Analysis of the latest 10 major incidents in cryptocurrency exchanges
On February 21, 2025, roughly 400,000 ETH (~$1.4–1.5B) was drained from Bybit’s Ethereum cold wallet — the largest crypto theft on record. Attackers compromised Safe{Wallet} infrastructure (AWS S3), injecting malicious JavaScript into the signing frontend on February 19. On February 21, Bybit multisig signers approved what looked like a routine cold-to-warm transfer; the payload instead handed control to the attacker. The FBI attributed the campaign to North Korea’s Lazarus Group. Bybit pledged to make customers whole and launched recovery bounties, but only a small share of funds was frozen early on. The breach highlights CEX dependence on third-party multisig UX and supply-chain attacks against signing interfaces.
On May 31, 2024, Japanese exchange DMM Bitcoin disclosed unauthorized transfer of 4,502.9 BTC (~$305M). A joint FBI / Japan NPA / DC3 statement attributed the attack to TraderTraitor (Lazarus), with initial access via social engineering against staff at wallet provider Ginco. DMM covered customer balances via a large parent-group capital injection, but later restricted services and in December 2024 announced a wind-down with account migration to SBI VC Trade. The case shows how vendor compromise and weak wallet-ops controls can destroy a regulated exchange even when customers are reimbursed.
On July 18, 2024, attackers drained roughly $230–235M (~45% of reserves) from a WazirX multisig wallet — India’s largest crypto heist. A malicious contract was deployed days earlier and activated through a deceptive signing interface. The US, Japan, and South Korea later attributed the attack to North Korean actors. Only about $3M (~1.3%) was reported frozen by early 2025; most funds were laundered via mixers. A bounty program of up to $23M did not restore user losses at scale. The incident underlines risks of external multisig UIs and concentrated custodial wallets.
In June 2025, Iranian exchange Nobitex was hit by hacktivist group Gonjeshke Darande (Predatory Sparrow), with roughly $90M affected. Unlike typical profit-driven thefts, portions of funds were burned via vanity addresses carrying political messages. The case shows that regional CEXs face not only financial crime but also geopolitically motivated cyber operations. For users, it again reinforces cold storage for large balances and avoiding single-exchange concentration.
In January 2025, Phemex reported a compromise that drained roughly $70–73M from hot wallets across multiple chains. The likely root cause was private-key / hot-wallet operational compromise—still the dominant CEX failure mode. The exchange paused withdrawals and investigated. Even after Bybit, the industry continues to lose large sums from weak key isolation and insufficient outbound-transaction monitoring.
On September 23, 2023, Mixin Network reported a breach of its cloud provider infrastructure: attackers accessed key-related material and stole around $200M in assets (mostly BTC). It was one of 2023’s largest non-Solidity incidents. The case highlights the danger of keeping seed/key material with cloud vendors and the need for HSMs, geographic separation, and zero-trust access to custody systems.
In November 2023, Poloniex suffered an attack with losses estimated around $100–126M. Industry reports placed it in the same month’s wave of major CEX/custody incidents (alongside HTX/Heco). Withdrawals were constrained while investigators and chain-analytics teams tracked funds. The event increased pressure for proof-of-reserves, insurance funds, and transparent CEX incident response.
In November 2023, the HTX (formerly Huobi) ecosystem and related Heco Bridge suffered combined losses on the order of $100–110M+ across linked compromise events. That month showed how CEX and cross-chain bridge risks amplify each other. User takeaway: diversify venues and avoid leaving large balances on centralized services long-term.
In June 2023, Atomic Wallet users reported mass unauthorized transfers; aggregate loss estimates ranged from tens of millions up to ~$100M depending on methodology. The vector was linked to client software / update-infrastructure compromise rather than a single-chain smart-contract bug. It remains a warning on supply-chain risk for non-custodial wallets: self-custody fails if the distribution channel or runtime is poisoned.
In September 2023, CoinEx reported a hot-wallet breach with roughly $70M lost. Services were paused for wallet migration and remediation; compensation commitments followed. As with other 2023 CEX cases, the core issue was attacker access to keys or signing systems. The incident reinforced hard hot/cold separation, auto-sign limits, and on-chain monitoring of outbound flows.
In September 2023, Stake.com reported a breach with about $41M in crypto withdrawn. While not a spot exchange, the custody model is CEX-like: user deposits under operator control. The case expands the risk map beyond DeFi—any custodial balance is a target for APT activity and access-control failures.
In 2025, Coinbase faced a major incident involving bribery/compromise of support staff and customer PII exposure—not a classic on-chain reserve drain. The lesson is social engineering and insider risk in human support flows that enable phishing and account takeover. Critical for any CEX/fintech with KYC access via customer support.
FTX, one of the largest cryptocurrency exchanges, went bankrupt due to massive fraud and improper management of client funds. Founder Sam Bankman-Fried used client funds for risky investments through the related company Alameda Research, leading to losses of over 8 billion dollars. Problems included the lack of separation between client funds and the exchange's own funds, opaque management structure, and the use of FTT tokens as collateral for obtaining loans. When the price of FTT fell, it triggered a cascade effect leading to bankruptcy. The incident shook the entire cryptocurrency market and led to stricter regulation in the industry. Many users lost all their funds, and trust in centralized exchanges was seriously undermined. This case demonstrated the critical importance of transparency and proper fund management in the cryptocurrency industry.
Binance, the largest cryptocurrency exchange, was attacked, resulting in the theft of 570 million dollars. The attackers gained access to the exchange's hot wallets through compromise of private keys. The attack was possible due to insufficient infrastructure security and lack of proper protection of private keys. The attackers were able to bypass the multi-level security system and gain access to client funds. After discovering the attack, Binance suspended operations and began an investigation. Fortunately, the exchange had an insurance fund that covered the losses, and clients were not affected. However, the incident demonstrated the vulnerability of even the largest market players and the importance of continuously improving security systems. After the attack, Binance strengthened security measures and increased the share of funds in cold wallets.
Coinbase, one of the largest cryptocurrency exchanges, fell victim to a user data breach, compromising the personal information of millions of clients. The attackers gained access to the exchange's database through a vulnerability in the data management system. The breach included names, email addresses, phone numbers, and partially encrypted passwords of users. Although client funds were not stolen, the data breach created serious security risks for users, including the possibility of phishing attacks and identity theft. After the incident, Coinbase strengthened security measures, implemented additional data encryption, and improved the security monitoring system. This case demonstrated the importance of protecting personal data in the cryptocurrency industry and the need to comply with security standards.
KuCoin, a popular cryptocurrency exchange, was attacked, resulting in the theft of 281 million dollars. The attackers gained access to the exchange's hot wallets through compromise of private keys. The attack was particularly devastating because KuCoin did not have sufficient insurance fund to cover losses. After discovering the attack, the exchange suspended operations and began the recovery process. KuCoin issued KCS tokens to cover losses, but many users lost their funds. The incident demonstrated the importance of having insurance funds and proper risk management in the cryptocurrency industry. After the attack, KuCoin strengthened security measures and increased the share of funds in cold wallets.
Crypto.com, a popular cryptocurrency platform, was attacked, resulting in the theft of 35 million dollars. The attackers gained access to user accounts through a vulnerability in the authentication system and performed unauthorized transactions. The attack was possible due to shortcomings in the security system and lack of proper protection against unauthorized access. The attackers were able to bypass two-factor authentication and gain access to user funds. After discovering the attack, Crypto.com suspended operations and began an investigation. The platform covered losses from its own funds, but the incident undermined user trust. After the attack, Crypto.com strengthened security measures and improved the system for monitoring suspicious activity.
Bitfinex, one of the oldest cryptocurrency exchanges, was attacked, resulting in the theft of 72 million dollars in bitcoins. The attackers gained access to the exchange's hot wallets through compromise of the key management system. The attack was particularly devastating because Bitfinex did not have an insurance fund to cover losses. After discovering the attack, the exchange suspended operations and began the recovery process. Bitfinex issued BFX tokens to cover losses, but many users lost their funds. The incident demonstrated the importance of proper key management and having insurance funds in the cryptocurrency industry. After the attack, Bitfinex strengthened security measures and switched to a more secure key management system.
Mt. Gox, once the largest bitcoin exchange, went bankrupt after it was discovered that 850,000 bitcoins (about 460 million dollars at the time) had been stolen as a result of a series of attacks. The attackers exploited a vulnerability in the transaction system known as "transaction malleability," which allowed them to create duplicate transactions and deceive the exchange's accounting system. Problems included insufficient infrastructure security, lack of proper auditing, and opaque fund management. After discovering the theft, Mt. Gox suspended operations and filed for bankruptcy. Many users lost all their funds, and trust in cryptocurrency exchanges was seriously undermined. This incident became a turning point in cryptocurrency history and led to stricter security measures in the industry.
Coincheck, a Japanese cryptocurrency exchange, was attacked, resulting in the theft of 534 million dollars in NEM tokens. The attackers gained access to the exchange's hot wallets through compromise of private keys. The attack was possible due to insufficient infrastructure security and lack of proper protection of private keys. Coincheck stored all funds in hot wallets, making them vulnerable to attacks. After discovering the attack, the exchange suspended operations and began an investigation. Fortunately, Coincheck was able to cover losses from its own funds, and clients were not affected. However, the incident led to stricter regulation in Japan and strengthened security measures in the cryptocurrency industry.
Bithumb, a South Korean cryptocurrency exchange, was attacked, resulting in the theft of 31 million dollars. The attackers gained access to the exchange's hot wallets through compromise of private keys. The attack was possible due to insufficient infrastructure security and lack of proper protection of private keys. The attackers were able to bypass the multi-level security system and gain access to client funds. After discovering the attack, Bithumb suspended operations and began an investigation. The exchange covered losses from its own funds, but the incident undermined user trust. After the attack, Bithumb strengthened security measures and increased the share of funds in cold wallets.
Upbit, a South Korean cryptocurrency exchange, was attacked, resulting in the theft of 49 million dollars in Ethereum. The attackers gained access to the exchange's hot wallets through compromise of private keys. The attack was possible due to insufficient infrastructure security and lack of proper protection of private keys. The attackers were able to bypass the multi-level security system and gain access to client funds. After discovering the attack, Upbit suspended operations and began an investigation. The exchange covered losses from its own funds, but the incident undermined user trust. After the attack, Upbit strengthened security measures and increased the share of funds in cold wallets. This incident demonstrated the importance of proper key management and having insurance funds in the cryptocurrency industry.