CoinDCX Loses $44.2 Million in Security Breach

Generated by AI AgentCoin World
Sunday, Jul 20, 2025 10:11 pm ET1min read
Aime RobotAime Summary

- Indian crypto exchange CoinDCX suffered a $44.2M theft via a compromised internal liquidity account on July 18.

- Attackers used Tornado Cash and cross-chain transfers; the breach was delayed 17 hours before disclosure.

- CoinDCX confirmed customer assets remained secure, losses covered by reserves, and launched a bug bounty program.

- The incident highlights crypto exchange vulnerabilities, reinforcing the need for robust security protocols and transparency.

On July 18, Indian centralized crypto exchange CoinDCX experienced a significant security breach, resulting in the theft of approximately $44.2 million in digital assets. The attack was first identified by onchain sleuth ZachXBT, who noted that the attacker withdrew assets worth around $44.2 million. The exchange's team did not report the attack for about 17 hours, during which time the hacker compromised the platform's internal operating account, which was used exclusively for providing liquidity on a partner exchange.

CoinDCX co-founder Sumit Gupta confirmed the incident, stating that the breach was the result of a "sophisticated attack" on the server. Gupta emphasized that the exchange's customer assets remained unaffected and completely safe, as the hack was limited to a single account. All platform losses were covered by treasury funds, and the incident did not affect the exchange's normal operations, including trading, deposits, and withdrawals.

CoinDCX has enlisted cybersecurity experts to investigate the incident and is working with its partner exchange to track the stolen funds to block and recover them. The exchange has also taken measures to isolate the affected operational account and plans to offset the value of the lost assets through its reserve. Additionally, CoinDCX is set to launch a bug bounty program to further enhance its security measures.

The breach involved the use of blockchain technology, with the attacker address initially funded with 1 ETH from Tornado Cash and later bridging a portion of the stolen funds from Solana to Ethereum. The incident highlights the ongoing vulnerabilities in cryptocurrency exchanges and the importance of robust security protocols. Despite the breach, CoinDCX has emphasized its commitment to transparency and user safety, with the CEO describing the event as a learning moment for the industry.

The theft of $44 million from CoinDCX is the latest in a series of high-profile hacks in the crypto industry, underscoring the need for enhanced security measures. The incident serves as a reminder of the potential risks associated with digital assets and the importance of prioritizing security in the cryptocurrency ecosystem. As the industry continues to evolve, exchanges and users alike must remain vigilant in their efforts to safeguard against cyber threats.

Comments



Add a public comment...
No comments

No comments yet