Indonesian crypto exchange Indodax has experienced a significant security breach, resulting in a loss of about $22 million in various cryptocurrencies.
Following the attack, the exchange has suspended its mobile and web applications to address the situation.
On September 11, blockchain analysis firms such as PeckShield, Cyvers, and SlowMist reported that Indodax’s hot wallets had been compromised. The stolen assets include Bitcoin, Tron, Ethereum, Polygon, Shiba Inu, and other tokens. Investigations revealed that the breach might have originated from a vulnerability in the withdrawal system, allowing the attacker to access the hot wallet.
The hacker managed to steal substantial amounts of Bitcoin, Tron’s TRX, various ERC-20 tokens, Polygon, and Ether from the Optimism blockchain. Cyvers identified over 150 suspicious transactions and noted that the stolen funds were being converted to Ether, likely using mixing services like Tornado Cash to obscure the trail.
In response, Indodax has temporarily halted its services to conduct a thorough investigation and assured users that their assets are secure. Yosi Hammer from Cyvers speculated that the Lazarus Group, a notorious North Korean hacking collective, could be behind the attack, citing similarities with previous incidents linked to the group.
Indodax’s current reserve balance is reported to be $369 million, potentially available to cover investor losses. This incident follows a similar hack in July involving WazirX, also attributed to the Lazarus Group.
Shiba Inu’s Shibarium team has launched an internal investigation into alleged rug pulls carried out by actors operating within the network.
Following a major security breach at decentralized exchange Cetus, the Sui blockchain has moved swiftly to recover user funds.
French police have arrested more than a dozen individuals, including minors, in connection with a string of crypto-related kidnapping cases that have shaken Paris in recent weeks.
A bizarre cyberattack involving the hacked Instagram account of hip-hop group Migos has surfaced, allegedly as part of an attempted extortion scheme aimed at Solana co-founder Raj Gokal.