UXLink Admin-Key Takeover Leads to $41 Million Loss Through Treasury Theft and Uncontrolled Token Minting
A single delegateCall on a compromised multisig gave an attacker control of Web3 social platform UXLINK's treasury, setting off a multi-chain incident that investigators now estimate at roughly $41 million once treasury theft and subsequent unauthorized token minting are combined.
Whoever held admin access to the multisig used delegateCall to strip the existing admin roles and install themselves as owner. From there, more than $4 million in stablecoins, 3.7 WBTC, and 25 ETH were initially reported stolen across chains — an early figure that would later be dwarfed by the full scope of the operation. In an ironic twist, the attacker was themselves victimized only minutes after minting trillions of unauthorized tokens, when a phishing scam drained 542 million UXLINK tokens from their own wallet into addresses linked to Inferno Drainer.

Reporting draws on analysis from Cyvers, Mannie, how2onchain, Vladimir S., UXLINK, ExVul, Blockscope, PeckShield, Hacken, CoinMarketCap, and Cos.
01Timeline of detection
How2OnChain first spotted unusual activity on September 22, flagging $5.3 million in UXLINK tokens moving quickly and triggering rapid sell-offs. Thirty-five minutes later, Cyvers reported a larger figure — $11.3 million — identifying the delegateCall mechanism used to remove the existing admins and seize control of the vault. Independent researcher Vladimir S. began tracing the wallet activity as the picture developed.
UXLINK itself did not acknowledge the breach until 92 minutes after it began, when it confirmed the incident: "We have identified a security breach involving our multi-signature wallet, resulting in a significant amount of cryptocurrency being illicitly transferred to both CEXs and DEXs." Unlike most DeFi incidents involving flash loans or price-oracle manipulation, this exploit stemmed entirely from misuse of legitimate administrative privileges.
02The admin takeover mechanism
UXLINK's multisig was not broken into through any complex exploit — it was commandeered by whoever already held admin-level access. The delegateCall came first, used to remove the legitimate admins, followed by a second call that installed the attacker as the new controller via addOwnerWithThreshold, as documented by Cyvers. The contract executed the instructions exactly as designed; it had no way to distinguish a hostile takeover from legitimate governance action, since both use the same underlying permissions.
03Tracing the funds
The address that seized control of the treasury was 0x2EF43c1D0c88C071d242B6c2D0430e1751607B87. From there, roughly $18 million moved out across several chains in what turned out to be only the opening phase of a larger operation. Security researcher Gangsterhome of Blockscope provided forensic detail for this reporting.
Initial theft transactions on Ethereum Mainnet:
25.27 ETH ($105k): 0x618e914f8c0afccaaf9be2d502730aa9c89f6cb0cc63aa6e700ef7e1d659b093
$2.68M USDT: 0x725a490ee5cd49209b08cf5b7e7513656098d1c174acdf006707b2d5589654bd
$1.3M USDT: 0x30c72951bce511d4b189844ef750b69fe07d9b78817167ae3ec28628860c2989
3.7 wBTC ($420k): 0x00de60732cb5ca53ad2ac0a2babdc63f94239645309ee097dddb7ed350a1f7e7
$1.45M USDT: 0x278bfd667d9d3e55a33f9255457b3cd4522b96294de4fdc8b79583835491e63c
$500K USDC: 0xf8dce9dfe0ef189b5fe7ad4cded7ef1e4bfffd6955dc1fcd8f3c2b7259afc650
$123K USDT: 0xc609ec7be6274c513fadfb6a95e009b395fd3c4805e81f4896e7ebd89d38dddd
Total stolen on Ethereum via this initial theft address: $6.578 million.
The proceeds were routed to 0x6385eb73faE34bF90Ed4c3d4c8aFBC957FF4121C, and from there partly swapped and forwarded to 0xaC77B44A5F3acC54E3844A609fffd64F182ef931.
That, however, was not the full extent of the damage on Ethereum. A second address, 0xb819e6ae5a6668bb0ce02d64d130deca9ff83691, moved almost double the first haul in a separate set of transactions around the same time: $5.382 million DAI, $1.377 million USDT, 4.009 million USDC, and 4.7327032 WBTC (about $538k) — a second-round total of $11.3 million. Metasleuth's trace of this second Ethereum exploit is available for review.
Combined Ethereum total: $17.885 million.
Smaller amounts were also taken on BSC: 19.5k KiloEx ($91), 70k SOLV ($2,902), and $23,943 in Binance-pegged USDC, for a BSC subtotal of roughly $26,936. Metasleuth's BSC trace documents that activity.
Combined initial theft across Ethereum and BSC: nearly $18 million — which turned out to be only the opening stage of the operation.
04Uncontrolled minting and cross-chain laundering
The treasury drain was followed by a far larger phase: unrestricted minting of the UXLINK token itself. UXLINK disclosed that "we have identified an unauthorized minting of UXLINK tokens today by a malicious actor."
The first batch of 1 billion unauthorized UXLINK tokens was minted in this transaction, prompting PeckShield to flag the token with a "DO NOT TRADE" warning. A second batch of 1 billion tokens followed in a subsequent mint, which PeckShield also flagged. Hacken later estimated that the attacker had ultimately minted close to 10 trillion tokens in total, with additional minting tracked throughout the day.
Forensic work from Blockscope traced roughly 6,700 ETH (about $26.8 million) moved from Arbitrum to Ethereum through cross-chain infrastructure including Across Protocol and Defiway. The pattern involved the attacker minting billions of UXLINK tokens on Arbitrum across multiple unlabeled wallets, swapping them for ETH via decentralized exchanges such as CoW Protocol, and bridging the resulting ETH to Ethereum Mainnet.
Blockscope identified ten addresses where the attacker's funds were being held as of the time of writing:
0x64ab9377a2b3bbb61dd79f8997e7f8c1cc1a4de8
0x7277c705b5b1963b602cb4e3ab8e188d925bed00
0xf35dde49a1bbe7a8883a8f35d48fb33c20a69b39
0x7e1f34418e2da204a8eabdb29eddf7c09a494a3f
0x5210bfdf0cfe6471322d597d16cf440f5ac59309
0xac77b44a5f3acc54e3844a609fffd64f182ef931
0xd7aa2bd9e9407f682a379bed346088b0849b6434
0x714dda349ef43326791f923e8389a21d11378c67
0xa3ce95ac672b62ed75afbe6f50285c28ef717a44

0xaade027d63ea859a4993961a8a8cc5aae3f020f3
Total operation scale, as of September 25: approximately $41 million. Blockscope's forensic analysis puts the attacker's realized proceeds from combined treasury theft and token minting at roughly that figure, though the firm notes this reflects ongoing analysis of complex multi-chain fund flows and may be revised as more evidence emerges.
05The attacker gets phished
While the attacker was busy inflating UXLINK's token supply, they became a target themselves. At 02:15 UTC on September 23, a phishing transaction drained a large portion of the exploiter's own holdings. Scam Sniffer identified the mechanism: a malicious "increaseAllowance" approval that let 542 million UXLINK tokens be pulled from the attacker's wallet. The tokens moved into addresses linked to Inferno Drainer, a group known for running phishing-as-a-service operations. SlowMist founder Cos confirmed that the original UXLINK exploiter had indeed been targeted and drained by Inferno Drainer.
06UXLINK's response
UXLINK's public statements evolved in stages as the scale of the incident became clear. The initial acknowledgment promised the team was "working around the clock" and would contact exchanges to attempt to freeze funds. A later statement shifted focus to warning users directly: "We strongly advise all community members not to trade UXLINK on DEXs at this time, in order to avoid potential losses caused by these unauthorized tokens" — an acknowledgment, in effect, that the circulating token supply had been compromised by the unauthorized mints. The same update said a majority of funds had been frozen, without detailing what portion remained unrecovered. Law enforcement, external security experts, and blockchain forensics firms were brought in to assist.
The most consequential response came in the form of an announced token swap: rather than attempt to fix the compromised token, UXLINK would retire it entirely in favor of a new contract with revised tokenomics and stated security guarantees. The company said it would "promptly initiate a token swap plan to ensure the integrity of our token economy," effectively setting aside the roughly 10 trillion unauthorized tokens now in circulation.
Two days after the incident began, UXLINK launched the new contract, which had passed a security audit, removed the mint function entirely, and was deployed on Ethereum rather than the compromised Arbitrum deployment. The announcement also referenced cooperation with Korean regulatory authorities and claimed certain hacker-linked addresses had been frozen.
A follow-up migration plan detailed a 1:1 token swap that would exclude tokens deemed "illegally issued," honoring only tokens considered "legally issued." An on-chain redemption portal was promised within five working days of September 24, and circulating supply was fixed at approximately 479 million tokens based on the project's whitepaper. A subsequent announcement confirmed the Ethereum Mainnet relaunch with a hard cap of 1 billion tokens, outlining both centralized-exchange and on-chain swap mechanics along with a tentative compensation framework. Frozen hacker-associated tokens would remain excluded from redemption, per the migration plan, while users caught up in the disruption might see partial compensation through buybacks, staking incentives, or trading rewards, contingent on how much value UXLINK could recover from the laundering trail.
Separately, security firm Guardrail AI stated that its monitoring tools would have detected the unauthorized minting before it escalated into large-scale token inflation.
07Market impact and unresolved questions
UXLINK's token price fell roughly 70%, from $0.30 to $0.072, erasing about $70 million in market capitalization, while trading volume spiked more than 1,320% to $437 million as holders rushed to exit.
What remains unresolved is how the attacker obtained admin-level access to the multisig in the first place — whether through a phished team member, a malicious insider, or compromised infrastructure. UXLINK has not specified a cause, and it is unclear whether a full post-mortem will follow. This distinguishes the incident from typical smart-contract exploits: flash loan attacks and oracle manipulation tend to produce detailed technical post-mortems that improve the broader ecosystem's defenses, whereas admin-key and access-control failures more often go unexplained, since attributing a breach to compromised human credentials is a harder narrative for a project to manage publicly than attributing it to a code bug.
Get new scam files the moment we publish them — usually 2–3 emails a week.