
A security dispute has emerged between OKX wallet and the ZeroDrift security team over a vulnerability ZeroDrift claims to have found in OnChainOS, which powers OKX Wallet’s agent related features.
According to an X post by ZeroDrift, the company stated that they could manipulate the OnChainOS agent using a malicious token, making it approve transactions that could empty a wallet. Their researchers explained the attack worked because token metadata from the search API went to the agent’s context without any sanitization.
According to ZeroDrift, a scam token’s description could include instructions, which the agent would process as a part of its workflow. According to them, these instructions could trigger an unlimited token approval, and the Trusted Execution Environment (TEE) would sign out without checking properly.
After investigating, OKX Wallet challenged these claims. They said they could not reproduce the attack in their own testing and wondered if ZeroDrift’s demonstration was actually running against the official, unaltered OnChainOS service.
感谢反馈!我们已就相关内容对 OnchainOS 开展核查。截至目前,我们未能复现视频所描述的情况,即仅通过在链上 Token 相关信息中写入特定文本,便可使官方 Agent 发起无限额度授权并完成签名。
经核查,视频中展示的接口返回内容及数据结构与 OnchainOS… HTTPS://T.CO/ZCDWSY1GI5
— OKX Wallet 中文 (@OKXWallet_CN) SEPTEMBER 15, 2026
ZeroDrift’s Security Claim
ZeroDrift first described their finding as an attack on OKX Wallet’s OnChainOS agent. They claim they could drain funds from the agent with a single prompt. The company stated that at the centre of this is OnChainOS passing unsanitized token metadata from its search API directly to the agent’s context.
We drained OKX @WALLET‘s OnchainOS agent with one prompt.
OnchainOS passes unsanitized token metadata from the search API into the agent’s context. A scam token’s description becomes instructions for an unlimited approval, which the TEE signs without validation. PIC.TWITTER.COM/GPFAN25LXI
— Zerodrift (YZi S4) (@ZeroDriftSec) SEPTEMBER 14, 2026
Their main focus is on the information tied to a token. In this scenario, a scam token might include a malicious description, which the agent would treat as instructions. Instead of only seeing the token information as data, the agent might actually follow the embedded instructions.
ZeroDrift believes this leads to unlimited approval. Here, the TEE would sign for it without checking what was really being approved. So their claim is really about how token metadata, agent instructions, and the signature process, all interact.
OKX Wallet Challenged the Demonstration
OKX Wallet responded by saying they checked out the OnChainOS content in question, but could not reproduce what ZeroDrift showed. They said they tried the steps described but could not get the official agent to issue unlimited authorization or complete the signing just by putting certain text in token information fields.
The company added that the interface behavior and data structures in ZeroDrift’s video did not match up with what they see in the real OnChainOS system.
On top of that, OKX Wallet said they checked on-chain activity for the involved addresses, but did not find anything resembling the attack described in the video. Based on all the public information and evidence, they do not think the video proves this issue exists in the official, unaltered OnChainOS setup.
They made it clear that they are open to security research. OKX Wallet said they welcome feedback from security experts and want researchers to use proper vulnerability disclosure channels. They asked for detailed steps, environment details, request and response logs, transaction information, everything needed to reproduce the issue.
ZeroDrift Promises a Full PoC
After OKX responded, ZeroDrift addressed the disagreement directly. They promised to provide a full proof of concept and test it on testnet for everyone to see.
we will provide the full poc and run it on testnet for verification,stay tuned
— Zerodrift (YZi S4) (@ZeroDriftSec) SEPTEMBER 15, 2026
This could be a turning point, since both sides still have very different takes. ZeroDrift stated that their attack shows a real security risk involving token metadata, agent instructions and unlimited approvals signed by the TEE. OKX Wallet says they cannot trigger those actions with the official interface and see inconsistencies between the demonstration and real OnChainOS behavior.
So, if ZeroDrift can reproduce the problem on testnet, it should let everyone take a closer look at the claim in a controlled setting. The researchers said they will share the full PoC and run it on testnet soon, which means more technical evidence is coming after OKX Wallet’s review.
Right now, the dispute is down to whether ZeroDrift’s attack works on the official OnChainOS environment, or if their demonstration depends on some special setup that does not reflect what OKX Wallet actually runs.
