CSIDB logo
Incident

CoinDCX

Incident posture

Attack window
Jul 2025
Location
India
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 02:48

Linked entities

Victim
CoinDCX
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jul 2025
Discovered
Undetermined
Disclosed
Jul 2025
Resolved
Pending

Summary

CoinDCX suffered a major security breach that compromised an internal operational wallet, leading to the theft of approximately US$44.2 million while customer funds remained secure in cold storage. Blockchain analysis showed the attackers initiated the move by sending one ETH from Tornado Cash, then used Solana wallets and transferred value to Ethereum via the Wormhole Bridge and Jupiter Swap Aggregator. Two wallets holding the stolen assets are still traceable, containing about 155,830 SOL valued at roughly US$27.6 million and 4,443 ETH valued at about US$15.7 million. The breach was not detected until roughly seventeen hours after a public disclosure by a blockchain researcher. In response, the exchange announced a bounty programme that could pay up to 25% of any recovered funds. The exchange stated it continues to operate normally and remains financially stable.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On 19 July 2025 CoinDCX, India’s largest cryptocurrency exchange, experienced a security breach that resulted in the loss of approximately US$44.2 million (about Rp700 billion) from an internal operational wallet used for liquidity provision. The attack occurred between 16 and 19 July 2025, with the hackers infiltrating the exchange’s liquidity infrastructure and siphoning funds in under five minutes. News of the breach did not become public until roughly 17 hours later when blockchain researcher ZachXBT disclosed it via his Telegram channel. CoinDCX CEO Sumit Gupta subsequently confirmed on platform X that an internal account had been compromised while emphasizing that all customer assets remained secure because they were stored separately in cold wallets. Gupta stated that the exchange’s priority was identifying and apprehending the perpetrators rather than recovering the stolen funds.

The attackers began their transaction chain by sending one ether from Tornado Cash, a mixer that has processed over US$7 billion since 2019, then moved funds through Solana wallets before transferring them to Ethereum using the Wormhole Bridge and Jupiter Swap Aggregator. Blockchain analysis revealed two primary wallets still holding the stolen assets: a Solana wallet containing 155,830 SOL valued at roughly US$27.6 million and an Ethereum wallet holding 4,443 ETH valued at about US$15.7 million. The delayed detection was attributed to the use of legitimate credentials, which allowed the malicious activity to blend with normal operations and avoid immediate suspicion. Cybersecurity expert Deddy Lavid of CyVers Security suggested that exposed internal credentials likely facilitated the initial access, granting the attackers sufficient operational rights to execute large transactions without triggering alerts.

In response, CoinDCX launched a bounty programme on 21 July 2025 offering up to 25 % of any recovered assets, potentially amounting to as much as US$11 million. The exchange affirmed that it remained fully operational and financially stable despite the incident. Industry observers noted that while the breach exposed vulnerabilities in internal systems, the separation of operational and customer wallets demonstrated a layered security approach that could serve as a model for other platforms. Broader data indicated that crypto theft losses in the first half of 2025 had already exceeded US$2.17 billion, surpassing the total for 2024, and that recovery rates remained low with less than 8 % of the estimated US$2.5 billion stolen being retrieved.

Sources

Sources available to members: 1 source.

CSIDB