CoinsPaid Hack
What happened
On July 22, 2023, CoinsPaid reported a $37.3 million theft after a months-long social-engineering campaign compromised an employee device through a fake recruitment task. CoinsPaid said the intruders used the compromised endpoint to reach internal infrastructure, exploit a cluster vulnerability, and submit fraudulent authorized withdrawal requests from hot wallets. The company said client funds remained available; no confirmed recovery of the stolen assets has been reported.
Case & protocol details
Attack Timeline
According to CoinsPaid's postmortem, attackers spent months gathering information, sending phishing and fake job offers, and attempting to gain access to the company. A critical employee installed a malicious application during a fake recruitment process. CoinsPaid says the malware exposed profiles and keys used to reach internal infrastructure, after which the attackers exploited a cluster vulnerability to establish a backdoor.
They recreated legitimate withdrawal requests, which the operational workflow treated as authorized and sent to the blockchain. CoinsPaid says the attackers did not directly obtain hot-wallet private keys. This was an endpoint, internal-infrastructure, and authorization-workflow compromise rather than a smart-contract exploit.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- analysis Website reference dlnews.com
- analysis Website reference coinspaid.com
- analysis CoinsPaid: The CoinsPaid hack explained coinspaid.com
- analysis CoinsPaid: Processing resumed after the incident coinspaid.com
- analysis Elliptic: Lazarus Group crypto-hack tactics elliptic.co
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.