Blockchain AcademicsBlockchain Academics
CoinDCX Breach Exposes $44M Security Gap Amid Rising Threats to Centralized Exchanges

CoinDCX Breach Exposes $44M Security Gap Amid Rising Threats to Centralized Exchanges

A $44M exploit on CoinDCX exposes major security flaws in centralized crypto platforms, raising systemic concerns across the industry.

Blockchain Academics NewsroomJuly 19, 20252 min read
Share

Indian crypto exchange CoinDCX has suffered a major internal security breach, resulting in the unauthorized transfer of approximately $44.2 million. The incident, traced by blockchain investigator ZachXBT and security firm Cyvers, underscores persistent vulnerabilities in centralized exchange infrastructure and the urgent need for proactive threat mitigation.

According to blockchain data, the exploit began with a transaction through the sanctioned mixer Tornado Cash, followed by a coordinated flow of funds bridged from Solana to Ethereum. This cross-chain maneuver suggests a high level of planning and technical sophistication on the part of the attackers. Investigators were able to trace the path of the stolen assets across multiple wallets and protocols, although attribution was complicated by the obfuscation tactics employed.

What sets this breach apart is its origin: not from a customer-facing hot wallet, but from an internal liquidity wallet that was not included in CoinDCX’s public proof-of-reserves disclosures. This highlights the difficulty in ensuring full transparency and the challenges of monitoring backend operations in real-time.

Security experts at Cyvers emphasized the wider implications of the breach. “This is not just a CoinDCX issue – it’s symptomatic of systemic flaws,” said Meir Dolev, CTO of Cyvers. “Over 65% of Web3-related losses in Q2 2024 stemmed from centralized exchange breaches, totaling nearly $500 million. Exchanges must adopt real-time wallet surveillance and proactive defense systems to prevent becoming the next target.”

Sumit Gupta, Co-founder and CEO of CoinDCX, confirmed the breach shortly after it was publicly identified by ZachXBT. Gupta assured users that no customer funds were compromised and explained that the targeted wallet was used for managing liquidity on a partner platform. The affected systems have been frozen, and a comprehensive investigation with cybersecurity experts is underway.

Initial alerts came from Cyvers’ Threat Intelligence platform, which detected abnormal withdrawal patterns from one of CoinDCX’s hot wallets. The rapid dispersion of funds across multiple addresses made tracking and recovery particularly complex.

While CoinDCX has sought to downplay user impact, the incident raises troubling questions about centralized custody and exchange infrastructure in an era of increasingly sophisticated attacks. As threats evolve, so must the industry's approach to defense — not just reactive containment, but anticipatory protection.

Discussion

Loading comments...