Worked example · 2023-09
CoinEx exchange hot-wallet compromise — Multi-chain (ETH, TRON, Polygon) — 2023-09-12
Summary
CoinEx, a Hong Kong-based cryptocurrency exchange founded in 2017, suffered a coordinated hot-wallet compromise on 2023-09-12. The attacker gained access to CoinEx's hot-wallet signing infrastructure and executed a synchronised multi-chain extraction, draining assets from hot wallets on Ethereum, TRON, Polygon, and several other chains simultaneously.
The total loss was estimated at approximately $54-70M, with estimates varying based on asset-valuation timing and the inclusion of lesser-liquidity tokens. The multi-chain extraction pattern — in which the attacker demonstrated pre-positioned access to signing infrastructure across independent blockchain networks — is the structural signature of the matured post-2022 OAK-G01 exchange-targeting playbook, reflecting multi-year operational learning from the single-chain Yapizon (2017), Bithumb (2018), and Upbit (2019) breaches.
CoinEx suspended deposits and withdrawals, transferred remaining assets to cold storage, and committed to a user-reimbursement programme. The exchange published a post-mortem and engaged with blockchain analytics firms and law enforcement. The FBI and CISA subsequently issued a joint advisory formally attributing the breach to DPRK's Lazarus Group.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2023-09-12 | Attacker executes coordinated multi-chain extraction from CoinEx hot wallets on Ethereum, TRON, Polygon, and other chains simultaneously (~$54-70M) | T11.001 (multi-chain signing-infrastructure compromise) |
| 2023-09-12 T+hours | CoinEx suspends deposits/withdrawals; transfers remaining assets to cold storage; discloses breach | (defender response) |
| 2023-09 to 2023-12 | Extracted assets routed through mixing and cross-chain laundering infrastructure; FBI/CISA joint advisory attributes breach to OAK-G01 | T7.001 (OAK-G01 characteristic laundering tradecraft) |
| 2023-09 to 2024 | CoinEx implements user-reimbursement programme; security architecture overhaul | (remediation) |
Realised extraction
Approximately $54-70M across multiple chains; attributed to OAK-G01. Partial recovery status not confirmed at v0.1. CoinEx committed to user reimbursement.
Multi-chain extraction as structural signature
The simultaneous-extraction pattern across Ethereum, TRON, and Polygon is the operational fingerprint that distinguishes the post-2022 OAK-G01 exchange-targeting tradecraft from the 2017-2019 wave:
- 2017-2019 wave (Yapizon, Bithumb, Upbit): single-chain or single-network extraction (Bitcoin-dominant in 2017; Ethereum-dominant by 2019). Exchange signing infrastructure was chain-isolated; the attacker had to compromise per-chain signing surfaces.
- 2022+ wave (CoinEx, Stake.com, BingX): multi-chain simultaneous extraction. OAK-G01 operators had matured to pre-position access across all chains an exchange supports, executing extraction in a single coordinated time window to maximise yield before the exchange's incident response could isolate per-chain signing surfaces.
The CoinEx case is the reference for the multi-chain extraction sub-pattern within T11.001.
Public references
- CoinEx official breach disclosure and post-mortem, September 2023
- FBI / CISA joint cybersecurity advisory on DPRK TraderTraitor campaign, 2023-2024
- Chainalysis, Elliptic, and TRM wallet-cluster attribution reports on CoinEx and broader OAK-G01 campaign
- SlowMist, PeckShield, and BlockSec forensic analyses, September 2023