CoinDCX Hack
What happened
On July 19, 2025, CoinDCX reported that an internal operational account used for liquidity provisioning on a partner exchange was compromised. The company estimated exposure at about $44 million, said customer assets in segregated cold wallets were unaffected, and committed to absorb the loss from treasury reserves.
The documented failure was compromise of an operational account in a partner-liquidity workflow, not a customer-wallet smart-contract exploit. CoinDCX’s public incident report does not identify the server vulnerability, credential theft path or attacker identity.
Case & protocol details
How it happened
- A server breach compromised an internal liquidity account.
- Approximately $44 million in USDT and other assets were routed through multiple addresses.
- CoinDCX isolated the account and continued protecting customer wallets in separate custody systems.
- The company said it was working with cybersecurity firms and law enforcement to trace funds.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report CoinDCX incident report: July 19, 2025 coindcx.com
- analysis Website reference crypto.news
- analysis Website reference bitcoinsensus.com
- analysis CoinDCX transparent security update coindcx.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.