T
iTokenly

Phemex hack — January 2025

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeCentralised exchange
Loss$69,000,000Published estimates range $69,000,000 to $85,000,000Price at time of incident
MethodPrivate key compromisehot wallet signing keys compromised across roughly fourteen chains; Phemex has never disclosed how the keys were obtained, and analysts note the cause of the breach remains undetermined
ChainsMultiple chains, Ethereum, Solana, Bitcoin
Attributed toUnidentified; several named analysts point to North Korea-linked actorsSuspected
OutcomeUnresolved

What happened

Phemex, a derivatives exchange, said it detected unusual activity in its hot wallet at 11:30 UTC on 23 January 2025 and suspended deposits and withdrawals. Funds left across more than a dozen chains while outside firms tracked the outflow, and the published estimate climbed for several days. Cyvers first flagged about $29 million. PeckShield reached more than $69 million. On 26 January, MetaMask's security lead Taylor Monahan put the total at about $85 million. Merkle Science's chain-by-chain reconstruction across fourteen blockchains added up to roughly $69 million, with the largest components on Ethereum at about $20.9 million, Solana at about $15.2 million, XRP at about $13.4 million and Bitcoin at $5.3 million.

Phemex has never published a loss figure of its own, so the gap between the $69 million and $85 million estimates has never been reconciled. The exchange said only hot wallets were affected, referenced its proof of reserves, and restored withdrawals chain by chain — ETH, USDT and USDC on 24 January, BTC and Solana assets on 25 January, and Arbitrum, Optimism, BNB Chain, Polygon and Base on 26 January. It said affected devices had been identified and isolated and that it had engaged security firms and law enforcement, but has not described the intrusion. Its chief executive called the attack sophisticated without giving technical specifics. A compensation plan was mentioned at the time and its terms were never published.

Several analysts pointed towards North Korea. The pseudonymous investigator SomaXBT said the attack vector resembled known North Korean activity, and Taylor Monahan noted that a large number of distinct assets were drained simultaneously across many chains and then moved manually to new addresses for swapping, which he read as the work of actors who had done this many times before. A separate unnamed security researcher drew a comparison to TraderTraitor, the state-sponsored group the FBI believes was behind the $308 million theft from the Japanese platform DMM. No government has attributed this breach, and analysts tracking the funds have said the exact cause of the compromise remains undetermined. Part of the proceeds was later moved through Tornado Cash.

Law enforcement

Phemex said it reported the incident to third-party security firms and law enforcement. No arrests, charges, indictments or sanctions connected to this breach have been identified. The North Korea link is analyst speculation only, with no FBI or OFAC statement naming Phemex.

Sources

  1. PhemexPrimary · retrieved 2026-08-01
  2. The Record (Recorded Future News)Secondary · retrieved 2026-08-01
  3. Merkle ScienceSecondary · retrieved 2026-08-01
  4. BleepingComputerSecondary · retrieved 2026-08-01
  5. The BlockSecondary · retrieved 2026-08-01

Official post-mortem: https://phemex.com/announcements/phemex-hot-wallet-security-incident-update-and-timeline

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Phemex hack — January 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/phemex
https://itokenly.com/hacks/phemex

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.