CoinEx Hot Wallets Drained of $54.3M Across Thirteen Chains
Exchange CoinEx had its hot wallets emptied across thirteen different blockchains, with losses eventually totaling $54.3 million — a notable contrast to the exchange's own homepage claim of being "secure and safeguarded with 0 incident."
The attack began with a transfer of nearly 4,950 ETH, worth roughly $8 million, at 1:20:59 PM UTC. Wallets were then rapidly emptied of ETH, TRON, and MATIC, followed by other holdings, which were subsequently swapped into native assets and moved on to new addresses over the following hours.

CoinEx acknowledged the incident roughly four hours after it began, though that initial post was later deleted and replaced with a message conveying greater urgency. The exchange told users it had a "special investigative team" reviewing the matter, characterized the missing funds as "just a very small portion of CoinEx's total asset," and pledged that losses would be covered. Deposits and withdrawals were suspended. CoinEx has not disclosed how the breach occurred but said a detailed timeline and report would follow.
As with the Stake hack roughly a week earlier — a $40 million-plus incident the FBI later attributed to DPRK-linked Lazarus Group hackers — the suspicious CoinEx outflows were first flagged by Cyvers. Subsequent analysis has pointed toward Lazarus Group involvement in this incident as well, marking a possible second major exchange hit attributed to the group within two weeks.
Where the funds went
Attackers withdrew a combined $54.3 million spread across the following addresses:
- ETH 1 ($10.4M): 0x8bf8cd7F001D0584F98F53a3d82eD0bA498cC3dE
- ETH 2 ($2.3M): 0x483D88278Cbc0C9105c4807d558E06782AEFf584
- ETH 3 ($5.3M): 0xCC1AE485b617c59a7c577C02cd07078a2bcCE454
- TRON ($11.5M): TPFUjxQzG88Vwynrpj2W61ZAkQ9W2QYgAQ
- BSC ($6.3M): 0x6953704e753C6FD70Eb6B083313089e4FC258A20
- XRP ($6M): rpQxVcjVF2fC23r3xKyJS53jw8d5SRhZQf
- BTC ($5.2M): 1DSvdmVZGKpCxAR4XexkywxM1whbcvHzbA
- SOL ($2.5M): G3udanrxk8stVe8Se2zXmJ3QwU8GSFJMn28mTfn8t1kq
- XDAG ($1.7M): 15VY3MadZvLpXhjzFXwCUmtZcHszju6L9
- KDA ($1.1M): k:a9f3672d7ad7a1e4592702d73b220cbc61db1fa17f89a56131d965bc03959913
- ARB ($520k): 0xfEec9F846E2FE529B765d832EBa988a399Fe3cD6
- XLM ($500k): GBPIDVKDSNF74OAGVBSPKLW73CSCGISBOBRB3ODROTMOEENZFC6WJFPN
- BCH ($400k): qrgxyhj8rzl4l7fgauu6q6vtu2grct4jeyrnaq2s75
- MATIC ($300k): 0x4515bE0067E60d8e49b2425D37e61c791C9B95e9
- OP ($260k): 0x964c192e54E5eF4176626875BB53071956579fca
Funds still held in CoinEx's remaining hot wallets appear to be consolidating in a multisig address that currently holds more than $70 million.
Tracing the trail

As additional wallets were identified and losses tallied, several associated addresses were linked to exchanges and Twitter accounts. However, given the prevalence of KYC-verified accounts sold for reuse and outsourced scam operations among organized cybercrime groups, such links rarely produce real consequences.
One notable overlap: an OP address tied to this incident matched a MATIC address used in the previous week's Stake casino breach, reinforcing the suspected Lazarus Group connection. Observers note that the group has remained highly active while much of the wider crypto market has grown comparatively complacent about security risks.
Centralized exchanges are generally positioned as a safer alternative to holding assets on-chain, yet incidents like this one raise the question of how often key compromises occur at platforms managing hundreds of millions of dollars in user funds. As was noted after the Stake hack the previous week, centralized platforms arguably warrant a higher security standard than they have so far demonstrated.
Get new scam files the moment we publish them — usually 2–3 emails a week.