CoinsPaid Hack

TOTAL LOST $37.3M
High Phishing Attacks

What happened

On July 22, 2023, CoinsPaid reported a $37.3 million theft after a months-long social-engineering campaign compromised an employee device through a fake recruitment task. CoinsPaid said the intruders used the compromised endpoint to reach internal infrastructure, exploit a cluster vulnerability, and submit fraudulent authorized withdrawal requests from hot wallets. The company said client funds remained available; no confirmed recovery of the stolen assets has been reported.

Case & protocol details

Classification Ecosystem / Other / Social Engineering
Protocol Type Exploit/Other
Official Website coinspaid.com
Protocol Twitter/X @coinspaid

Attack Timeline

According to CoinsPaid's postmortem, attackers spent months gathering information, sending phishing and fake job offers, and attempting to gain access to the company. A critical employee installed a malicious application during a fake recruitment process. CoinsPaid says the malware exposed profiles and keys used to reach internal infrastructure, after which the attackers exploited a cluster vulnerability to establish a backdoor.

They recreated legitimate withdrawal requests, which the operational workflow treated as authorized and sent to the blockchain. CoinsPaid says the attackers did not directly obtain hot-wallet private keys. This was an endpoint, internal-infrastructure, and authorization-workflow compromise rather than a smart-contract exploit.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.