Cyber Incident Victim: Cryptopia Limited
Date:
Jan 2019
Location:
New Zealand
Summary
A New Zealand-based cryptocurrency exchange suffered a security breach, prompting an immediate shutdown of services for damage assessment and unscheduled maintenance. Trading remains suspended while authorities, including local police and the High Tech Crimes Unit, investigate the incident; reports indicate unusual token transfers occurred prior to the breach, though their connection remains unconfirmed. The extent of losses, cause, and responsible parties were undisclosed at the time, with the exchange committing to ongoing updates during the resolution process.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 15, 2019, New Zealand-based cryptocurrency exchange Cryptopia publicly announced it had suffered a security breach, prompting an immediate shutdown of its platform. The exchange first detected the incident on Monday, January 14, according to its Twitter communications, though the exact timing of the initial compromise remained unspecified. Upon discovery, Cryptopia's staff took services offline, citing 'unscheduled maintenance' on its website homepage while initiating damage assessments. Trading services were suspended indefinitely during this period, with the exchange pledging regular updates to users throughout the recovery process. Cryptopia did not disclose technical details regarding the breach vector, attacker entry points, or compromised systems at this initial stage. Concurrently, New Zealand Police and the High Tech Crimes Unit launched an investigation into the incident, though no suspects or attribution details were released.

Independent blockchain monitoring firm Whale Security observed unusual transaction patterns over the preceding weekend, including transfers of Centrality (CENNZ) tokens and Ethereum, though no confirmed link to Cryptopia's breach was established. The exchange did not quantify financial losses or specify which digital assets were impacted, leaving the scale of customer fund exposure unclear. Cryptopia maintained its commitment to resolving the situation but provided no timeline for service restoration or further technical disclosures. The incident marked a sustained operational disruption, with the platform remaining offline beyond the initial announcement date as investigations continued without public conclusions regarding culprits or security failure origins.
