Data leak [loss] $70M+

Tweet by CoinEx

2023-09-12 [vendor] CoinEx
Primary Source ↗
Financial Loss $70.0M (70,000,000 USD)

Incident Details

Various blockchain watchers noticed suspicious transfers from a hot wallet known to belong to the CoinEx cryptocurrency exchange. CoinEx later confirmed a “security incident” involving “unauthorized transactions”, and disclosed that around $70 million was stolen. Outside researchers have suggested that the thieves appear to be a part of the North Korean state-sponsored hacking group, Lazarus.CoinEx is based out of Hong Kong, and was recently forced to stop serving US customers as part of a settlement with the New York Attorney General which also required them to pay a $1.7 million fine.

Total loss estimated at $70,000,000.

Technical Details

Initial Attack Vector
Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise
Vendor / Product
CoinEx

Timeline

  1. 2023-09-12 Breach occurred
  2. 2023-09-12 Publicly disclosed