T
iTokenly

CoinEx hack — September 2023

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeCentralised exchange
Loss$70,000,000Published estimates range $54,000,000 to $80,000,000Price at time of incident
MethodPrivate key compromisehot wallet private key leaked, enabling withdrawals across many chains
ChainsMultiple chains, Ethereum, Tron, Bitcoin, Solana
Attributed toLazarus Group (North Korea)Alleged
OutcomeUsers reimbursed

What happened

CoinEx is a centralised cryptocurrency exchange. On 12 September 2023 its risk-control system flagged withdrawals it had not authorised from several hot wallet addresses used to hold user assets for day-to-day liquidity. CoinEx said the cause was the leakage of a hot wallet private key. Its incident page lists losses across more than twenty assets, including 231 BTC, 4,953 ETH, 135,600 SOL, 12,625,364 XRP, 16,695,400 DOGE and 137,127,860 TRX, and states that the specific values were still being liquidated.

Estimates of the total have never converged. Cointelegraph reported the loss was first estimated at about $27 million and roughly doubled over the following week; Elliptic used approximately $54 million while noting the total was not yet known. CoinEx's own estimate within the week of the incident was roughly $70 million, the figure the UN Panel of Experts on North Korea later recorded. In a statement published on 25 June 2026, CoinEx put the loss at approximately $80 million.

CoinEx suspended withdrawals, moved remaining assets from the compromised hot wallet to secure addresses on 12 September, rebuilt its wallet architecture between 14 and 21 September with new deposit addresses for every user, and resumed deposits and withdrawals for ten mainstream assets including BTC, ETH, USDT and USDC on 21 September 2023. It said user assets had not been affected and that its User Asset Security Foundation would bear the loss.

Elliptic found that some of the stolen funds went to an address previously used to launder proceeds of the Stake.com theft, were bridged to Ethereum using a bridge Lazarus had used before, and returned to an address controlled by the CoinEx attacker. It concluded Lazarus should be suspected. CoinEx has since said the attack was attributed by multiple investigations to a North Korea-affiliated group. No one has been charged.

Law enforcement

Listed in the UN Security Council Panel of Experts report on North Korea released 7 March 2024 among cryptocurrency heists under investigation as North Korean, entered as 'CoinEx, 12 September 2023, $70m'. No arrests or charges have been reported.

Sources

  1. CoinExPrimary · retrieved 2026-08-01
  2. CoinExPrimary · retrieved 2026-08-01
  3. EllipticSecondary · retrieved 2026-08-01
  4. The Record (Recorded Future News)Secondary · retrieved 2026-08-01
  5. CointelegraphSecondary · retrieved 2026-08-01

Official post-mortem: https://www.coinex.com/en/announcements/detail/19187420867348

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "CoinEx hack — September 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/coinex
https://itokenly.com/hacks/coinex

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.