GDAC hack — April 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | April 10, 2023 |
| Target type | Centralised exchange |
| Loss | $13,000,000Published estimates range $13,000,000 to $13,000,000Price at time of incident |
| Method | Private key compromiseAssets moved directly out of GDAC-controlled hot wallets to attacker addresses, beginning with a 0.5 ETH test transfer at 18:36 UTC on 8 April 2023 and continuing with the bulk of the funds about six minutes later. CertiK's analysis attributes the incident to exposure of the private key behind a GDAC externally owned account and related exchange-controlled wallets; the transactions appeared on-chain as ordinary transfers. GDAC did not publish a technical root cause of its own beyond describing the compromise as affecting its hot wallet system. |
| Chains | Bitcoin, Ethereum, Other |
| Outcome | Unresolved |
What happened
GDAC, a South Korean cryptocurrency exchange, lost roughly $13 million from its hot wallets late on 8 April 2023 UTC, which was the early hours of 9 April local time. CertiK's reconstruction places the first movement, a 0.5 ETH test transfer, at about 18:36 UTC, with the bulk of the funds leaving roughly six minutes later. The exchange announced the breach publicly on 10 April, though some coverage dates the announcement to 9 April local time.
The attacker took 10 million WEMIX, about 61 BTC, 350.5 ETH and 220,000 USDT. The WEMIX, moved on the WEMIX chain, accounted for most of the value at roughly $10.7 million. On Ethereum the stolen USDT was swapped into ETH, and about 462 ETH was subsequently pushed through Tornado Cash. GDAC said the stolen assets amounted to about 23 percent of the customer assets it held. CertiK noted that the attacker did not empty every wallet, leaving roughly $1.78 million untouched elsewhere, which points to a targeted rather than comprehensive compromise.
GDAC never published a technical root cause. CertiK's analysis concluded the incident was highly likely caused by exposure of the private key behind a GDAC-controlled account, since the transfers appear on-chain as ordinary transfer calls with nothing anomalous about them; that judgement is an inference from the transaction pattern, not a confirmed finding by the exchange.
GDAC suspended deposits and withdrawals, shut down the affected wallet servers, and reported the incident to local police and the Korea Internet & Security Agency. It did not disclose the underlying security failure or give a timeline for restoring services. No recovery of the funds, no arrests and no customer compensation programme have been publicly reported, and the attacker has never been identified.
Sources
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "GDAC hack — April 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/gdachttps://itokenly.com/hacks/gdacPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.