Asset Theft Strikes Again: How to Navigate the Dark Forest?

11/19/2024, 4:04:10 AM
DEXX founder Roy stated that user losses would be compensated, and several users reported that their assets had been isolated to secure addresses. However, in similar past incidents, cases where funds were successfully recovered and users satisfactorily compensated have been rare.

On November 16, user assets on the on-chain trading terminal DEXX were stolen, leading to significant short-term dumps of multiple meme coins and severely dampening the enthusiasm of the meme market. According to incomplete estimates from the community, the DEXX incident has impacted over 500 independent victims, with losses estimated to be around $13 million.
DEXX founder Roy stated that user losses would be compensated, and several users reported that their assets had been isolated to secure addresses. However, in similar past incidents, cases where funds were successfully recovered and users satisfactorily compensated have been rare.

Security Vulnerability—Private Keys

Following the DEXX theft, the community has begun to re-examine this meme-specific trading platform.
DEXX’s audit was conducted by Certik, which scored DEXX at 59.31, a failing grade that highlighted 9 risks. The main risk, “centralization,” remained unresolved; two out of four medium-level risks, including “vulnerable code,” were still unaddressed; and of four low-level risks, only one had been resolved.

Previously, DEXX claimed to use a non-custodial wallet for private key storage. However, community observations revealed that DEXX actually managed user private keys through centralized methods.
SlowMist founder Yu Jian noted, “The affected users were those involved in meme coin trading on DEXX. The private keys were centrally managed by DEXX and were definitely leaked, though the method of the leak is still under investigation.”
Additionally, the community discovered that during private key export through developer tools, DEXX private keys were displayed in plaintext, meaning they were actually stored on official servers. If communication was not encrypted, attackers could intercept user private keys during transmission. Even with HTTPS transmission, transferring private keys directly could lead to data breaches due to browser vulnerabilities or other security issues.
Whether the incident is ultimately deemed a hacker attack or insider misconduct, it is evident that DEXX operated under the mindset that “users don’t understand, are easily deceived, and don’t care whether private keys are genuinely non-custodial.” While we cannot control project teams’ attitudes or actions, we can adopt principles to minimize our losses in similar incidents. Without strict risk management of one’s own assets, there is no guarantee of secure funds.

How to Protect Yourself

Custodial vs. Non-Custodial Wallets

Choosing a secure way to store assets starts with selecting a reliable wallet based on your needs. Mainstream crypto wallets can be categorized into custodial and non-custodial wallets based on where the private keys are stored.

Custodial Wallets

Custodial cryptocurrency wallets store assets on behalf of users. This means a third party holds and manages the private keys. Consequently, users cannot have complete control over their funds or sign transactions. When choosing a custodial service provider, consider factors such as regulatory status, service types, private key storage methods, and whether insurance is provided.

Non-Custodial Wallets

Non-custodial cryptocurrency wallets give users full control of their private keys. This type of wallet is suitable for those who wish to have complete control over their funds. Without intermediary intervention, users can directly trade cryptocurrencies from their wallets. However, this also means users bear full responsibility for their keys, facing risks like loss and attacks.

Asset Segregation

Just as you wouldn’t put all your eggs in one basket, it’s important to effectively segregate your assets. Here’s a standard approach to asset storage:

  1. Hot Wallet: Used for frequent interactions, this wallet should not store large amounts of assets—just enough to cover gas fees. This wallet is suitable for engaging in opportunities but should be set up to control potential phishing attack losses.
  2. Warm Wallet: An isolated wallet for assets with less frequent interactions, such as those used for staking. It allows for transactions but at a lower frequency than the hot wallet, reducing the risk of key leaks.
  3. Cold Wallet: Large assets should be stored in a hardware wallet (cold storage) that does not interact online.

Security Recommendations

  1. Be skeptical of unsolicited recommendations; always DYOR (Do Your Own Research) on the product mechanisms. Use trading bots that do not store private keys on servers.
  2. Opt for trading bots with long-standing operations and professional teams.
  3. Avoid clicking on unknown links or responding to messages in Telegram groups.
  4. Transfer large funds to a cold wallet after transactions, regardless of the tools used.

Reminder: There have been reports of phishing scams targeting DEXX victims, such as “victim support groups,” “DEXX theft registration,” or “DEXX compensation” offers. Users should be cautious, avoid uploading private keys or seed phrases, and not connect wallets for confirmations to prevent further harm.

* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.

Share

Crypto Calendar

Proje Güncellemeleri
Etherex, 6 Ağustos'ta REX token'ını piyasaya sürecek.
REX
22.27%
2025-08-06
NFT AI Ürün Lansmanı
Nuls, üçüncü çeyrekte bir NFT AI ürünü piyasaya sürecek.
NULS
2.77%
2025-08-06
dValueChain v.1.0 Lansmanı
Bio Protocol, ilk çeyrekte dValueChain v.1.0'ı piyasaya sürmeye hazırlanıyor. Amacı, DeSci ekosisteminde güvenli, şeffaf ve değiştirilemez tıbbi kayıtlar sağlamak için merkeziyetsiz bir sağlık veri ağı kurmaktır.
BIO
-2.47%
2025-08-06
Yapay Zeka Tarafından Üretilen Video Altyazıları
Verasity, dördüncü çeyrekte AI tarafından üretilen video altyazı fonksiyonu ekleyecek.
VRA
-1.44%
2025-08-06
VeraPlayer Çok Dilli Destek
Verasity, dördüncü çeyrekte VeraPlayer'a çok dilli destek ekleyecek.
VRA
-1.44%
2025-08-06

Related Articles

DOGS Token Overview: Tokenomics and Airdrop Claiming (as of 2025)
Advanced

DOGS Token Overview: Tokenomics and Airdrop Claiming (as of 2025)

The DOGS token, inspired by the mascot Spotty designed by TON founder Pavel Durov for the Telegram community, embodies the unique spirit and culture of the Telegram ecosystem. As of 2025, DOGS has established itself as a leading meme token on the TON blockchain, ranking in the top 50 cryptocurrencies by market cap. The ecosystem has expanded significantly, featuring DOGS 2.0 protocol with enhanced staking, DeFi integrations across multiple chains, and a community governance system. DOGS now supports NFT collections, gaming integrations, and cross-chain functionality, with Gate providing comprehensive trading support and improved liquidity options.
5/22/2025, 3:02:50 AM
Gate.io Launches Pilot Trading Section: Capture On-chain Alpha and Seize 100x Opportunities!
Advanced

Gate.io Launches Pilot Trading Section: Capture On-chain Alpha and Seize 100x Opportunities!

The Gate.io Pilot Trading Section is a newly launched independent trading board focused on finding popular on-chain projects. It helps users participate in on-chain project launches without needing a Web3 wallet.
9/14/2024, 6:35:55 AM
Grass (GRASS) — Decentralized AI Data Collection
Advanced

Grass (GRASS) — Decentralized AI Data Collection

Grass is a DePIN project built on the Solana network that leverages unused internet bandwidth to gather information from public networks. This information is then used to train large language models (LLMs) and establish a transparent data marketplace that rewards all participants. The protocol utilizes the bandwidth of users' devices to search for necessary information, process the collected data, and record its provenance history on the blockchain using zero-knowledge proofs (ZKPs).
11/4/2024, 6:54:01 AM
Virtuals Protocol (VIRTUAL) — The AI Agent Generation Platform at the Forefront of Innovation
Beginner

Virtuals Protocol (VIRTUAL) — The AI Agent Generation Platform at the Forefront of Innovation

Founded in 2021, Virtuals Protocol is an AI agent generation platform built on Base Rollup. It was co-founded by Prakash Somosundram, Colin Choo, Christopher Johnson, and Matthew. The platform aims to allow anyone to create an AI agent—a virtual character capable of interacting with and participating in its environment like a human. It incentivizes the decentralized creation and monetization of AI agents for every virtual interaction, whether in gaming, the metaverse, online engagements, or other applications.
12/18/2024, 8:57:22 AM
Kaito (KAITO) - A Decentralized InfoFi Platform
Beginner

Kaito (KAITO) - A Decentralized InfoFi Platform

Kaito is a decentralized application platform based on Web3 and AI technologies, aimed at providing users with low-barrier personalized AI robot creation tools and building an open and fair AI content ecosystem.
2/28/2025, 7:34:54 AM
Gate.io Launches PreMint: A Revolution in Pre-Market Trading
Advanced

Gate.io Launches PreMint: A Revolution in Pre-Market Trading

Gate.io recently launched PreMint feature for pre-market trading. PreMint is a staking and minting mechanism for pre-market trading. It allows users to stake USDT to mint PreToken.
9/3/2024, 3:58:28 AM
Start Now
Sign up and get a
$100
Voucher!