Remitano hack — September 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 14, 2023 |
| Target type | Centralised exchange |
| Loss | $2,700,000Price at time of incident |
| Recovered | $1,400,000 |
| Method | Private key compromiseCompromise of the exchange's Ethereum hot wallet keys, used to make unauthorised withdrawals to a freshly created address (0x74530e81E9f4715c720b6b237f682CD0e298B66C) with no prior transaction history. Remitano has never disclosed how the keys were obtained. |
| Chains | Ethereum |
| Outcome | Partially recovered |
What happened
Remitano, a Seychelles-registered peer-to-peer exchange with large user bases in Vietnam and Nigeria, lost funds from its hot wallets on 14 September 2023. Blockchain monitoring firm Cyvers flagged the outflows publicly, saying more than $2.7 million had been moved to a freshly created address, which had no prior transaction history. The transfers itemised in contemporaneous reporting were on Ethereum: roughly $1.4 million in USDT, about $208,000 in USDC and 104,000 ANKR worth around $2,000. Those components total substantially less than the $2.7 million headline and no source published a breakdown of the remainder, so the total rests on Cyvers' figure alone. Remitano said its Bitcoin, Bitcoin Cash and Litecoin balances were unaffected and transfers on those chains continued. Tether froze the address holding roughly $1.4 million in USDT, preventing that portion from moving further. Remitano acknowledged the incident, describing it as a small amount of funds moved from its hot wallets to suspicious addresses through unauthorised withdrawal transactions, and said it had suspended deposits and withdrawals, moved remaining balances to cold storage, deactivated the compromised addresses and worked with Cyvers and Tether on monitoring and freezing. The exchange's characterisation of the size of the loss is noticeably softer than Cyvers', and Remitano never published its own figure. How the keys were obtained has not been disclosed, and no actor has been identified. Some commentary at the time speculated about North Korean involvement given the run of exchange hacks that month, but no security firm or government body has published an attribution for this incident.
On-chain references
Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.
Attacker addresses
- 0x74530e81E9f4715c720b6b237f682CD0e298B66C
Sources
- RemitanoPrimary · retrieved 2026-08-01
- MariblockSecondary · retrieved 2026-08-01
- CryptoPotatoSecondary · retrieved 2026-08-01
- crypto.newsSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Remitano hack — September 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/remitanohttps://itokenly.com/hacks/remitanoPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.