CoinEx (2023) — Crypto Hack
LaunderedCoinEx hot wallet private keys compromised, resulting in $70M drained across multiple blockchains.
Summary
CoinEx hot wallet private keys compromised, resulting in $70M drained across multiple blockchains.
How It Was Compromised — CEX via Private Key Compromise
Attackers obtained private keys for CoinEx's hot wallets across Ethereum, Tron, Polygon, and Bitcoin networks. Funds were systematically drained across all four networks. Blockchain analysts (SlowMist) attributed the attack to North Korea's Lazarus Group based on fund flow patterns matching previous Lazarus operations.
Fund Flow & Laundering Analysis
Stolen funds moved through multiple intermediary addresses before converging at mixers. ETH portion routed via Tornado Cash. Tron assets moved through multiple hops. Bitcoin sent through ChipMixer before it was seized. Lazarus Group's trademark fund consolidation pattern visible on-chain.