Indonesian crypto exchange Indodax has experienced a significant security breach, resulting in a loss of about $22 million in various cryptocurrencies.
Following the attack, the exchange has suspended its mobile and web applications to address the situation.
On September 11, blockchain analysis firms such as PeckShield, Cyvers, and SlowMist reported that Indodax’s hot wallets had been compromised. The stolen assets include Bitcoin, Tron, Ethereum, Polygon, Shiba Inu, and other tokens. Investigations revealed that the breach might have originated from a vulnerability in the withdrawal system, allowing the attacker to access the hot wallet.
The hacker managed to steal substantial amounts of Bitcoin, Tron’s TRX, various ERC-20 tokens, Polygon, and Ether from the Optimism blockchain. Cyvers identified over 150 suspicious transactions and noted that the stolen funds were being converted to Ether, likely using mixing services like Tornado Cash to obscure the trail.
In response, Indodax has temporarily halted its services to conduct a thorough investigation and assured users that their assets are secure. Yosi Hammer from Cyvers speculated that the Lazarus Group, a notorious North Korean hacking collective, could be behind the attack, citing similarities with previous incidents linked to the group.
Indodax’s current reserve balance is reported to be $369 million, potentially available to cover investor losses. This incident follows a similar hack in July involving WazirX, also attributed to the Lazarus Group.
A former Bank of America employee has admitted to playing a role in an international money laundering network that funneled millions of dollars through fraudulent bank accounts, according to the U.S. Department of Justice (DOJ).
An international arrest warrant has been requested for Hayden Davis, co-creator of the LIBRA token, which became the center of a major political scandal in Argentina.
Chris Larsen, the co-founder of Ripple, suffered a significant financial blow in 2024 when he lost over $661 million worth of XRP due to a security breach in the password management system LastPass.
Venture capitalist and Mission Gate founder George Bachiashvili is now facing imprisonment in Georgia after a court revoked his bail.