In Brief: CoinDCX Confirms $44M Exchange Account Hack
Indian crypto exchange CoinDCX confirmed a $44 million hack across two accounts linked to its internal liquidity operations, occurring on Friday, July 19, 2025.
- Customer wallets and funds remain unaffected.
- The exchange is offering a $11 million bounty (up to 25% of recovered funds) to individuals who assist in tracing and retrieving stolen assets.
- The breach has reignited security concerns within the regional crypto market.
Key Details
CEO Sumit Gupta confirmed the incident shortly after it occurred, attributing it to a sophisticated cyberattack. Analysis indicates the attacker initiated operations using funds withdrawn via the mixer Tornado Cash.
The breach targeted an isolated liquidity account; operational accounts are said to be segregated from customer wallets.
Stolen funds ($44 million) were traced to two wallets: $43.4 million moved to Ethereum and $27.7 million identified in a Solana address initially.
Industry Context
The hack follows CoinDCX CEO Sumit Gupta’s call for transparency following last year’s $230 million WazirX breach.
Cybersage firm Cyvers noted similarities with attacks attributed to groups like Lazarus, emphasizing risks posed by centralized infrastructure.
The incident has fueled calls for enhanced cryptocurrency security standards and preventative measures.
Company Response & Collaboration
CoinDCX assured its treasury reserves absorb the financial loss and is actively collaborating with cybersecurity firms and blockchain analytics.
“Cybercrime is an attack on trust,” CoinDCX stated, framing its bounty program as a measure to rebuild community confidence.
The exchange reported the incident to India’s Computer Emergency Response Team (CERT-In).
Expert Commentary
Experts emphasized the need for robust security protocols. Arjun Vijay (Giottus) highlighted the imperative to “reduce single-point risks,” while Vedang Vatsa (Hashtag Web3) stressed the opportunity for regulatory-exchange collaboration.
The incident occurs almost one year after the widespread WazirX breach, underscoring persistent challenges within the crypto security landscape.