CoinsPaid hack — July 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 26, 2023 |
| Target type | Custodian or payment processor |
| Loss | $37,300,000Published estimates range $37,200,000 to $37,300,000Price at time of incident |
| Method | Social engineeringFake recruiter job test installed malware, giving access to withdrawal infrastructure |
| Chains | Tron, Bitcoin, Ethereum |
| Attributed to | Lazarus Group (DPRK-linked)Confirmed |
| Outcome | Users reimbursed |
What happened
CoinsPaid, a Ukrainian-founded crypto payment processor registered in Estonia, lost about $37.3 million from its hot wallets on 22 July 2023.
The intrusion followed roughly six months of attempts against the company's staff, beginning in March 2023. In the successful attempt the attackers posed as recruiters for Crypto.com and other firms, approaching CoinsPaid employees over LinkedIn and messaging apps with offers of $16,000 to $24,000 a month. One employee was given a technical test task that required installing an application. CoinsPaid describes the software installed as a JumpCloud agent; it was malicious and handed the attackers profiles and keys from the machine and then access to CoinsPaid's internal infrastructure. From there they exploited a cluster vulnerability, created backdoors and issued withdrawal requests to the blockchain from the company's own systems.
Chief executive Max Krupyshev told CoinDesk that the wallets' private keys were never taken and that, as soon as the servers were switched off, the transfers stopped. Chief financial officer Pavel Kashuba put the active attack phase at about four hours and 23 minutes; CoinDesk's account places that window on 21 July, while CoinsPaid's own statement and subsequent reporting date the theft to 22 July. Tron-based USDT, bitcoin and ERC-20 tokens were taken, then routed through cross-chain bridges, SwftSwap, Uniswap and SunSwap, several centralised exchanges, and the Sinbad mixer.
CoinsPaid said client funds were not affected and remained fully available, covering the loss from its own reserves. On 26 July 2023 it attributed the attack to North Korea's Lazarus Group, citing overlaps with the June 2023 Atomic Wallet theft. Elliptic reports that the FBI subsequently confirmed that attribution. BleepingComputer's headline gives the amount as $37,300,000 while its body text says $37,200,000.
Law enforcement
The FBI's press release of 22 August 2023 named DPRK TraderTraitor-affiliated actors (also tracked as Lazarus Group and APT38) as responsible for a $37 million theft from CoinsPaid, alongside the Alphapo and Atomic Wallet thefts, and published bitcoin addresses holding stolen proceeds. CoinsPaid said Estonian law enforcement was assisting, along with Chainalysis, Binance, Crystal, Match Systems and others. No arrests, indictments or incident-specific sanctions designations have been reported.
Sources
- CoinsPaidPrimary · retrieved 2026-08-01
- Federal Bureau of InvestigationPrimary · retrieved 2026-08-01
- EllipticSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- BleepingComputerSecondary · retrieved 2026-08-01
- DL NewsSecondary · retrieved 2026-08-01
Official post-mortem: https://coinspaid.com/company-updates/the-coinspaid-hack-explained/
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "CoinsPaid hack — July 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/coinspaidhttps://itokenly.com/hacks/coinspaidPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.