CoinDeal Hack
Incident Overview
The U.S. Securities and Exchange Commission charged individuals and companies involved in the fraudulent investment scheme CoinDeal that raised over $45 million from sales of unregistered securities to investors, alleging that the defendants enriched themselves while defrauding tens of thousands of retail investors.
Six people and two companies involved in a fraudulent investment scheme named CoinDeal that raised over $45 million from sales of unregistered securities to thousands of investors worldwide have been charged by the Securities and Exchange Commission (SEC). The SEC alleges that Neil Chandran, Garry Davidson, Michael Glaspie, Amy Mossel, and Linda Knott falsely claimed that investors could generate returns by investing in a blockchain technology company named CoinDeal that was sold for trillions of dollars. The SEC says that the defendants collectively misappropriated millions of dollars of investor funds for personal use, and Chandran used investor funds to purchase items such as cars, real estate, and a boat.
The SEC seeks to reclaim the money allegedly stolen by the defendants along with pre-judgment interest, penalties, and permanent injunctions against all defendants. Chandran is already behind bars, awaiting trial in a separate investment fraud case under the U.S. Justice Department.
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to CoinDeal, these are the critical security checks that could have prevented this incident (January 2023).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next CoinDeal
The CoinDeal hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.