Skip to content

Latest commit

 

History

History
103 lines (82 loc) · 5.4 KB

File metadata and controls

103 lines (82 loc) · 5.4 KB

CoinEx

Date:: September 12th, 2023

Amount Stolen: $54,000,000


Details

A fifth attack, this time targeting the crypto exchange CoinEx on September 12th.

In response to this, the company has released several tweets indicating that suspicious wallet addresses are still being identified, and therefore the total value of stolen funds is not yet known, however it is currently believed to be around $54 million.

Around $43M of assets were transferred from CoinEx hotwallet addresses to EOAs across Bitcoin, Binance Smart Chain, Ethereum, Tron and Polygon. Possible private key leak but unconfirmed.

The cryptocurrency exchange CoinEx suffered a hacker attack. The cause of the incident was initially determined to be the leakage of hot wallet private keys. The damage caused is estimated to have reached US$70 million, and the impact has affected multiple blockchains. CoinEx tweeted that it had identified and quarantined suspicious wallet addresses related to the hack and that deposit and withdrawal services had been suspended. On September 13, SlowMist found during the analysis process that CoinEx hackers were related to Stake.com hackers and Alphapo hackers. CoinEx hackers may be the North Korean hacker group Lazarus Group.

On-Chain

  • ETH 0x483d88278cbc0c9105c4807d558e06782aeff584 Theft 1
  • ETH 0x1a61df134d766f1e240fbfaee79bbecc04195f62 Theft 1b
  • ETH 0x8bf8cd7f001d0584f98f53a3d82ed0ba498cc3de Theft 2
  • ETH 0x40cbe7580168d52b7fec884120b31115c3f7e37e Theft 2b
  • ETH 0xcc1ae485b617c59a7c577c02cd07078a2bcce454 Theft 3
  • ETH 0x2118e4432d668acfa347ddba0efccc6bb04db297 Theft 3b
  • MATIC 0x4515be0067e60d8e49b2425d37e61c791c9b95e9 Theft 1 Polygon
  • MATIC 0xd4342e0277b3b9d11902fa1760f072868ecdbe2e Theft 2 Polygon
  • BNB 0x6953704e753c6fd70eb6b083313089e4fc258a20 Theft 1 BSC
  • BNB 0xC844F7178379782eC19F3EE6E399f2EB7b2b984F Theft 2 BSC
  • FTM 0x13b4147f29e53eb85276dc01c74e8fb6b0a28b76 Theft 1 FTM
  • FTM 0x4349fc96680bd7dd7e4db5e0d1f694e4c381074f Theft 2 FTM
  • AVAX 0xAE61C1262678261f78bB4c99c21648E52dE4e5C5 Theft
  • OPETH 0x964c192e54e5ef4176626875bb53071956579fca Theft 1
  • ETH 0x0516063942078f5a0608ea42ddb5346cb6cf1c56 Theft 2
  • ARBETH 0xfEec9F846E2FE529B765d832EBa988a399Fe3cD6 Theft
  • ETC 0x37a966ade96de7270e393b5533f46cb849398bf3 Theft 1
  • ETC 0x7afea174b395c1cea747eaf761bb2f95f512bee7 Theft 2
  • TRX TPFUjxQzG88Vwynrpj2W61ZAkQ9W2QYgAQ Theft 1
  • TRX TP75t6owoqXxskLq6FB2R37PymNTmohq9L Theft 2
  • XRP rpQxVcjVF2fC23r3xKyJS53jw8d5SRhZQf Theft
  • SOL G3udanrxk8stVe8Se2zXmJ3QwU8GSFJMn28mTfn8t1kq Theft
  • BTC 16TseLu7FkyN6ozm9Kf37xESaQq6LgNtXL Theft
  • BTC 1PYAsDXF9rDwrW6zwCrzMpNckNckaptPjo Theft
  • BTC 1BHNb9UJy4cWFB5wywZkTVgoNB4JbFmswH Theft
  • BCH qrgxyhj8rzl4l7fgauu6q6vtu2grct4jeyrnaq2s75 Theft
  • VET 0xBcbb4cA01cF62c07DB339C985c609a67acdf1DBC Theft
  • TON EQATuwsj4O2cXXFwaIdDRyS9Vv19Emmd6mwHy41QiiBqLH8N Theft
  • LTC Lcrkh5it7ndxVswms1QuRd78g7Fx8a2Ude Theft
  • DOGE DGAipZhEbf9r65QdB7WPwzdBKDpefVwwsZ Theft
  • DOT 1WUqwCnEpTN8cEHBqmVrFxxgDArBuBb2KBVtbKBTVFhFxAs Theft
  • XLM GBPIDVKDSNF74OAGVBSPKLW73CSCGISBOBRB3ODROTMOEENZFC6WJFPN Theft
  • XDAG 15VY3MadZvLpXhjzFXwCUmtZcHszju6L9 Theft
  • KDA k:a9f3672d7ad7a1e4592702d73b220cbc61db1fa17f89a56131d965bc03959913 Theft
  • KDA a9f3672d7ad7a1e4592702d73b220cbc61db1fa17f89a56131d965bc03959913 Theft
  • APT 0x2a80f8be5f79fc6619cba022e38ed44cb3d15d05d26fc1c2238d8f90fbff94d6 Theft
  • ETHPOW 0x0F2eB0e8d8E6F5f10e76cA5Ce588e16D5F9ffdf1 Theft 1
  • ETHPOW 0xe4afdba7664799401691da733cac9c1a3c1fccc2 Theft 2
  • KAVA kava1spv566tt3gt05n7cx9vfz47j3z878h88yywgan Theft
  • ONE one1gcx262juw97v73m29en5z2ny0h86s20tfal4l8 Theft
  • TOMO 0xbbE2a100822fc7022c0f42E277b338F67371c5b0 Theft
  • XTZ tz1UH89jqhV9x9W6UKByuUQkeGhWtWgm1Fq2 Theft
  • ZIL zil1ntf5fv4swp9d2tns6dftsvy3apry5t4n2ydw4a Theft
  • eos coinexhot111 Theft

CoinEx Addresses

  • 0x5db93150ce94085d9fbde67ef0b13953a5567458 CoinEx Hot Wallet
  • 0xd782e53a49d564f5fce4ba99555dd25d16d02a75 CoinEx Hot Wallet
  • 0x33ddd548fe3a082d753e5fe721a26e1ab43e3598 CoinEx Hot Wallet
  • 0x8701edd420781fe6b12238b4b9719fab6e6e7a63 CoinEx Multisig Deployer
  • 0xf54635836862aad6e255e9b4fe49275fa5047e5d CoinEx Multisig
  • 0x53eb3ea47643e87e8f25dd997a37b3b5260e7336 CoinEx Hot Wallet
  • 0x85cf05f35b6d542ac1d777d3f8cfde57578696fc CoinEx Hot Wallet - BSC
  • 0xeb20c7b5b86c0ae1f7b314892ec1e2e74fbaac5a CoinEx Multisig
  • 0x3a28edc3917a8019523396420eb145f28c33e108 CoinEx Hot Wallet - Polygon
  • 0xed1568101082eeaa1d483d3ba051690bdbb1255b CoinEx Hot Wallet - OP
  • 0xe25bc2eb5be0f8605b47e79945a9cb11a0b2450f CoinEx Hot Wallet - FTM
  • TFp4V3S9JqJyQAMMCewyn4aAaLueJwzS7H CoinEx Hot Wallet
  • https://eosflare.io/account/coinexhot111 CoinEx Hot Wallet

On-Chain Theft IoCs

  • 174.128.251.99

  • timeZone: Asia/Shanghai (GMT+0800)

  • Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36

  • en-US,en;q=0.9,ko;q=0.8,zh-CN;q=0.7,zh;q=0.6

URLs