Cyber Incident Victim: DragonEx
Date:
Mar 2019
Location:
Singapore
Summary
A Singapore-based cryptocurrency exchange suffered a security breach where attackers stole over $1 million in digital assets, transferring portions to other platforms. While partial recovery was achieved, not all funds were retrieved. The incident prompted the platform to enter maintenance mode for infrastructure enhancements and investigation, with assistance from authorities in multiple jurisdictions. The breach resulted in significant financial losses and operational disruption.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 24, 2019, Singapore-based cryptocurrency exchange DragonEx suffered a cybersecurity breach resulting in the theft of digital assets. The exchange publicly acknowledged the incident through a message posted on its English Telegram channel, confirming that attackers had compromised part of its funds. According to the announcement, hackers transferred stolen cryptocurrency to other exchanges following the breach. DragonEx reported recovering some funds through collaborative efforts with these platforms, though a portion remained unrecovered. Industry observers estimated losses exceeding $1 million USD worth of cryptocurrency, though the exchange did not disclose official figures. The attack prompted DragonEx to enter maintenance mode, suspending normal operations to investigate the intrusion and implement infrastructure improvements.

The incident triggered a multinational investigation involving authorities from Estonia, Thailand, Singapore, and Hong Kong. DragonEx did not specify which systems or operational components were compromised during the attack, nor did it describe the exact method of intrusion. The exchange maintained limited public communication, failing to respond to media inquiries from outlets including ZDNet. While partial fund recovery was achieved, the breach caused operational disruption through extended platform downtime. The financial impact remained unquantified by the exchange itself, relying instead on external estimates of losses. No user data exposure was mentioned in available reports, with the incident appearing confined to asset theft from exchange-controlled wallets.
