Exchange

BitBNS Exchange Hacked for $8 Million, Incident Initially Concealed

Summary # On February 1, 2022, BitBNS, an Indian crypto exchange, fell victim to a hacking incident resulting in the loss of $8 million. The exploit was made possible through a vulnerability in their AWS (Amazon Web Services) cloud storage, allowing the attacker to access the exchange’s private keys and steal funds. BitBNS initially attempted to hide the breach from users by tweeting about “system maintenance in progress.” The CEO later admitted to concealing the incident, stating that the decision was made following law enforcement advice. ...

LCX Exchange Hacked for $8 Million

Summary # On January 8, 2023, cryptocurrency exchange LCX was hacked, resulting in the theft of cryptocurrencies $8 million. Hackers gained access to the exchange’s hot wallets and stole various cryptocurrencies, including ETH, USDC, SAND, LINK, QNT, ENJ, and MKR. Attackers # The identity of the hackers who attacked LCX is unknown. Hacker ETH Wallets: 0x165402279F2C081C54B00f0E08812F3fd4560A05 0x29875bd49350aC3f2Ca5ceEB1c1701708c795FF3 Losses # LCX estimated the losses from the hack to be $8 million. ...

AscendEX Hack: $77 Million Stolen in Hot Wallet Breach

Summary # On December 11, 2021, AscendEX, a cryptocurrency exchange, was the victim of a hot wallet breach that resulted in the loss of $77 million. The attacker gained access to one of the exchange’s hot wallets, used to store user funds available for withdrawal. Attackers # The identity of the attacker(s) remains unknown. Wallet addresses to which assets were transferred: ERC20: 0x2c6900b24221de2b4a45c8c89482fff96ffb7e55 Polygon: 0x2c6900b24221de2b4a45c8c89482fff96ffb7e55 BSC: 0x2c6900b24221de2b4a45c8c89482fff96ffb7e55 LTC: LSvQWLf2kGm7UdXtwKvNj4GU1B4xKWUQXR BCH: qp2x5rnn2fkraxcp4hr6suqmnpdehfaaaqn3tv6jke Losses # The attackers managed to steal approximately $77 million worth of assets from the AscendEX network. ...

BitMart Exchange Suffers $196 Million Security Breach

Summary # On December 4, 2021, BitMart Exchange, a global cryptocurrency platform operating in 180+ countries, fell victim to a significant security breach. The attacker extracted approximately $196 million worth of various digital assets from the hot wallets of the exchange across two networks: Binance Smart Chain (BSC) - $96 million, and Ethereum - $100 million. The primary targets were meme-based tokens, such as SHIB and SAFEMOON. The attacker converted the stolen tokens into ETH and BNB via 1inch and laundered these assets using TornadoCash. ...

Bilaxy Exchange Suffers Security Breach with a Loss of $21 Million

Summary # On August 28, 2021, Bilaxy, a Seychelles-based centralized exchange, experienced a security breach, resulting in a loss of approximately $21 million. The attacker compromised Bilaxy’s hot wallet and transferred roughly 300 tokens, including notable cryptocurrencies such as USDT, USDC, UNI, and Bilaxy Token(BIA), among others. As of August 16, 2023, the attacker still controls various tokens worth roughly $3,628,005. Attackers # The identity of the attackers remains unknown. ...

Liquid Exchange Hacked for $97 Million

Summary # On August 18, 2021, Liquid, a Japanese cryptocurrency exchange, was hacked for $97 million. The attacker gained access to one of the exchange’s hot wallets, which are used to store user funds that are available for withdrawal. Attackers # The identity of the attacker(s) is unknown. BTC: 1Fx1bhbCwp5LU2gHxfRNiSHi1QSHwZLf7q ETH: 0x5578840aae68682a9779623fa9e8714802b59946 0xefb33ccafc98d5fdb27a6f5ff17350ca76bf3b53 XRP: rfapBqj7rUkGju7oHTwBwhEyXgwkEM4yby TRX: TSpcue3bDfZNTP1CutrRrDxRPeEvWhuXbp Losses # The attackers managed to steal a total of $97 million worth of cryptocurrency from the Liquid hot wallet. ...

Uranium Finance Exploit Resulting in a $57.2 Million Loss

Summary # On April 28, 2021, Uranium Finance, a BSC-based decentralized exchange, was exploited due to a calculation error bug in its v2 pair contracts, which had been forked from the Uniswap v2 code. The bug allowed an attacker to swap minimum amount of the input token for 98% of the total balance of the output token, leading to massive losses. Uranium Finance had discovered the potential vulnerability but failed to prevent the attack: ...

Thodex Cryptocurrency Exchange Collapses in $2 Billion Exit Scam

Summary # In April 2021, Turkey-based cryptocurrency exchange Thodex collapsed in an exit scam, defrauding investors of $2 billion. Thodex’s founder, Faruk Fatih Ozer, fled to Albania with the stolen funds but was later arrested and extradited back to Turkey. In January 2023, Faruk Fatih Ozer and his two siblings were sentenced to 11,196 years in prison each for money laundering, fraud, and organized crime. Thodex’s rapid growth and promises of a safe and secure trading platform concealed its fraudulent intentions. ...

Africrypt Founders Vanished with $3.6 Billion in Bitcoin

Summary # On June 23, 2021, Africrypt, a centralized platform claiming to connect banks, payment providers, and digital asset providers for seamless global money transfers, was reportedly compromised. Ameer and Raees Cajee, the exchange’s founders, were reported missing after alleging that almost $3.6 billion invested in the protocol was stolen in a “hack”. Africrypt staff lost access to the exchange’s back-end systems seven days before the claimed attack. Subsequent investigations found that most of the bitcoin invested with the exchange had been withdrawn and moved through tumblers and mixers, making it harder to track. ...

EXMO Exchange Hot Wallets Compromised: Approximately $10.5 Million Stolen

Summary # On December 21, 2020, the attackers gained unauthorized access to the EXMO exchange’s hot wallets. Through these security weaknesses, they managed to execute malicious transactions, resulting in the theft of a substantial amount of cryptocurrency. Attackers # The identities of the attackers remain undisclosed. The following addresses were involved: 1A4PXZE5j8v7UuapYckq6fSegmY5i8uUyq 0x4BA6B2fF35055aF5406923406442cD3aB29F50Ce qrfrw5q9gag2vp6jc5nlx0haplm2jlhx9vsvxd9u3e t1StUQiw1YyHT515xDxwxjfhEcw2iGSq2yL rwU8rAiE2eyEPz3sikfbHuqCuiAtdXqa2v Destination Tag: 2033412069 0x4d9EF6846126Da2867AF503448be0508542C971e Losses # The EXMO security breach resulted in the theft of around $10. ...