CryptoReal
CASE FILE — Sep 25, 2023

$200M Vanishes From Mixin Network After a Cloud Database Breach

Mixin Network disclosed a $200 million loss on the morning of September 25, 2023, tied to an attack that had actually taken place two days earlier, on Saturday. A few hours after that announcement, the Hong Kong-based project told users via livestream that only 50% of assets were guaranteed to be safe, according to reporting from The Block. An English-language summary of that livestream, which the team had promised, had not yet appeared at time of writing.

A nine-figure loss at a platform many outside certain regions had barely heard of recalls Poly Network's leaderboard-topping incident from August 2021, and underscores how disconnected crypto communities in different parts of the world can be from one another.

Despite describing itself as "decentralised," Mixin Network attributed the losses to a breach at a third-party database provider — an explanation that raises more questions than it answers.

What's known so far

The precise mechanism by which the funds were extracted has not been disclosed. Mixin's own statement placed the blame elsewhere:

the database of Mixin Network's cloud service provider was attacked by hackers, resulting in the loss of some assets on the mainnet

The transactions themselves look like ordinary transfers, which points toward a leak of private keys belonging to Mixin users and stored on that cloud service. BlockSec has suggested that some of the drained addresses may in fact have belonged to Mixin's own hot wallets.

Sums referenced in this case file

The assets identified as stolen so far are entirely liquid — ETH, USDT (subsequently swapped into DAI, which cannot be frozen), and BTC — with no obscure tokens involved. Mixin says it is working with Google, presumably the cloud provider referenced in its statement, along with security firm SlowMist to investigate.

Attacker addresses identified so far (with roughly $50 million still unaccounted for), per reports:

If the $200 million figure holds up, this would rank as the largest hack of 2023 to date, surpassing the $197 million Euler Finance exploit from March (funds from that incident were eventually returned).

Because the stolen assets are still sitting in the attacker's wallets, there remains some possibility that Mixin's on-chain request for the funds to be returned — accompanied by an offered $20 million bounty — could succeed, though the decision to convert USDT into DAI is not an encouraging sign.

The pattern of this incident bears resemblance to past operations attributed to the Lazarus Group, which has been linked to a string of recent attacks including those on CoinEx, Stake, and Alphapo.

Broader context

Mixin's decision to point to a third party echoes Nansen's similar move just days earlier on Friday — both cases sidestepping one of the industry's core principles: accountability. Relying on a conventional web2 service provider to store sensitive on-chain data runs counter to much of what this industry was originally built to avoid, a point that may prompt uncomfortable questions for LayerZero given its own recent partnership with Google Cloud.

Some observers have been quick to note that this looks like a hack rather than an exploit — a failure of legacy infrastructure rather than of on-chain code — reinforcing the case for continuing to build toward more resilient, self-custodied systems. As one commentator put it: decentralization doesn't matter, until it really, really does.

Mixin Network
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.