Toutes les vulnérabilités
CRITICALWeb3

WEB3-COINEX-2023

Web3 · CEX · CoinEx

Résumé

On September 12, 2023, exchange CoinEx lost an estimated $54 to $70 million after attackers compromised its hot-wallet private keys, exploiting lax single-key hot-wallet security. CoinEx's own assessment preliminarily identified leakage of the hot-wallet private key as the cause; wallets controlled by a single key are especially exposed to phishing and malware, the favored access vectors of the attributed actor, and once the key leaked the attacker swept assets directly. The theft was attributed to North Korea's Lazarus Group: one of the CoinEx attacker addresses was reused from the Stake.com hack (FBI-confirmed Lazarus) and funds were bridged via infrastructure previously used by Lazarus, with the linkage confirmed by Elliptic, CertiK, SlowMist, ZachXBT and overlapping addresses tying CoinEx, Stake.com and Alphapo together. CoinEx absorbed the loss and fully reimbursed affected users without diluting its CET token, restoring full operations over the following months.

Comment l’éviter dans votre code

  • Migrate from single-key hot wallets to MPC/threshold signing or multisig.
  • Keep most funds in cold storage; cap hot-wallet exposure to operational needs.
  • Protect keys in hardware security modules; harden and isolate signing machines from email/web.
  • Apply least-privilege access and key segregation across infrastructure.
  • Enforce withdrawal allowlists, rate limits, and anomaly detection on outbound flows.

Références

Vulnérabilités liées

Tout Web3 →