FixedFloat Hack

Reported loss $3.0M
Key Leaked via Infrastructure

What happened

On March 31, 2024, the instant crypto exchange FixedFloat lost roughly $2.8 million to $3 million from its Ethereum hot wallet, about six weeks after a much larger February 2024 breach. Cyvers flagged withdrawals of ETH, USDT, WETH, DAI and USDC and put the loss at $2.8 million; CertiK told CoinDesk about $3 million moved across Ethereum and Tron. The attacker swapped the tokens to ETH on a DEX and sent most of it to the eXch exchange, with about $100,000 in USDT going to a Binance deposit address on Tron. Tether blocklisted ten addresses tied to the withdrawals, freezing about $400,000 in USDT.

FixedFloat first called it "minor technical problems" and paused service. In a June 2024 statement it said the same attacker behind the February breach struck again on March 31, after gaining unauthorized access across all of its servers hosted with the third-party provider Time4VPS. FixedFloat dropped Time4VPS, rebuilt its infrastructure and suspended operations for about two months.

How it happened

  1. The attacker gained unauthorized access to every FixedFloat server hosted at Time4VPS, a third-party VPS provider where some of the exchange's nodes and subsystems still ran (per FixedFloat).
  2. Using that access, the attacker withdrew ETH, USDT, WETH, DAI and USDC from FixedFloat's Ethereum hot wallet.
  3. The stolen tokens were swapped to ETH through a DEX and most of the value was sent to the eXch exchange; about $100,000 in USDT went to a Binance deposit address on Tron.
  4. Tether blocklisted ten addresses linked to the withdrawals, freezing about $400,000 in USDT.

Protocol details

Classification Frontend & Infrastructure
Protocol Type CEX

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.