T
iTokenly

CoinDCX hack — July 2025

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Target typeCentralised exchange
Loss$44,200,000Price at time of incident
MethodInfrastructure compromiseserver breach reaching an internal liquidity-provisioning account held at a partner exchange; mechanism never disclosed
ChainsSolana, Ethereum
OutcomeUnresolved

What happened

CoinDCX, India's largest cryptocurrency exchange by volume, lost about $44 million from an internal operational account in July 2025. Chief executive Sumit Gupta described the cause as a sophisticated server breach that reached an account used solely for liquidity provisioning on a partner exchange.

The exchange did not disclose the loss until after the on-chain investigator ZachXBT posted about it on his Telegram channel on 19 July. Gupta then confirmed it publicly, saying the affected account had been isolated as soon as the attack was detected, that operational accounts are segregated from customer wallets, and that customer assets remained secure in cold storage. CoinDCX said the exposure was limited to that one account and would be absorbed in full from its own treasury reserves.

The date of the theft itself is genuinely unsettled and sources disagree by more than a week. CoinDCX titled its own incident report 19 July 2025 and Gupta's statement gives that date; CoinDesk placed the breach on Friday 18 July; Merkle Science's on-chain analysis dates the theft to 12 July 2025 and treats 19 July as the disclosure date. This record uses 19 July as the date CoinDCX itself gives, but flags it as approximate, and the gap between the theft and its disclosure has never been explained by the exchange.

Merkle Science's analysis traced a wallet funded with roughly 1 ETH routed out of Tornado Cash through FixedFloat, bridged to Solana via deBridge, swapped through the Jupiter aggregator, then moved back to Ethereum over the Mayan bridge and consolidated into a single address holding about 4,443 ETH. It describes the stolen assets as approximately $44.2 million in USDC and USDT. TechCrunch gave the loss as $44.2 million and reported holdings of roughly 4,443 ETH and 155,830 SOL; CoinDesk and CoinDCX itself used the rounder $44 million.

CoinDCX has not published technical detail on how the server was compromised, no actor has been named, and the funds have not been recovered.

Law enforcement

CoinDCX said it was working with blockchain forensics firms and relevant authorities on recovery. No arrests, charges or sanctions reported.

Sources

  1. CoinDCXPrimary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. TechCrunchSecondary · retrieved 2026-08-01
  4. Merkle ScienceSecondary · retrieved 2026-08-01

Official post-mortem: https://coindcx.com/blog/announcements/incident-report-july-19-2025/

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "CoinDCX hack — July 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/coindcx
https://itokenly.com/hacks/coindcx

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.