T
iTokenly

FixedFloat hack — February 2024

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedFebruary 18, 2024
Target typeOther
Loss$26,100,000Price at time of incident
MethodInfrastructure compromiseExternal compromise of FixedFloat's server infrastructure, leading to the draining of the service's own hot wallets on Bitcoin and Ethereum. FixedFloat said the attack was external rather than the work of an employee and that the problem lay in its infrastructure, which was 'compromised due to flaws and insufficient protection'. The operators of the exchange service eXch, which received part of the stolen funds, said the attackers 'managed to intrude the whole core infrastructure and to obtain full privileges and dump the whole database'. No technical post-mortem was ever published.
ChainsBitcoin, Ethereum
OutcomeUnresolved

What happened

FixedFloat is a non-KYC instant cryptocurrency exchange service, described by contemporary reporting as non-custodial: Forbes noted that it 'does not perform the functions of a custodial service, that is, it does not store user funds'. The wallets drained were the service's own operating hot wallets rather than customer balances. Users began reporting stuck orders on 16 and 17 February 2024. The service switched to maintenance mode and initially described the problem as minor technical issues, prompting accusations that it was absconding with funds. On 18 February it confirmed that it had been hacked.

On-chain analysts tracked 409 BTC, worth roughly $21.1 million, and 1,728 ETH, worth roughly $4.85 million, out of the service's wallets, for a total reported at just over $26 million. BlockFence identified the receiving bitcoin address. PeckShield traced most of the stolen ether to the exchange service eXch, with further amounts reported moving to HitBTC.

FixedFloat later stated that the breach was external: "The recent hacking of our system was not carried out by our employees; it was an external attack caused by vulnerabilities in our security structure," adding that "the problem was in our infrastructure, which was compromised due to flaws and insufficient protection." The operators of eXch said the attackers had taken full privileges over FixedFloat's core infrastructure and dumped its database. FixedFloat said it does not hold customer balances, that the loss fell on the service itself, and that it would settle orders left unfilled. It promised a full report once its investigation closed; none was published.

The service was breached a second time on 1 April 2024 for a further $2.8 million. Sentinel Protocol, which analysed the April incident, said it was purportedly carried out by the same group responsible for the February breach. No funds from February were recovered and no arrests have been reported.

Sources

  1. DecryptSecondary · retrieved 2026-08-01
  2. UnchainedSecondary · retrieved 2026-08-01
  3. ForbesSecondary · retrieved 2026-08-01
  4. Sentinel ProtocolSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "FixedFloat hack — February 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/fixedfloat
https://itokenly.com/hacks/fixedfloat

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.