CoinDCX's $44.3 Million Breach Went Unannounced for 17 Hours
India's second-largest crypto exchange, CoinDCX, lost $44.3 million to attackers who spent days preparing the operation before draining its wallets — and the company said nothing publicly for roughly 17 hours, until on-chain investigator ZachXBT surfaced the activity himself.
Of the total taken, $28.3 million was in SOL and $15.78 million in ETH, both funneled toward mixing services. CoinDCX's executives did not comment during the intervening period. Once the exchange did respond, its statements leaned on now-familiar language: a "sophisticated" breach of a server, funds drawn from treasury reserves, and assurances that customer holdings were untouched — while sidestepping the fact that the public first learned of the incident from an outside researcher rather than the company itself.

How the discovery unfolded
ZachXBT was not specifically targeting CoinDCX; he was tracing a lead that security firm Cyvers had already flagged involving unusual withdrawals from a wallet with no public tag attached to the exchange.
At 14:41 UTC on July 19, ZachXBT posted in his Telegram channel that CoinDCX appeared to have been drained of roughly $44.2 million about 17 hours earlier and had not yet disclosed anything to its users.
Tracing back, the first attacker transaction touched CoinDCX's Solana wallet on July 18 at 23:22 UTC, moving out roughly $4.3 million. The transaction can be viewed here: 5mPfNreuEeNanMoxCtGuWWgw1pbpM7SXC7ZZJH9Z6qeGq7YgEsNPmXrZKhnJezFHZFcdronZJKaoGieXcg4S9sqx.
According to ZachXBT's tracing, the attacker's funding trail began with 1 ETH sourced from Tornado Cash, after which the stolen assets were split across multiple Solana addresses and later bridged to Ethereum. Because the compromised wallet had never been publicly labeled or listed among CoinDCX's proof-of-reserves addresses, investigators had to identify it manually through counterparty analysis.
The sequence of events — an attack late Friday, fund movement continuing into Saturday, and no word from the exchange until it was publicly called out — meant that CoinDCX's disclosure arrived nearly a full day after the theft began, and only after external pressure forced the issue.
A response that arrived in minutes, not hours
Notably, once ZachXBT's post went out at 14:41 UTC on July 19, CoinDCX CEO Sumit Gupta responded publicly just seven minutes later, at 14:48 UTC, with a statement asserting the company's commitment to transparency.
Gupta's statement described a "sophisticated server breach," noted that operational accounts were segregated from customer wallets, referenced treasury reserves covering the shortfall, and stated that no customer funds were affected. It did not address why customers had learned of the incident from social media rather than from CoinDCX directly.
An hour after that, at 16:41 UTC, co-founder Neeraj Khandelwal posted that Portfolio APIs were experiencing issues due to heavy platform load. Two minutes later, Gupta added a similar message, appending "PS: Customer assets remain safe!"
ZachXBT was unpersuaded by the exchange's messaging, writing in response that CoinDCX's team had waited 17 hours to disclose the incident and only did so after being publicly alerted. He also noted reports that members of the exchange's community team had asked users on Discord to thank Gupta for his transparency.
Signs of a planned operation
Evidence suggests the attack was not opportunistic but planned over several days. On July 16, 1 ETH left Tornado Cash and was routed through FixedFloat, then Polygon, before being bridged to Solana via deBridge. That funding transaction is recorded here: 0x90083b839d093536104efb592aa46847993dca26a9410faac99aad4ec236f41b.
July 17 appears to have been used for infrastructure setup and testing. On July 18 at 21:07 UTC, a single test transaction in USDT preceded the main event. Then, between 22:09 and 22:14 UTC that same day, a rapid sequence of withdrawals moved funds out in quick succession: $2 million, $7 million, $10 million, $10 million, two separate $5 million transfers, and a final $5 million withdrawal.
The stolen assets ended up spread across several addresses:
- Solana address #1: 6peRRbTz28xofaJPJzEkxnpcpR5xhYsQcmJHQFdP22n
- Solana address #2: 3btch8cSVp3Uh2SiY9DeiRNYUBmFiBNHZQzDyecJs7Gu
- Ethereum address holding approximately $44.3 million as of July 22: 0xEF0c5b9E0E9643937D75C229648158584A8CD8D2

A full breakdown of the fund movements is available via Breadcrumbs. The precision and pacing of the withdrawals point to an attacker with detailed knowledge of CoinDCX's internal wallet structure.
A bounty, and a familiar pattern
The following Monday, CoinDCX announced a recovery bounty: up to 25% of any recovered funds would go to individuals or teams who helped trace and retrieve the stolen assets. Gupta said identifying and catching the attackers mattered more than recovering the funds themselves. Co-founder Neeraj Khandelwal echoed the bounty announcement and thanked several security firms and foundations for their assistance.
CoinDCX has stated that its $538.35 million in reserves will absorb the loss, and both executives maintained that the incident did not affect customers or platform operations.
This is the second major breach at a leading Indian exchange in roughly a year: in July 2024, WazirX lost $235 million and likewise delayed public disclosure until external pressure mounted. In both cases, attackers executed methodically over several days while the exchanges stayed quiet until outside investigators forced their hand.
Some analysts, citing the operation's cross-chain laundering and precise execution, have suggested the Lazarus Group could be involved, the same state-sponsored group linked to numerous exchange breaches globally. CoinDCX has not confirmed or ruled out this attribution, nor commented on whether an internal investigation into potential insider involvement is underway.
Get new scam files the moment we publish them — usually 2–3 emails a week.