CSIDB logo
Incident

Phemex

Incident posture

Attack window
Jan 2025
Location
Singapore
Status
Historical
CIA posture
Available to members
Updated
2026-09-03 10:32

Linked entities

Victim
Phemex
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Jan 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A suspected cyberattack on Singapore-based cryptocurrency platform Phemex forced the company to pause some operations after blockchain security firms observed millions of dollars in digital assets flowing out of the platform. Researchers at Cyvers initially detected suspicious transactions involving $29 million worth of cryptocurrency, while a final tally from PeckShield confirmed losses exceeding $69 million across ETH, Bitcoin, Binance coin, and other tokens. The exchange's CEO stated that withdrawals were being restored and manually processed due to the sophistication of the threat actor, while the company took a snapshot of user balances and announced a forthcoming compensation plan. Several experts cited the technical sophistication and fund movement patterns as indicative of experienced actors, with some pointing to North Korean government hackers. Phemex, which holds operational approvals in the U.S., Canada, Turkey, and Lithuania and serves over five million users, continued trading services despite the disruption.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Thursday, January 23, 2025, the Singapore-based cryptocurrency exchange Phemex was hit by a suspected cyberattack that resulted in the theft of more than $69 million in digital assets and forced the platform to suspend portions of its operations. The incident began in the morning hours when multiple blockchain security firms began observing large, anomalous outflows of funds from Phemex-controlled wallets. Researchers at the blockchain security company Cyvers were the first to flag the activity, initially identifying suspicious transactions involving roughly $29 million in cryptocurrency leaving the platform. As the day progressed, additional investigators tracked further movements, and PeckShield, another blockchain analytics firm, provided Recorded Future News with a final tally showing that more than $69 million worth of assets — including Ether (ETH), Bitcoin, Binance Coin, and other cryptocurrencies — had been siphoned out of the exchange. The pattern and speed of the withdrawals, along with the technical characteristics of how the funds were moved, drew the attention of multiple external analysts who reviewed the on-chain activity.

Phemex's leadership publicly acknowledged the breach on Friday morning. CEO Federico Variola issued statements indicating that the platform was in the process of restoring withdrawal functionality and that, in the interim, all withdrawal requests would be processed manually while the team conducted reviews to ensure the integrity of remaining balances. He noted that testing of the system was taking longer than initially anticipated, attributing the delay to what he described as the sophistication of the threat actor involved. The company also announced that it had taken a snapshot of all user balances as of 12:00 p.m. UTC, framing the measure as a way to recognize user loyalty, and stated that additional details regarding a compensation plan would be communicated in the near term. On social media, Phemex and its development team issued an apology for the disruption and reaffirmed that the company's broader mission of providing a trusted trading environment remained intact. The platform indicated that ongoing business operations were functioning and that trading services were continuing as usual despite the incident.

The breach had immediate operational and reputational consequences for Phemex. The platform, which stated it holds regulatory approvals to operate in the United States, Canada, Turkey, and Lithuania, and which reported having more than five million users worldwide, was forced to freeze or restrict certain withdrawal functions while security reviews were carried out. Customers experienced delays in accessing their funds, and the company publicly committed to a compensation plan for affected users, though specific terms were not disclosed at the time of the reports. Subsequent coverage of the broader cryptocurrency theft landscape in 2025 referenced the Phemex incident as a significant event, with one industry summary citing losses of "more than $73 million" from the exchange, reflecting a slightly higher figure than the initial $69 million tally as additional analysis accounted for the full scope of the stolen assets.

External experts who reviewed the attack provided commentary on its likely origin. Several analysts who spoke to cryptocurrency news outlet The Block pointed to the technical sophistication of the intrusion and the manner in which the funds were drained from the platform as indicators that it was carried out by experienced, well-resourced actors. At least two of those experts specifically named North Korea as a likely suspect, aligning the Phemex breach with a broader pattern of high-value cryptocurrency thefts attributed to government-linked hacking groups from that country. This assessment was consistent with warnings issued just days earlier by the United States, Japan, and South Korea, which released a joint statement cautioning the cryptocurrency industry that North Korean actors would continue to target digital asset platforms in 2025. The joint statement referenced prior headline-making incidents, including the $308 million theft from DMM Bitcoin and the $235 million theft from WazirX, both of which occurred in 2024. The three governments expressed a shared objective of preventing thefts from private industry, recovering stolen funds where possible, and denying North Korea illicit revenue that could fund its weapons of mass destruction and ballistic missile programs.

Industry data placed the Phemex attack within a wider trend of escalating cryptocurrency thefts. Chainalysis reported that hacking groups connected to the North Korean government stole approximately $1.34 billion across 47 incidents during 2024. United Nations experts were also investigating 58 cyberattacks on cryptocurrency firms allegedly conducted by North Korean hackers, which collectively generated an estimated $3 billion over a six-year period. The Phemex breach was not an isolated case affecting Singapore-based platforms: within the preceding six months, two other Singapore-headquartered cryptocurrency firms — Penpie and BingX — had been attacked. In September 2024, nearly $30 million was stolen from Penpie, while $44 million was taken from BingX. When year-end totals for 2025 were compiled by firms such as Chainalysis, TRM Labs, and the Web3 security company De.Fi, the Phemex hack was listed among the year's most serious incidents alongside other major events, including a $223 million theft from the decentralized exchange Cetus and approximately $128 million in losses from an attack on the Balancer protocol. The cumulative stolen value across 2025 reached an estimated $2.7 billion, described in industry coverage as a record high in the history of crypto-asset-related incidents, with North Korean government hackers accounting for at least $2 billion of that total according to analyses from Chainalysis and Elliptic.

Sources

Sources available to members: 2 sources.

CSIDB