Open app

HostDeFi › Is OKX safe

Is OKX safe? The exchange that froze for five weeks — then got drained through an old contract

OKX is the three-limb venue: a custodial CEX publishing zk-STARK proof-of-reserves monthly, a self-custody wallet, and a DEX aggregator — with two documented incidents that land on different limbs: five weeks of frozen withdrawals in 2020 (a key holder went unreachable), and a $2.7M drain through a deprecated approved contract in 2023. Both resolved; both permanent lessons. The wallet arm and the proof-of-reserves program pull in the safety direction; the incident record is what honest diligence looks like for a custodian of this size.

Updated September 28, 2026 · By the HostDeFi editorial desk · Sources linked throughout; vendor claims labeled.

What OKX is — three limbs, three custody answers

OKX (OKEx until its January 2022 rebrand) is a top-tier global exchange with three distinct products whose custody answers differ completely: the custodial CEX (balances are claims, backed by a monthly published proof-of-reserves), the OKX Wallet (self-custody, keys on your device), and the DEX aggregator (nothing held — but your token approvals stand against its contracts). It is the only venue in this family with documented incidents on two different custody surfaces.

October 2020: five weeks frozen, zero dollars missing

On October 16, 2020, OKEx suspended all withdrawals: one of its private key holders was unreachable — cooperating with a public security bureau investigation (widely reported as founder Star Xu; officially unconfirmed). The exchange's own postmortem admits the gap: its contingency plan covered a key holder's death or incapacitation — not unreachability. Withdrawals stayed down ~five weeks. When they reopened (November 26-27) after the holder returned, OKX stated it had been cleared of wrongdoing, had held 100% reserves throughout, and that no assets had moved at all.

That is the cleanest documented demonstration of a truth every CEX user should hold: solvency and access are different things. Users weren't robbed — they were locked out for five weeks by a key-personnel dependency, at scale, at one of the world's largest venues.

December 2023: the deprecated contract that still had approvals

On December 12-13, 2023, a suspected proxy-admin private key compromise let an attacker upgrade a deprecated OKX DEX proxy contract. The new implementation invoked TokenApprove's claimTokens path — draining tokens users had approved long ago, ~$2.7M by SlowMist/PeckShield accounting (Arkham linked the actor to other exploits). OKX revoked the contract's permissions, removed it from the trusted list, and committed to reimbursing affected users.

Structurally identical to SushiSwap's RouteProcessor2: a contract you no longer use can still spend what you approved it to. The exploit needed no bug in the live system — just a dead contract holding live allowances and an admin key that leaked.

Proof of reserves — what it does and doesn't cover

OKX publishes monthly proof-of-reserves (zk-STARK-based; 100%+ backing on major assets, with user self-verification tooling). It is the strongest transparency the major-CEX class offers — and its limits are precise: PoR attests that assets exist at a snapshot; it does not publish liabilities, and it cannot speak to operational risk — the 2020 freeze happened at full reserves, on a venue whose solvency was never in question and whose withdrawals still stopped for five weeks. PoR answers 'does the money exist', not 'can you reach it on a bad day' — and the 2020 freeze is the documented case of the second question failing while the first stayed true.

The risk stack, per limb

LimbCustodyDocumented risk
CEXCustodial claims2020: 5-week withdrawal freeze at full reserves (key-person dependency)
DEX aggregatorNone — approvals only2023: $2.7M drained via deprecated proxy + live approvals
WalletSelf-custodyStandard set: seed loss, phishing, fake apps
All—Phishing clones of a top-3 brand

The stale-approval lesson travels

The 2023 incident's instruction is the same one the SushiSwap page carries: approvals granted to a contract outlive the interface that asked for them — and a deprecated contract with a privileged upgrade path is a loaded shelf. Periodically reviewing and revoking token allowances is the user-side mirror of OKX revoking the proxy's permissions; the difference between 'was exposed' and 'was drained' for the affected wallets was simply whether a live allowance existed at exploit time.

Where OKX stands

Two instructive incidents, both resolved without permanent user losses — plus monthly PoR and a self-custody arm for users who want out of the custodial question entirely. The dated read: a major CEX whose scars prove the lessons — custody means access risk even at 100% reserves, and approvals outlive the contracts that earned them — with the transparency tooling to check the solvency half yourself, and a documented history of making users whole when its own side failed.

The verdict in one line: OKX froze withdrawals for five weeks at full reserves and lost $2.7M through a dead contract — it's safe in the ways it can prove (reserves, reimbursement) and risky in exactly the ways custody and stale approvals always are.

Frequently asked questions

Is OKX a legitimate exchange?

Yes — OKX (OKEx until its January 2022 rebrand) is one of the largest global crypto exchanges, with a published monthly proof-of-reserves program (zk-STARK-based, 100%+ major-asset backing) plus a self-custody OKX Wallet arm. Its record includes two genuinely instructive incidents — a five-week withdrawal freeze in 2020 and a $2.7M contract exploit in 2023 — both resolved without user-fund losses from custody.

What happened in the OKX 2020 withdrawal freeze?

On October 16, 2020 (as OKEx) the exchange suspended all withdrawals — one of its private key holders was unreachable, cooperating with a public security bureau investigation (reported as founder Star Xu; officially unconfirmed). The exchange admitted its contingency plan covered a key holder's death or incapacitation but not unreachability. Withdrawals stayed frozen ~five weeks, reopened November 26-27 after the holder returned — OKX states it was cleared of wrongdoing, held 100% reserves throughout, and no assets ever moved.

What was the December 2023 OKX DEX exploit?

A suspected proxy-admin private key leak let an attacker upgrade a deprecated OKX DEX proxy contract — which could then invoke TokenApprove's claimTokens path to drain tokens users had previously approved, ~$2.7M total (SlowMist/PeckShield/SharkTeam analyses; attacker linked to other exploits by Arkham). Same mechanism as SushiSwap's RouteProcessor2: an old approved contract became the weapon. OKX revoked permissions, pulled the proxy from its trusted list, and promised to reimburse affected users — the textbook stale-approval incident.

Does OKX hold your crypto?

The exchange, yes — CEX balances are custodial claims, which is precisely what the 2020 freeze proved matters: users couldn't withdraw for five weeks despite full reserves, because withdrawals needed a human key holder. The OKX Wallet app is the opposite — self-custody, keys on device. The DEX aggregator adds a third shape: nothing held, but your token approvals stood exposed to a deprecated contract — which is what the 2023 incident exploited.

Does OKX publish proof of reserves?

Yes — monthly PoR reports using zk-STARK proofs, claiming 100%+ backing on major assets since early 2023, with self-verification tooling for users to check inclusion of their balances. PoR shows assets exist at a snapshot — it does not show liabilities, and it cannot prove a freeze can't recur (2020 was an operational freeze, not an insolvency). It is the strongest transparency a major CEX currently offers, and still a snapshot, not a guarantee.

What are OKX's real risks?

In order: (1) custodial/operational risk — 2020 proved a single key holder's unavailability can halt all withdrawals for weeks regardless of solvency; (2) approval-layer risk — 2023 proved deprecated contracts with live user allowances stay dangerous (both are documented, not hypothetical); (3) phishing clones of a top-3 brand; (4) jurisdictional/regulatory variance by region. The wallet arm's risks are the standard self-custody set.

HostDeFi is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a HostDeFi product