CoinStats Hack

Reported loss $2.2M
Private Key Compromised (Unknown Method)

What happened

On June 22, 2024, CoinStats detected an active attack on its infrastructure. The attacker extracted private keys for 1,590 CoinStats Wallets, about 1.3% of all such wallets, and stole about $2.2 million. CEO Narek Gevorgyan said the AWS infrastructure was likely breached through an employee who had been socially engineered into downloading malicious software onto a work computer. CoinStats' July 12 incident report says the attackers reached parts of its infrastructure and third-party providers, including a HashiCorp Vault that stored 2FA keys and wallet APIs. Some affected users had received messages in the app pointing to a malicious website, though not every victim got one. SecurityWeek reported that $800,000 of the loss came from two wallets that had imported their seed phrases into CoinStats Wallet. Connected wallets (such as MetaMask or Phantom) and exchange accounts were not affected, because CoinStats had only read-only access to them. CoinStats shut the platform down, rebuilt its production environment from scratch, notified the FBI and fully restored service on July 3. It attributed the attack to the Lazarus Group or a related organization.

Example theft transaction: 0x8d0360632bc385171e20c12aa3152933bb041402bb3e06ab29136985a4745e57

How it happened

  1. According to the CEO, a CoinStats employee was socially engineered into running malicious software on a work computer, which gave the attacker a foothold in the company's AWS environment.
  2. From there the attacker reached more internal systems and third-party services, including a HashiCorp Vault that held 2FA keys and wallet APIs.
  3. Using that access, the attacker extracted private keys for 1,590 CoinStats-hosted wallets and moved about $2.2 million out of them.
  4. CoinStats detected the attack on June 22 and shut down the platform, which limited how many wallets were drained.

Protocol details

Classification Infrastructure / Social Engineering / Other
Protocol Type Exploit/Phishing
Protocol links Website @CoinStats

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.