Coinrail Hack

REPORTED LOSS $40.0M
High Exchange compromise; initial access unknown ethereum

What happened

Coinrail's June 2018 exchange breach included the theft of 2.6 billion NPXS. Pundi X confirmed that the loss arose at Coinrail, rather than from a compromise of NPXS itself. Its response illustrates the limits of token freezing after stolen assets reach private wallets.

Technical Root Cause

This was an exchange custody incident. The reviewed issuer statement does not identify the exchange's underlying access failure.

Case & protocol details

Classification CeFi / Access Control
Protocol Type Exploit/Access control
Official Website coinrail.co.kr/
Protocol Twitter/X @coinrail_korea

How it happened

  1. Tokens held by Coinrail were withdrawn without authorization; the initial intrusion method remains undisclosed.
  2. At Korean police's request, Pundi X suspended its token contract for ten days to assist the investigation.
  3. Some stolen NPXS was sold through IDEX on June 25 and 26. Pundi X requested suspension of trading.
  4. Pundi X explained that selectively freezing or burning the attacker's private-wallet balance was unavailable under the token's controls.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.