Coinrail Hack
What happened
Coinrail's June 2018 exchange breach included the theft of 2.6 billion NPXS. Pundi X confirmed that the loss arose at Coinrail, rather than from a compromise of NPXS itself. Its response illustrates the limits of token freezing after stolen assets reach private wallets.
This was an exchange custody incident. The reviewed issuer statement does not identify the exchange's underlying access failure.
Case & protocol details
How it happened
- Tokens held by Coinrail were withdrawn without authorization; the initial intrusion method remains undisclosed.
- At Korean police's request, Pundi X suspended its token contract for ten days to assist the investigation.
- Some stolen NPXS was sold through IDEX on June 25 and 26. Pundi X requested suspension of trading.
- Pundi X explained that selectively freezing or burning the attacker's private-wallet balance was unavailable under the token's controls.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report coindesk.com
- report Post-mortem medium.com
- analysis Web Archive web.archive.org
- analysis An update on the Coinrail hack incident blog.pundix.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.