CryptoReal
CASE FILE — Jan 24, 2025

Access-Control Failure at Phemex Bleeds $73.5M Across Nearly 30 Blockchains

Centralized exchange Phemex lost roughly $73.54 million after an attacker gained control of its hot wallet infrastructure and siphoned funds across almost thirty separate blockchains. The incident, which unfolded over the course of January 23-24, 2025, ranks among the largest centralized-exchange breaches of the year and stands out less for its size than for its reach: rather than draining a single chain, the attacker moved through Ethereum, Solana, Base, Avalanche, Bitcoin and dozens of other networks in rapid succession, often faster than the exchange's team could respond to alerts on the chain before it.

Phemex's cold storage reserves were reportedly untouched; the losses were confined entirely to hot wallets, underscoring how a single access-control failure can cascade across every chain an exchange operates on once an attacker obtains the right credentials.

01How the breach came to light

Blockchain monitoring firm PeckShield was first to flag the activity, posting about unusual outbound transfers early on January 23. Shortly after, Cyvers' detection systems picked up more than $29 million in suspicious movements spanning multiple chains — a figure that would later prove to be only a fraction of the eventual total.

Phemex confirmed the incident publicly and paused withdrawals as a containment measure. Hacken's initial security review attributed the breach to an access-control failure that gave the attacker operational control over the exchange's hot wallets across its supported networks.

MetaMask lead security researcher Taylor Monahan, speaking to The Block, pointed to the sophistication of the operation: near-simultaneous withdrawals from wallets on different chains, a deliberate pattern of swapping into assets less likely to be frozen, and execution that appeared manual rather than automated via a single script.

02Chain-by-chain breakdown

Losses were spread unevenly across networks, with Ethereum and Solana absorbing the largest shares. What follows is the confirmed breakdown, chain by chain, including the exchange's affected hot wallet, the attacker-controlled address, and (where documented) the destination of the stolen funds.

Ethereum

Solana

XRP

Bitcoin

BSC

Sui

Base

Tron

Litecoin

Avalanche

Arbitrum

Polkadot

Stellar (XLM)

Sums referenced in this case file

Polygon

Optimism

zkSync Era

03The total climbs: additional chains identified later

After the initial disclosure, on-chain investigator Tayvano reported that the losses were larger than first believed, and further affected chains were subsequently identified and tallied.

Dogecoin

Cardano

Hedera

Algorand

TON

Filecoin

XDC Network

Zcash

Cosmos

Ethereum Classic

Bitcoin Cash

Tezos

Dash

Total stolen (as adjusted on 2/3/2025): $73,540,297

As funds continued moving across chains in the days after the attack, it became apparent that the very feature Phemex had marketed — deep multi-chain support — was also what allowed the breach to spread so widely once the attacker had a foothold.

04Aftermath

Phemex maintained that customer assets held in cold storage were unaffected and said a compensation plan for impacted users would be announced in the near term, without providing further specifics at the time. As of this writing, the precise mechanism by which the attacker obtained access-control privileges over the hot wallets — whether through leaked private keys, a compromised signing process, or another vector — had not been publicly detailed, a pattern common to many exchange breaches where root-cause disclosure lags well behind the initial incident report.

The episode adds Phemex to a growing list of exchanges whose hot-wallet architecture proved to be the weak point, reinforcing that operating across dozens of chains multiplies not only trading options but also the number of potential points of failure an attacker can exploit.

CEXPhemex
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.