Cryptopolitan
2025-07-19 16:35:19

CoinDCX CEO confirms internal account got breached

CoinDCX, one of India’s biggest crypto platforms, just got wiped for $44.2 million in what looks like a hot wallet exploit. The hit happened about 17 hours ago, and the company didn’t say a word until on-chain sleuth ZachXBT exposed it. The stolen crypto was first flagged by Cyvers, a blockchain security firm that spotted suspicious transactions and alerted Zach. Zach went public with the information on Telegram : “ Looks like the India centralized exchange ‘CoinDCX’ was likely drained for ~$44.2M almost 17 hours ago and has yet to disclose the incident to the community. ” He said the hacker address got 1 ETH from Tornado Cash, and then bridged part of the stolen funds from Solana to Ethereum. The hack wasn’t traced to a tagged wallet or listed in CoinDCX’s proof of reserves. Zach said he figured out the link by checking counterparties manually. He also listed the attacker’s addresses: Solana: 6peRRbTz28xofaJPJzEkxnpcpR5xhYsQcmJHQFdP22n Solana: 3btch8cSVp3Uh2SiY9DeiRNYUBmFiBNHZQzDyecJs7Gu Ethereum: 0xEF0c5b9E0E9643937D75C229648158584A8CD8D CEO confirms internal account got breached Right after Zach’s post started circulating, Sumit Gupta, the CEO of CoinDCX, finally stepped up with a statement on X, saying, “ Hi everyone, At CoinDCX, we have always believed in being transparent with our community, hence I am sharing this with you directly. ” According to Sumit, the compromised account was an internal operational wallet, not one that holds customer funds. He said it was used “only for liquidity provisioning on a partner exchange” . The breach was caused by a “sophisticated server attack,” but Sumit claims all customer wallets were safe and hadn’t been touched. “ No customer funds have been impacted. Your assets remain completely safe and protected in our secure cold wallet infrastructure. All trading activity and INR withdrawals are fully operational. ” The team isolated the breached account fast and says the loss is being covered from their own treasury, not customers’ assets. They’ve brought in cybersecurity firms to dig through the breach, patch vulnerabilities, and track where the funds are moving. Gupta said they’re also working with the unnamed exchange partner where the liquidity account was being used. They plan to launch a bug bounty program to catch other possible security gaps. He also said, “ Every security incident is a learning, and we will learn from this and further strengthen our platform… this is our time to win this war against cyberthreats in the industry. ” He ended by promising real-time updates going forward: “I understand incidents like this can be unsettling – even when customer assets are unaffected. That’s why I am sharing this incident with you with full transparency. Thank you for your continued trust. I will keep you informed on a real-time basis as we learn more.” Cryptopolitan Academy: Want to grow your money in 2025? Learn how to do it with DeFi in our upcoming webclass. Save Your Spot

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.