DX3 AI Bot Exchange Function Price Manipulation Vulnerability
Notice: This page is a freshly imported case study from an original repository. While the original content had a similar format, some sections may not have been fully completed. Please help fill in any empty sections or any missing information you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.
Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!
D3XAI is a Binance Smart Chain-based project that promoted itself as an AI-driven decentralized trading platform, promising advanced market analysis, automated strategies, and a decentralized user-controlled ecosystem. Central to its offering was the D3X AIBOT, claiming to use AI for real-time trading and offered token rewards for participation. However, the platform's closed-source smart contract was exploited through a price manipulation vulnerability, reportedly resulting in losses of around $159,000, as confirmed by blockchain security firms TenArmor and BlockSec. The exploit was linked to the platform relying on an externally manipulable spot price from a UniswapV2 pair. As of now, the project has not publicly acknowledged the incident, no recovery efforts have been announced, and the platform’s future remains uncertain.[1][2][3][4][5][6]
About D3X Smart Contract
D3XAI is a project on the Binance Smart Chain (BSC) that claims to offer a next-generation decentralized trading platform powered by artificial intelligence. According to its promotional materials, the platform aims to leverage AI for deep market analysis, strategy optimization, and automated trade execution, with the goal of improving efficiency and accuracy for both novice and professional traders.
The platform promises to aggregate liquidity from over 24 major blockchains and support more than 2,000 trading pairs, including spot and leveraged contracts. It also advertises a user-friendly interface, API support for algorithmic trading, and a decentralized structure where users retain full control over their assets. However, how well these features perform in practice or how extensively they're adopted remains to be seen.
A central component of the ecosystem is the so-called D3X AIBOT—an AI-powered trading bot that undergoes a 15-day pre-training phase before becoming active. Once deployed, each bot is said to autonomously analyze market data, recognize patterns, monitor price fluctuations and sentiment, and execute trades accordingly. These bots are described as forming a decentralized AI compute network, contributing to the platform's overall intelligence and trading capabilities.
In return for participating in this network, users running AIBOTs can earn $D3XAI tokens, which are advertised as convertible to other assets like $D3XAT or USDT.
The Reality
The smart contract for D3X was closed source. The platform unfortunately had a price manipulation vulnerability. The project markets this as a way to "earn with computing power," but—as with many crypto-based projects—the actual utility, token value, and long-term sustainability of the reward system remain largely speculative and dependent on broader adoption.
As with any early-stage or DeFi-related platform, it's important for potential users and investors to exercise caution, verify claims, and assess both the technical implementation and real-world performance before getting involved.
What Happened
D3XAI, a Binance Smart Chain project promoting AI-driven decentralized trading, suffered a ~$159K loss due to a price manipulation exploit in its closed-source smart contract.
| Date | Event | Description |
|---|---|---|
| August 16th, 2025 2:44:25 AM MDT | Attack Transaction | The attack transaction is accepted by the BSC network onto their blockchain. |
| August 16th, 2025 4:18:00 AM MDT | BlockSec Posts Notice | BlockSec posts an alert on Twitter/X about the exploit. |
| August 17th, 2025 9:14:00 PM MDT | TenArmor Tweet Posted | TenArmor posts a tweet about the exploit. |
Technical Details
Description by TenArmor: "It appears that the exchange() function of the contract 0xb8ad relies on the #d3xat token spot price from a UniswapV2 pair, which was exploited by the attacker through a price manipulation attack."
Description from BlockSec: "Although the contract is not open-source, preliminary analysis indicates a likely case of price manipulation due to spot price dependency."
Total Amount Lost
TenArmor reports that the attack resulted "in an approximately loss of $158.9K" while BlockSec reports "an estimated loss of ~$160K".
The total amount lost has been estimated at $159,000 USD.
Immediate Reactions
The incident was publicly reported on by TenArmor and BlockSec. It does not appear that the project itself has acknowledged the exploit.
Ultimate Outcome
The outcome remains to be seen. The project social media remain operational.
Total Amount Recovered
There is no suggestion of any recovery at this time.
There do not appear to have been any funds recovered in this case.
Ongoing Developments
It is unclear how this situation will resolve itself.
Individual Prevention Policies
No specific policies for individual prevention have yet been identified in this case.
For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.
Platform Prevention Policies
Policies for platforms to take to prevent this situation have not yet been selected in this case.
For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.
Regulatory Prevention Policies
No specific regulatory policies have yet been identified in this case.
For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.
References
- ↑ TenArmor - "Our system has detected that #D3X AI @D3X_AI on #BSC was attacked, resulting in an approximately loss of $158.9K." - Twitter/X (Accessed Sep 22, 2025)
- ↑ Attack Transaction - BSCScan (Accessed Sep 22, 2025)
- ↑ BlockSec Team - "Alert! Our system has detected suspicious transactions targeting an unknown contract (named D3XAT) on #BSC, resulting in an estimated loss of ~$160K. Although the contract is not open-source, preliminary analysis indicates a likely case of price manipulation due to spot price dependency." - Twitter/X (Accessed Sep 22, 2025)
- ↑ Attack Transaction - BlockSec (Accessed Sep 22, 2025)
- ↑ CryptoJPTrans - "#BlockSec reports that #D3XAT in the BSC ecosystem may have been attacked" - Twitter/X (Accessed Sep 22, 2025)
- ↑ https://x.com/PANewsCN/status/1956687367911473634 (Accessed Sep 22, 2025)