Xeggex Goes Dark: A Timeline of the "Hack", the Frozen Wallets, and Echoes of Cryptsy
Xeggex, a little-known exchange that had built a niche hosting small-cap altcoins, went offline abruptly in early February 2025, and on-chain evidence suggests some user funds may have moved in ways that don't match the official explanation.
The exchange said its CEO's account had been "hacked," shortly before its database was reported "corrupted," locking users out of their holdings. The disruption began just hours after a broad market downturn in early February — timing that struck many observers as convenient. Millions of dollars in altcoins tied to the exchange's wallets reportedly remain stranded, out of reach for many account holders.

A familiar shape
Community researchers have drawn a direct line between this collapse and two earlier ones. They point to Paul Vernon, the operator tied to the 2016 collapse of Cryptsy, who was subsequently indicted by the U.S. Department of Justice over allegations that he took customer funds. Court filings describe Vernon going well beyond simply walking away from Cryptsy: after the exchange entered receivership in April 2016, he is alleged to have remotely accessed its servers, copied out the customer database along with remaining funds, and destroyed evidence in the process.
A second precedent, Altilly, followed a similar arc in 2020 — a claimed hack, followed by database-corruption excuses that permanently cut users off from their assets. Investigators now argue that Cryptsy, Altilly, and possibly Xeggex share a template: sudden technical failure, frozen customer funds, and open-ended recovery promises that blockchain data tends to contradict.
Who ran the exchange
Xeggex marketed itself on low fees, fast listings, and no KYC requirements, making it a haven for small-cap tokens that couldn't get listed elsewhere and for traders who preferred anonymity. The person behind it was known publicly only by the handle "Karl," whose real identity was never disclosed. Based on community research, "Karl" has been alleged — though not confirmed — to be Paul Vernon himself.
Warning signs had already surfaced before the collapse. A user reported a 2FA bypass vulnerability in January 2025 and was reportedly told such an exploit was "impossible." A former business partner, Nayiem Willems, had separately flagged serious security shortcomings and the absence of adequate disaster-recovery planning. A database architect also publicly questioned why an exchange processing millions of dollars in volume was built on MongoDB rather than a database architecture suited to financial systems.
Timeline of the collapse
On February 3, 2025, amid a sharp market-wide sell-off, Xeggex announced a crisis, stating: "Dear users, in this hard time our CEO was hacked and he lost tg account and xeggex community group..." The message followed a pattern common to exchange failures — vague warnings, references to technical trouble, and assurances that user funds remained secure.
Within hours, blockchain analysts at Bitrace reported unusual activity: known Xeggex business wallets had moved funds before the "hack" was even announced. One flagged transfer originated from a Xeggex hot wallet, address 0x20FfE0D07D7f7c2C21A24537538b4cDE06c9048a, shortly before the platform went dark. It remains unclear whether this reflected a deliberate exit or simply a cluster of unusual but unrelated transactions — but the timing raised immediate questions.
Xeggex's Arkham Intelligence profile shows a sharp decline in tracked token balances — including USDC, USDT, ETH, and BNB — between February 2 and February 3, right around the incident window. At the same time, millions of dollars in other altcoins sat untouched in separate Xeggex hot wallets, among them 0xa0387AdBA7636722ABE119cbF9220Ce0B9938b0b and the Tron address TQwyYfukuzSNiyEsGmS3cZB8yqeMJzitTr — leaving those balances effectively locked away from their owners.
The updates that followed offered little clarity:
- February 4: Xeggex stated its "development team is busy to restore all services."
- February 6: the exchange said, "We are still working hard to get our backup restored. Tomorrow, a senior MongoDB developer will be assisting us." Around this time, a user who offered concrete MongoDB recovery commands in the exchange's Telegram group was promptly muted rather than engaged.
- February 10: Xeggex said it was "restoring what we recovered to a new database server," while noting that roughly 20% of user email addresses were missing.
- February 11: the exchange reported it was still restoring service.
- February 13: logins were partially restored, though trading and withdrawals stayed disabled.
- February 14–16: some withdrawals were gradually re-enabled.
- February 18: Xeggex ran a poll on X asking whether the exchange should keep operating or wind down once claims were processed; 86% of respondents voted to keep it running.
- February 19: a claims portal went live at xeggex.com/claims for users still locked out of their accounts.
Even as many users remained unable to access their funds, on-chain activity continued — most notably around Pepe (PEPE) holdings. Xeggex's designated Pepe wallet, which still holds a substantial share of total Pepe supply, has been steadily shrinking: incoming deposits appear to be routed back out almost as soon as they arrive, despite the exchange's claims of being crippled by database failure. The Pepecoin community took notice; one user remarked, "I see that the Xeggex Pepecoin wallet is sending and receiving millions of coins today, yet no one else can get to their coins?" Meanwhile, complaints have continued to accumulate on Reddit's dedicated "Xeggex Victims" forum, and the exchange's Discord server has been locked to read-only for weeks.
A pattern across three collapses
Researchers tracking these cases argue the resemblance goes beyond superficial similarity. In the Cryptsy case, court documents describe Vernon not merely taking funds but methodically covering his tracks — deleting evidence, eliminating recovery paths, and obscuring the on-chain trail — while a DOJ investigation uncovered a network of shell companies allegedly used to launder the proceeds. Notably, in March 2022, blockchain trackers observed 11,325 BTC (worth roughly $540 million at the time) move out of wallets that had been dormant since 2014, funds that investigators believe may trace back to the original Cryptsy theft.
Between Altilly and Xeggex specifically, the parallels cited include: both blamed compromised hosting providers; both cited database corruption as the reason users couldn't access funds; both promised recovery timelines that kept extending; and both ultimately left users permanently unable to reach major portions of their holdings. A Reddit post from Nayiem Willems describes both episodes following the same communication arc — initial claims of a minor issue, escalating problems, and recovery promises that were never fully honored. Willems warned: "If Xeggex is supposedly hacked, offline, its Telegram hacked, or its database deleted or corrupted, then you can be sure that your funds are gone. If 'they' claim to be working on a fix to restore funds or databases, don't fall for it. It's just a way to buy time."
Separately, NonKyc.io moved to distance itself from the unfolding situation, denying involvement and describing itself as "hands off from the project." Whether the same person or simply the same playbook connects the three exchanges, researchers say the recurring pattern is hard to dismiss as coincidence.
Real assets replaced with IOUs

Weeks after the outage began, users who managed to regain access to their accounts found their dashboards intact — but with their actual holdings swapped for "promissory tokens", labeled USDTXX, BTCXX, and ETHXX. These tokens cannot be withdrawn or traded and do not appear on any blockchain explorer or decentralized exchange — they exist only inside Xeggex's own internal database. Xeggex has stated that the tokens will "earn an interest rate of 0.5% per month while in balance" and will eventually "be replaced with actual assets as funds are raised." The exchange made no announcement of this change through Twitter, Discord, or Telegram; the notice was posted quietly on its own website.
CPUChain, one of the tokens affected, publicly disavowed the promissory version of its coin: "Delisting on #XeggeX is official and we will remove our coins from the insecure exchange asap. If you see any 'Promissory' CPUchain coins after Mar 28th note that it is not genuine CPUchain coin and has nothing to do with us." Xeggex's reply read: "Hello, You know we can just move the coins right before your fork block right? Don't test us. Anyways, we will delist this junk regardless."
Around the same period, the exchange also quietly altered its code to block U.S.-based users without prior notice — a move consistent with delay tactics seen in other exchange collapses.
The community investigation
As the situation dragged on, the crypto community organized its own inquiry across Reddit, Discord, and X, alongside a Change.org petition calling for formal investigation by authorities. Drawing on nearly a decade of comparable exchange failures, investigators outlined a recurring sequence: launch or acquire an exchange with attractive terms, build up deposits and reputation, drain valuable holdings such as BTC, ETH, and stablecoins, announce a "hack" or "database corruption," and then stall users with ongoing technical excuses.
From Cryptsy in 2016, to Altilly in 2020, to Xeggex in 2025, researchers note the underlying script has barely changed — only the exchange's name is different. Regardless of whether a single operator or a shared method links the three cases, the outcome for users has been consistent: locked wallets and unfulfilled recovery promises.
As of this writing, frozen balances sit alongside the newly issued promissory tokens, the Change.org petition continues to gather signatures, and questions about who actually controls Xeggex remain unresolved. Community members caution that, given the similarities to Cryptsy and Altilly, this may not be the last time this same sequence of events plays out under a different exchange name.
Get new scam files the moment we publish them — usually 2–3 emails a week.