FixedFloat Hack

Reported loss $26.1M
Bitcoin Ethereum
Private Key Compromised

What happened

FixedFloat's February 2024 breach drained Bitcoin and Ethereum worth approximately $26 million from its operational wallets. FixedFloat attributed the theft to weaknesses in its service infrastructure and said the stolen assets belonged to the service.

Technical root cause

FixedFloat described flaws and insufficient protection in its infrastructure that exposed service functions. It did not identify the precise initial-access vulnerability or credential failure.

How it happened

  1. An external attacker compromised FixedFloat's infrastructure and gained access to service functions, according to the operator.
  2. Bitcoin and Ethereum were transferred from operational wallets to attacker-controlled addresses.
  3. FixedFloat entered maintenance mode and subsequently confirmed the theft.

Protocol details

Classification Infrastructure / Frontend & Infrastructure / Exchange (DEX)
Protocol Type Exploit/Access control
Protocol links Website @FixedFloat

Post-Incident Timeline

  • 2024-04-02

    Apr 2, 2024 $2.8M was withdrawn from FixedFloat's hot wallet on the $ETH chain. FixedFloat team has announced that "On April 1, we were again attacked by the attackers who were behind the February 16 hack. The attackers did not stop there and continued to use various methods to try to hack our service again."

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.