T
iTokenly

CoinStats hack — June 2024

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJune 22, 2024
Target typeWallet software or provider
Loss$2,200,000Price at time of incident
MethodPrivate key compromiseCoinStats says an attacker obtained unauthorised access to parts of its infrastructure and to third-party providers, including a HashiCorp Vault instance inside its own environment that held the 2FA PINs securing CoinStats Wallets, and the APIs of a wallet-as-a-service provider. That combination gave the attacker the private keys to 1,590 in-app wallets. Wallets merely connected for read-only portfolio tracking were not affected.
ChainsMultiple chains
Attributed toLazarus GroupSuspected
OutcomeUnresolved

What happened

CoinStats, a portfolio tracker that also issues in-app wallets, was breached on 22 June 2024 at about 18:00 UTC.

In its incident report the company said an attacker gained unauthorised access to parts of its infrastructure and to third-party service providers, including a HashiCorp Vault instance that secured the 2FA keys for CoinStats Wallets, and the APIs of a wallet-as-a-service provider. That access yielded the private keys. CoinStats put the number of compromised wallets at 1,590, which Security Affairs and crypto.news both report as about 1.3 percent of its hosted wallets, and the value taken at roughly $2.2 million. Wallets connected only for read-only tracking, such as MetaMask, Phantom and exchange accounts, were not affected. Separately, crypto.news reported that during the same period users received push notifications through the CoinStats app promising rewards and linking to a wallet-drainer site.

The $2.2 million figure comes solely from CoinStats. Neither of the independent outlets that covered the breach published a dollar amount, and crypto.news noted at the time that the company was still investigating the extent of funds moved. Security Affairs also reported that some users said funds had been taken from wallets that did not appear on CoinStats' published list of affected addresses, which suggests the company's scoping, and therefore its total, may understate the loss.

CoinStats took the application offline to contain the incident, published a list of affected addresses and urged those users to export their keys and move funds immediately. It migrated to new cloud accounts rather than reusing compromised infrastructure, restored full service on 3 July 2024, engaged outside researchers, and said it had reported the matter to local law enforcement and the FBI.

CoinStats attributed the attack to the Lazarus Group or a related organisation with nation-state level resources, and its chief executive said there was significant evidence of a North Korea-linked APT group. That attribution is the company's own and has not been confirmed by any government body. Affected users were asked to file a support form by 15 August 2024 to be eligible for future support; no reimbursement programme was announced and the company said only that it was exploring ways to support those affected.

Law enforcement

CoinStats states it reported the incident to local law enforcement and the FBI. No charges, arrests or public agency confirmation have been reported.

Sources

  1. CoinStatsPrimary · retrieved 2026-08-01
  2. Security AffairsSecondary · retrieved 2026-08-01
  3. crypto.newsSecondary · retrieved 2026-08-01

Official post-mortem: https://coinstats.app/blog/security-incident-report/

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "CoinStats hack — June 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/coinstats
https://itokenly.com/hacks/coinstats

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.