CONTRACT CREATOR: DxSale Exploiter 1, the attacker’s own label.

Contrast, sealed on-chain: the relay wallets RELAY-01 and RELAY-02 also executed type-0x4 transactions, but they delegate to 0x63c0c19a282a1B52b07dD5a65b58948A07DAE32B — a widely-deployed standard wallet delegate — not to the attacker’s custom delegate.

Scope: the scale figures (>10M authorizations, nonce 123,429) are explorer-computed aggregates on sealed screenshots, not re-derived by me; the delegate’s bytecode was not deconstructed. This is a seed for a dedicated investigation.


10. Two opsec postures — over commingled funds Medium · hypothesis

This is an interpretive frame over the evidence findings above; it asserts no new facts, no identity, and no intent. And it inherits the commingling caveat in full: the attacker address is a serial operator (123,448 transactions; the EIP-7702 apparatus of F-09), and the funds below are its commingled proceeds. The sealed evidence does not establish that they derive from the DxSale locker drain specifically. The link to DxSale is the shared address, not a value-trace.

With that stated, the two chains look very different:

  • BSC — minimal obfuscation. Attacker → 2 distributors → exactly 30 wallets (2,965.28 BNB, outbound-complete by nonce), with all 5 sampled wallets sweeping to a single Binance 51 hot wallet: a direct, KYC-exposed exit that concentrates any subpoena leverage on one exchange.
  • Solana — substantially more sophistication. The bridged tranche (operator-valued ~$1,350,897.92 across 24 crossings) split across three destinations, swapped into USDT, sent 1,107.45 SOL into a Privacy Cash mixer, and fanned out to non-enumerated accounts — with only 38,276 USDT reaching a Binance-tagged deposit account.

Possible readings, none asserted: (a) different operators or playbooks per chain; (b) one operator applying higher opsec to the cross-chain tranche; (c) the BSC exit relied on mule or compromised accounts where KYC exposure was acceptable. The asymmetry could also be an artifact of how deeply I enumerated each side. I frame it for the reader; I do not resolve it.


11. Captured, but not drained Medium · hypothesis

Of the at least six captured lockers (F-01), only the Legacy Liquidity Locker 0xEb3a9C56d963b971d320f889bE2fb8B59853e449 has a sealed on-chain drain to the attacker (F-03/F-04). For the other five, read-only checks (explorer transfer filters from each locker to the attacker) returned no drain transaction as of those checks.

This is a bounded, single-source negative observation — an absence of observed drain in read-only checks, not proof that those lockers were never drained or cannot be drained; exhaustive confirmation would require archive-node range scans outside this investigation’s read-only tooling. Under this bounded observation, five captured lockers remained under attacker ownership with no observed drain, leaving their locked liquidity exposed to the same ownership-capture vector exercised against the Legacy locker. Independent third-party reporting (rekt.news) characterized a comparable residual exposure as “$15.5M still at risk” — I cite that figure as external reporting only, not as a sealed quantity, and I do not independently value the exposed liquidity.


What this investigation does not claim

  • No DxSale-specific dollar figure for the laundered funds. The funds are commingled proceeds of a serial operator; the tie to DxSale is the shared address, not a sealed value-trace.
  • No real-world identity. Every “Binance”, “Bybit”, “DxSale Exploiter”, and “Privacy Cash” reference is a block-explorer entity label — an attributed observation, not a proven identity, and never a natural person.
  • No exhaustive counts on BSC — with one proven exception. Wallet and transaction counts on the EVM side are floors, except the distributor outflow set (F-05), which is proven complete by consensus-enforced account nonces. The exchange attribution of the 30 receiving wallets rests on the sealed 5-wallet sample plus third-party (Arkham) corroboration — not on sealed hops for all 30.
  • No terminal landing on Solana. The mixer and non-enumerated fan-out are hard boundaries.
  • No proven drain mechanism. F-04 is a hypothesis pending contract deconstruction.

Methodology and custody

Every cited transaction, address, and block is reproducible by any third party against the public BNB Smart Chain and Solana. All evidence is sealed under a write-once chain of custody: each artifact is content-hashed (SHA-256) at capture and the hashes are pinned; the finding set is validated by a mechanical export gate before publication. Confidence levels follow my forensic standard OCS-FIS-V1: affirmative language is used only for sealed, observable evidence, and interpretations are labeled as hypotheses. The pre-existing public trail for this case was treated as a lead only — every fact here was independently re-collected and re-sealed.

Reference addresses and transaction hashes appear inline above and resolve directly on public explorers.

← All investigations