$21 000 000 USD

NOVEMBER 2024

GLOBAL

DEXX

DESCRIPTION OF EVENTS

"DEXX is a multi-platform on-chain tool that lets users manage funds, perform multi-strategy trading, and track token market data. It’s designed to give on-chain users a faster, more convenient, and all-in-one trading experience."

 

"DEXX tackles the common issues found in Telegram bots and DEX platforms today, such as low security, complicated interfaces, and limited functionality. As a next-generation token trading tool, DEXX integrates these features and innovates on them, making it easier for beginners to seamlessly enter the on-chain world."

 

"With DEXX, it takes just three seconds to go from seeing market data to executing a trade. You can trade any token on chains like ETH, SOL, TRX, BAS, BSC, SUI, or TON anytime, anywhere.

 

User-Friendly Unlike other tools with complex interfaces, DEXX offers a simple and intuitive layout similar to traditional CEX platforms, making it easy for new users to navigate. Features like Mev protection, copy trading, liquidation, auto slippage, and quick mode switching ensure effortless trading — no need for complex setups, just one-click solutions.

 

Fast Trading Speed matters for on-chain traders. DEXX eliminates unnecessary steps, streamlining the entire trading process to be fast and smooth. With global node broadcasting and 3rd-party transaction acceleration services, trades can be completed in as soon as 3 seconds, even when mev protection is enabled.

 

Real-Time Data DEXX is equipped with global nodes to provide the most up-to-date trading info like liquidity, market cap, trading volume, holder count, and contract risk monitoring. This saves you time gathering data and helps you avoid honeypot scams. Additionally, DEXX sends real-time push for smart money moves, token fluctuations, your watchlist changes, and price notifications, keeping you informed at all times.

 

Fund Security Our development team has years of on-chain experience, employing multi-layer encryption and ensuring private keys never touch the servers. Combined with top-tier auditing and security teams, DEXX keeps your assets safe. Unlike many Telegram bots, DEXX uses its own trading system with 2FA authentication, reducing the risk of phishing or account bans, and keeping your funds secure."

 

"We’ve received 1100+ reports of stolen funds from the community. After removing duplicates, over 900 unique victims have been identified, with total losses estimated at $21 million (subject to price fluctuations)."

 

"Breakdown of Losses (so far): • > $1M: 1 victim • $500K–$1M: 2 victims • $100K–$500K: 33 victims • $10K–$100K: 292 victims • < $10K: 656 victims"

 

"DEXX has officially filed a case, and @SlowMist_Team has been actively assisting law enforcement in the subsequent investigation.

 

At the same time, DEXX is actively discussing a compensation plan. Regarding compensation, the platform hereby makes the following solemn statement: 1. If all assets are recovered, DEXX will immediately provide full compensation to ensure users’ interests are not affected. 2. If only a portion of the assets can be recovered, the platform will still fulfill its responsibility for compensation. The specific compensation plan will depend on the amount recovered.

 

DEXX is currently mobilizing all resources and efforts to recover the stolen assets and resolve the issue as quickly as possible. We sincerely appreciate our users’ understanding!"

 

"Mr./Ms. Hacker,"

 

"We have received strong support from security agencies, partners and exchanges to locate our stolen token. We are also monitoring your addresses to freeze the stolen funds in a timely manner. We ask that you resolve this incident within the next 24 hours. This will prevent us from taking any further action.

 

We ask that you communicate with us via email at team@dexx.ai or current evm address, and return the stolen funds. As a token of our appreciation, we will offer you a generous bug bounty and a generous token gift (We can negotiate the specific ratio).

 

Once you have returned the funds, we will immediately destroy all information we currently have about the hack. We will also stop all follow-up tracking and analysis. You will no longer be held responsible. However, if you do not comply, we will continue our investigation with the local police, security agencies and the exchanges to take enforcement action to protect user assets, however long that takes."

 

"Due to a hacker attack on the platform, please do not deposit any cryptocurrencies into the platform for trading until the issue is resolved to prevent further asset losses. Data interfaces such as K-line charts and smart money rankings are still functioning normally."

 

"We deeply apologize for the security breach that resulted in losses to user assets. Since the incident occurred, DEXX has been working closely with security teams and law enforcement agencies to investigate, trace the hackers, and track on-chain activities in an effort to minimize losses for affected users. Below is an update on the progress of the investigation and the subsequent response plan."

 

"• November 16: Between 4–5 AM, the hack was detected. Internal reviews were initiated, and a security firm was contacted. • November 17: Salus Security team commenced emergency analysis of the attack path and identified initial evidence of the server intrusion. DEXX relayed information to domestic law enforcement, requesting case registration. • November 18: The attack path analysis was completed, and preliminary evidence and estimated losses were submitted to domestic and international law enforcement. Multiple security teams helped identify hacker-controlled wallets. • November 19: Domestic law enforcement officially opened a case. SlowMist joined the investigation, assisting with evidence collection alongside the police. • November 20–23: • SlowMist compiled affected wallet addresses and examined key evidence. • Internal personnel checks were conducted, with no anomalies found. • Security enhancements and DEXX relaunch preparations began. • November 24–30: Partial identification of stolen assets and addresses was achieved. SlowMist provided an on-chain investigative report to inform the compensation plan. Evidence such as server IP addresses and user agents (UAs) tied to the hacker’s activities was submitted to law enforcement. • December 1–4: Law enforcement conducted further investigations of suspects. Simultaneously, the platform finalized the compensation plan and continued security optimizations. • December 6: Partial security upgrades were completed. High-risk user wallet functions are undergoing testing, with wallet module adjustments in progress."

 

"After upgrading to the latest version, you can find the Compensation on your profile page to confirm your affected tokens. If you have any questions about the data, please contact our customer service. We will record your query, manually verify and update the data."

 

"Comprehensive security fortifications have been implemented, including but not limited to web applications, source code, internal servers, encryption protocols, zero-trust architecture, bastion hosts, and weak password policies."

 

"Our collaborative investigation with security teams and law enforcement identified two critical IP addresses and user agents (UAs) linked to the hacker. In a recent inquiry, a suspect was found using a device with matching UAs and VPN-related IPs. A Monero mnemonic phrase was also discovered. Although technical forensics have identified a significant suspect, definitive evidence remains lacking. The investigation continues, and updates will be shared as they become available.

 

We acknowledge the significant impact this incident has had on our users and apologize for the delay in updates. The sensitivity of the investigation, involving cross-jurisdictional approval processes, and the need to avoid alerting suspects have required discretion. Rest assured, DEXX is fully committed to collaborating with law enforcement and security teams to track the hackers and enhance our security framework, ensuring the safety of user assets.

 

Thank you for your understanding and continued support."

 

Explore This Case Further On Our Wiki

DEXX offered a web wallet with enhanced security. "Our development team has years of on-chain experience, employing multi-layer encryption and ensuring private keys never touch the servers. Combined with top-tier auditing and security teams, DEXX keeps your assets safe." Despite all these promises, users found their assets suddenyl disappearing from their wallets starting on November 15th, 2024. Overall, around $21m+ in assets were taken. The team behind the wallet reached out to SlowMist and law enforcement for assistance in tracking down the stolen funds, and appear to have made progress in identifying a suspect. They have launched a compensation portal for users through their application.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2019 - 2025 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.