Deribit's Hot Wallets Drained of $28M Across Ethereum and Bitcoin
Deribit, which markets itself as the world's largest Bitcoin and Ethereum options exchange, confirmed the loss of $28 million from hot wallets spanning both the Ethereum and Bitcoin networks.
In an official statement, the exchange said the shortfall would be covered by its own reserves, and noted that 99% of user funds are kept in cold storage specifically to limit exposure in events like this one.

Withdrawals were paused immediately afterward. A subsequent update told users that on-chain deposit addresses for BTC, ETH, and USDC were being regenerated, rendering any previously issued addresses invalid.
As with most disclosures framed around "compromised keys," only Deribit's internal team can say precisely how the breach happened. If phishing turns out to be the vector, attention would likely turn to the usual names associated with such campaigns.
The losses were roughly split between the two chains. On Ethereum, the affected hot wallet lost 6,968 ETH along with 3.4 million USDC, while the Bitcoin hot wallet lost 691 BTC.
Attacker's ETH address: 0xb0606f433496bf66338b8ad6b6d51fc4d84a44cd
Attacker's BTC address: bc1qw5g8lw4kzltpdcraehy2dt6dqda8080xd6vhl4kg4wwsypwerg9s3x6pvk
Both addresses still hold the stolen funds untouched, leaving room for a possible negotiated settlement.
That dormant balance invites comparison to the 5:5 bounty framework SBF had recently proposed as an industry standard — SBF — which in this case would put roughly $1.4 million on the table for the attacker against the full $28 million taken. Whether the attacker would prefer a $1.4 million settlement over holding onto $28 million remains to be seen.

The incident arrives roughly a year after a run of centralized exchange breaches tied to compromised hot wallets — Bitmart ($196M), Ascendex ($78M), and Crypto.com ($34M) among them. Attention later moved toward bridge exploits, populating the leaderboard with names like Ronin, BNB, Wormhole, Nomad, and Harmony — several of which have since been tied to North Korea's state-sponsored Lazarus Group.
Should this attack ultimately trace back to the same group, recovery of the funds would be unlikely. The scale of what North Korea has historically done with proceeds from such hacks underscores why attribution matters here.
Of the $5.2 billion currently tracked on the leaderboard, it's impossible to say with certainty how much has flowed to state-sponsored actors. This incident puts Deribit at #32 on that list.
Get new scam files the moment we publish them — usually 2–3 emails a week.