Worked example · 2019-01
Cryptopia exchange sustained drain — Ethereum and ERC-20 tokens — 2019-01-14 to 2019-01-28
Summary
Cryptopia, headquartered in Christchurch, New Zealand, was at the time of the event a mid-sized cryptocurrency exchange with an unusually broad listing surface — at peak the platform listed over 400 tradeable assets, with significant presence in long-tail ERC-20 tokens — and a user base of approximately 960,000 active users. Beginning approximately 2019-01-13 / 2019-01-14, attacker-controlled withdrawals began draining ETH and a wide range of ERC-20 token balances from Cryptopia's hot-wallet infrastructure. Cryptopia detected the activity on 2019-01-14 / 2019-01-15 and announced the breach publicly on 2019-01-15, suspending trading. Per subsequent industry-forensic reporting (Elliptic) and per Cryptopia's later-public statements, the drain was not a single concentrated extraction event but a sustained multi-week extraction across approximately 2019-01-14 through 2019-01-28 — meaning the active-extraction window persisted for nearly two weeks after the public disclosure of the breach.
The temporal shape of the case is what makes it analytically distinctive in the OAK record. Most exchange-hack worked examples in the OAK corpus (Bitstamp 2015, Bitfinex 2016, NiceHash 2017, Coincheck 2018, Bithumb 2018, KuCoin 2020) document concentrated extractions where the active-drain window is hours-to-days. Cryptopia 2019 documents a sustained multi-week extraction where the attacker continued to reach hot-wallet contract addresses and authorise withdrawals across the post-disclosure window. The structural implication is that Cryptopia's defender-side controls did not include either (1) anomaly detection on aggregate hot-wallet-balance-decay that would have flagged the cumulative drain pattern within the first 24–48 hours, or (2) effective rotates-on-disclosure discipline that would have invalidated the compromised access path the moment the breach was publicly announced. The post-disclosure continuation of the extraction is the load-bearing fact; it tells defenders that the operational practice of "rotate hot-wallet signing authority the moment a breach is publicly announced, before any further withdrawals can land" was not yet operational practice at Cryptopia in January 2019.
For OAK's purposes the Cryptopia 2019 case is the canonical low-and-slow T11 + T5.002 worked example. Defenders writing detection runbooks for hot-wallet operations should treat the case as the cleanest available illustration of why aggregate-balance-decay anomaly detection — rather than per-transaction anomaly detection on individual withdrawals — is the load-bearing detection layer for low-and-slow extractions. The case is also structurally significant for OAK's recovery-mechanism documentation because it produced the canonical New Zealand legal precedent (Ruscoe v Cryptopia Limited [2020] NZHC 728) on the property-status of customer cryptocurrency holdings in insolvency proceedings — a precedent that subsequently shaped how digital-asset insolvencies are handled across the New Zealand and broader common-law jurisdictional surface.
Timeline (UTC unless noted)
| When | Event | OAK ref |
|---|---|---|
| Pre-event (2018-Q4 to 2019-01-13) | Operator-side compromise of Cryptopia's hot-wallet key material; the exact entry vector was not publicly disclosed in technical detail. The compromise produced sustained access to authorise withdrawals across hundreds of monitored ERC-20 contract addresses | T11 entry — operator-side hot-wallet key compromise (no exact OAK v0.1 sub-technique match) |
| 2019-01-13 / 2019-01-14 | Attacker-controlled withdrawals begin draining ETH and ERC-20 token balances from Cryptopia hot-wallet contract addresses | T11 + T5.002 extraction begins |
| 2019-01-14 / 2019-01-15 | Cryptopia detects the activity; suspends trading; announces the breach publicly via Twitter and corporate channels | (operator detection / disclosure) |
| 2019-01-15 onward | New Zealand Police investigation initiated; FBI cooperation publicly acknowledged | (law-enforcement engagement) |
| 2019-01-15 to 2019-01-28 | Sustained extraction continues post-disclosure across approximately 14 days — attacker continues to reach hot-wallet contract addresses and authorise withdrawals despite the public breach announcement | T5.002 — low-and-slow extraction across multi-week window |
| 2019-01-28 | Aggregate drain reaches ~NZ$23M+; active-extraction window ends; Cryptopia engages in continuing damage assessment and asset accounting | (extraction window closes) |
| 2019-03-04 | Cryptopia partially reopens trading on a read-only basis, allowing user-balance-view but no withdrawals | (operational partial-recovery) |
| 2019-05-15 | Cryptopia enters liquidation under New Zealand insolvency law; Grant Thornton appointed as liquidator | Insolvency proceeding initiated |
| 2019-05 onward | Grant Thornton liquidator conducts creditor-claim verification; the cryptocurrency-as-property treatment becomes the central legal question | (liquidation administration) |
| 2020-04-08 | High Court of New Zealand judgment in Ruscoe v Cryptopia Limited [2020] NZHC 728: Justice David Gendall rules that customer cryptocurrency holdings at Cryptopia constituted "property" within the meaning of section 2 of the Companies Act 1993, held on express trust for users | Foundational NZ-law precedent on digital-asset insolvency |
| 2020-04-15 | Arrest by New Zealand Police of a former Cryptopia employee in relation to a separate ~NZ$250,000 theft from the company; no public-record charge connects any individual to the 2019-01 multi-week extraction | (separate-incident law-enforcement action) |
| 2020 onward | Liquidator continues creditor-claim verification and partial-distribution administration across the multi-year proceeding; the case continues well past the OAK v0.1 cutoff | (recovery — partial and continuing) |
What defenders observed and learned
- Pre-event: the load-bearing failure was that the attacker reached operator-side hot-wallet key material with authority to authorise withdrawals across hundreds of monitored contract addresses, and that this access surface was not invalidated by any periodic-rotation discipline or just-in-time signing access control. A defender writing an exchange-custody runbook should treat persistent operator-side authority over a broad set of hot-wallet contract addresses as a primary control to fix; the post-2020 industry baseline of just-in-time / break-glass elevation, hardware-token-mediated signing access, and aggressive periodic key rotation is retro-engineered against this failure shape.
- At-event (detection): detection occurred approximately 24–48 hours into the extraction window — late enough that meaningful drain had already occurred, but early enough that, had the rotates-on-disclosure discipline been in place, the post-disclosure continuation of the drain would not have happened. The detection signal that did fire (Cryptopia's contemporaneous statements indicate detection came from operational-side observation) was per-transaction-level rather than aggregate-balance-decay-level. The defender lesson is that aggregate-balance-decay detection across the population of monitored hot-wallet contract addresses — rather than per-transaction anomaly detection on individual withdrawals — is the load-bearing detection layer for low-and-slow extractions. The Cryptopia case is the cleanest available illustration of why this matters.
- At-event (rotates-on-disclosure): the post-disclosure continuation of the extraction across approximately 14 days is the single most operationally instructive feature of the case. A rotates-on-disclosure discipline that treated the public breach announcement as a triggering event for hot-wallet signing-authority rotation — invalidating the compromised access path before any further withdrawals could land — would have stopped the drain at the disclosure point. This discipline was not operational practice at Cryptopia in January 2019; the case is therefore the canonical illustration of why the post-2020 industry baseline of rotate-on-disclosure exists at all.
- Post-event (insolvency / property-status): the Ruscoe v Cryptopia Limited [2020] NZHC 728 judgment is a structurally significant outcome of the case. Justice David Gendall's ruling that customer cryptocurrency holdings at Cryptopia constituted "property" held on express trust for users — and therefore that user-creditors had priority claims against the cryptocurrency holdings rather than ranking pari passu with general unsecured creditors of the company — is a foundational New Zealand-law precedent on digital-asset insolvency proceedings. Defenders writing jurisdiction-of-incorporation analyses for exchanges, custodians, or DAO treasuries should treat the New Zealand precedent as a real and case-tested option for ensuring user-creditor priority through insolvency.
- Post-event (attribution): no public-record indictment, attribution-cluster claim, or law-enforcement disposition has named the Cryptopia 2019 attacker. The 2020-04 arrest of a former Cryptopia employee in relation to a ~NZ$250,000 separate theft is operationally unrelated to the multi-week extraction. The case sits cleanly outside the OAK-G01 cohort and is genuinely
pseudonymous-unattributedafter multiple years of investigation.
What this example tells contributors writing future Technique pages
- Cryptopia 2019 is the canonical low-and-slow T11 + T5.002 worked example. The temporal shape — multi-week sustained extraction, post-disclosure continuation, aggregate-balance-decay-driven impact — is structurally distinct from the concentrated-extraction shape that dominates most OAK exchange-hack worked examples. Contributors writing T5.002 Technique pages should treat Cryptopia 2019 as the canonical illustration; contributors writing T11 sub-technique pages should cross-reference Cryptopia as the case that demonstrates the temporal-shape variation within the broader T11 family.
- Aggregate-balance-decay anomaly detection deserves its own M-axis treatment. OAK's mitigation taxonomy currently emphasises per-transaction-level anomaly detection on hot-wallet egress. The Cryptopia case demonstrates that this control class is insufficient against low-and-slow extractions: an attacker who stays below per-transaction thresholds at every individual step can produce structurally significant aggregate balance decay over a multi-week window. Contributors writing M-axis pages should treat aggregate-balance-decay detection across the population of monitored hot-wallet contract addresses as a distinct mitigation class, with Cryptopia 2019 as the canonical reference case.
- Rotates-on-disclosure discipline is the operationally cleanest defender-side fix the case illustrates. The post-disclosure continuation of the drain is the single most actionable defender lesson — a rotate-on-disclosure discipline that invalidated the compromised access path the moment the breach was publicly announced would have stopped the drain at the disclosure point. Contributors writing M22-class rotation-discipline pages should treat Cryptopia as a primary reference for the practical content of rotate-on-disclosure as an operational practice rather than a checkbox.
pseudonymous-unattributedattribution is the right marker. No public-record indictment, attribution-cluster claim, or law-enforcement disposition has named the Cryptopia 2019 attacker after multiple years of investigation. The case sits cleanly outside the OAK-G01 cohort and should not be retro-fit to that cluster. Contributors writing other 2018–2019 exchange-hack worked examples should expect a mix of attribution surfaces — someconfirmed(Bitfinex 2016, post-2022 disposition), someinferred-strong(Coincheck 2018, KuCoin 2020), and some genuinelypseudonymous-unattributed(Cryptopia 2019), with the pattern being that smaller-magnitude / non-G01-cohort cases tend to remain unattributed indefinitely.- The Ruscoe v Cryptopia Limited [2020] NZHC 728 precedent deserves its own line in any jurisdiction-comparison material. The case is the foundational New Zealand-law precedent on digital-asset insolvency proceedings, and contributors writing jurisdiction-comparison pages or recovery-mechanism pages should reference it as the New Zealand pillar of the case-tested precedent set (alongside Mt. Gox / Japan civil-rehabilitation as the Japanese pillar, FTX 2022 / Delaware as the US Chapter 11 pillar, and adjacent jurisdiction-specific precedents).
Public references
[cryptopiapress2019]— Cryptopia New Zealand Limited. Statement on the January 2019 security incident. 2019-01-15 onward; primary-source operator disclosure across the breach response and continuing operational updates.[ellipticcryptopia2019]— Elliptic primary forensic analysis of the Cryptopia laundering cluster, the multi-week extraction shape, and the post-event laundering activity through 2019.[grantthorntoncryptopia2019]— Grant Thornton (NZ liquidator). Cryptopia New Zealand Limited (in liquidation) — liquidator's reports. 2019-05 onward; primary-source insolvency-proceeding documentation including loss-magnitude and creditor-claim accounting.[ruscoecryptopia2020]— Ruscoe v Cryptopia Limited (in liquidation) [2020] NZHC 728. High Court of New Zealand judgment, 2020-04-08; Justice David Gendall. Foundational NZ-law precedent on digital-asset insolvency property-status.[stuffcryptopia2019]— Stuff (NZ). Christchurch cryptocurrency exchange Cryptopia hacked. 2019-01-15 / 2019-01-16; contemporaneous New Zealand press coverage of the breach disclosure.[radionzcryptopia2020]— Radio New Zealand. Former Cryptopia employee arrested over alleged theft. 2020-04-15; primary-source NZ press coverage of the separate-incident arrest.
Discussion
Cryptopia 2019 is the OAK record's canonical low-and-slow T11 + T5.002 worked example. The case is analytically distinctive along three axes that no other v0.1 exchange-hack worked example covers cleanly: the temporal shape of the extraction (multi-week sustained drain rather than concentrated event), the post-disclosure continuation of the drain (the public breach announcement did not invalidate the compromised access path), and the foundational insolvency-precedent outcome (Ruscoe v Cryptopia Limited [2020] NZHC 728 as the New Zealand-law digital-asset-property-status precedent).
The temporal-shape distinction matters most for the M-axis (mitigation) Technique surface OAK is building. Most exchange-hack worked examples in the OAK corpus document concentrated extractions with hours-to-days active-drain windows; per-transaction-level anomaly detection on hot-wallet egress is at least theoretically capable of catching such patterns within the first hour. Cryptopia 2019 demonstrates that a sufficiently patient attacker — one who stays below per-transaction thresholds at every individual step but accumulates structurally significant aggregate balance decay over a multi-week window — defeats per-transaction anomaly detection by construction. The defender-side fix is aggregate-balance-decay anomaly detection across the population of monitored hot-wallet contract addresses, and Cryptopia is the cleanest available case in the OAK record to anchor that mitigation class. Contributors writing M-axis pages on aggregate-balance-decay detection should treat Cryptopia 2019 as the primary reference case.
The rotates-on-disclosure discipline gap is the most directly actionable defender lesson. The drain continued for approximately 14 days after the public breach announcement — meaning the operational practice of "rotate hot-wallet signing authority the moment a breach is publicly announced, before any further withdrawals can land" was not yet operational practice at Cryptopia in January 2019. This discipline is now standard at well-run custody operations; the Cryptopia case is the cleanest historical illustration of why the discipline has the operational shape it does. Contributors writing M-axis pages on rotates-on-disclosure should treat Cryptopia as a primary reference, alongside Bitstamp 2015 (where rotates-on-suspicion against an observed spear-phishing campaign would have invalidated the signing authority before the compromise that produced the drain).
The Ruscoe v Cryptopia Limited precedent deserves to be flagged as the foundational New Zealand-law digital-asset insolvency precedent. Justice David Gendall's 2020-04-08 ruling — that customer cryptocurrency holdings at Cryptopia constituted "property" within the meaning of section 2 of the Companies Act 1993, held on express trust for users — is the single clearest available illustration in the OAK record of how a common-law jurisdiction can ensure user-creditor priority over cryptocurrency assets through insolvency. Defenders writing jurisdiction-of-incorporation analyses for exchanges, custodians, or DAO treasuries should treat the New Zealand precedent as a real and case-tested option, with Cryptopia as the singular precedent for what the New Zealand pillar of the digital-asset-insolvency precedent set actually contains.
Finally, the pseudonymous-unattributed attribution surface is itself a documentation discipline matter. After multiple years of investigation by New Zealand Police with FBI cooperation, no public-record indictment, attribution-cluster claim, or law-enforcement disposition has named the Cryptopia 2019 attacker. The case sits cleanly outside the OAK-G01 cohort and is genuinely unattributed; the 2020-04 arrest of a former Cryptopia employee in relation to a ~NZ$250,000 separate theft is operationally unrelated to the multi-week extraction. Contributors writing 2018–2019 exchange-hack worked examples should expect a mix of attribution surfaces and should preserve the genuine-pseudonymous outcomes rather than retro-fitting them to nearby attributed cohorts. The OAK record's value depends on accurate attribution-strength notation, and Cryptopia 2019 is one of the cleanest available cases for the genuinely-unattributed end of the attribution-strength spectrum.