LCX Hot Wallet Compromised in $7.94M Private Key Breach
LCX has become the latest centralized exchange to suffer a private-key compromise, with $7.94M drained from its hot wallet.
The intrusion began around 10:30 PM UTC on January 8th. Peckshield was the first to identify the activity, and an official statement from LCX followed shortly afterward.

It's a familiar refrain by now, echoing prior incidents at Bitmart and AscendEX: when firms holding millions of dollars in customer funds repeatedly fail at basic hot-wallet key security, it raises questions about what value centralized custody is actually providing. The case for CeFi keeps getting thinner.
01The numbers
LCX's official incident report confirmed $7.94M in total losses and stated that deposits and withdrawals to the platform had been paused.
- LCX hot wallet: 0x4631018f63d5e31680fb53c11c9e1b11f1503e6f
- Attacker's wallet: 0x165402279f2c081c54b00f0e08812f3fd4560a05
Assets taken:
- 162.68 ETH ($502,671)
- 3,437,783.23 USDC ($3,437,783)
- 761,236.94 EURe ($864,840)
- 101,249.71 SAND ($485,995)
- 1,847.65 LINK ($48,557)
- 17,251,192.30 LCX Token ($2,466,558)
- 669.00 QNT ($115,609)
- 4,819.74 ENJ ($10,890)
- 4.76 MKR ($9,885)
Roughly $1M in LCX Token remains sitting in the attacker's address, alongside 611,000 EURe that Monerium has since frozen. The remainder — 1,891 ETH, worth approximately $6M — was routed through Tornado Cash.

02The recurring question
Why do these firms keep failing to keep private keys private? It's a fair question whether standard corporate security practices are really that hard to implement and maintain.
With CeFi incidents like this, outside observers are left largely dependent on whatever the team involved chooses to disclose. Perhaps, going forward, breached exchanges should just draft their own incident reports from a template — there's little more to add each time.
Get new scam files the moment we publish them — usually 2–3 emails a week.