FixedFloat Hack
What happened
FixedFloat's February 2024 breach drained Bitcoin and Ethereum worth approximately $26 million from its operational wallets. FixedFloat attributed the theft to weaknesses in its service infrastructure and said the stolen assets belonged to the service.
FixedFloat described flaws and insufficient protection in its infrastructure that exposed service functions. It did not identify the precise initial-access vulnerability or credential failure.
How it happened
- An external attacker compromised FixedFloat's infrastructure and gained access to service functions, according to the operator.
- Bitcoin and Ethereum were transferred from operational wallets to attacker-controlled addresses.
- FixedFloat entered maintenance mode and subsequently confirmed the theft.
Protocol details
Post-Incident Timeline
-
2024-04-02
Apr 2, 2024 $2.8M was withdrawn from FixedFloat's hot wallet on the $ETH chain. FixedFloat team has announced that "On April 1, we were again attacked by the attackers who were behind the February 16 hack. The attackers did not stop there and continued to use various methods to try to hack our service again."
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.