CoinDCX Hack

REPORTED LOSS $44.2M
High Access Control

What happened

On July 19, 2025, CoinDCX reported that an internal operational account used for liquidity provisioning on a partner exchange was compromised. The company estimated exposure at about $44 million, said customer assets in segregated cold wallets were unaffected, and committed to absorb the loss from treasury reserves.

Technical Root Cause

The documented failure was compromise of an operational account in a partner-liquidity workflow, not a customer-wallet smart-contract exploit. CoinDCX’s public incident report does not identify the server vulnerability, credential theft path or attacker identity.

Case & protocol details

Classification Infrastructure / CeFi / Key Compromise
Protocol Type CEX
Official Website coindcx.com/
Protocol Twitter/X @CoinDCX

How it happened

  1. A server breach compromised an internal liquidity account.
  2. Approximately $44 million in USDT and other assets were routed through multiple addresses.
  3. CoinDCX isolated the account and continued protecting customer wallets in separate custody systems.
  4. The company said it was working with cybersecurity firms and law enforcement to trace funds.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.