T
iTokenly

Remitano hack — September 2023

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedSeptember 14, 2023
Target typeCentralised exchange
Loss$2,700,000Price at time of incident
Recovered$1,400,000
MethodPrivate key compromiseCompromise of the exchange's Ethereum hot wallet keys, used to make unauthorised withdrawals to a freshly created address (0x74530e81E9f4715c720b6b237f682CD0e298B66C) with no prior transaction history. Remitano has never disclosed how the keys were obtained.
ChainsEthereum
OutcomePartially recovered

What happened

Remitano, a Seychelles-registered peer-to-peer exchange with large user bases in Vietnam and Nigeria, lost funds from its hot wallets on 14 September 2023. Blockchain monitoring firm Cyvers flagged the outflows publicly, saying more than $2.7 million had been moved to a freshly created address, which had no prior transaction history. The transfers itemised in contemporaneous reporting were on Ethereum: roughly $1.4 million in USDT, about $208,000 in USDC and 104,000 ANKR worth around $2,000. Those components total substantially less than the $2.7 million headline and no source published a breakdown of the remainder, so the total rests on Cyvers' figure alone. Remitano said its Bitcoin, Bitcoin Cash and Litecoin balances were unaffected and transfers on those chains continued. Tether froze the address holding roughly $1.4 million in USDT, preventing that portion from moving further. Remitano acknowledged the incident, describing it as a small amount of funds moved from its hot wallets to suspicious addresses through unauthorised withdrawal transactions, and said it had suspended deposits and withdrawals, moved remaining balances to cold storage, deactivated the compromised addresses and worked with Cyvers and Tether on monitoring and freezing. The exchange's characterisation of the size of the loss is noticeably softer than Cyvers', and Remitano never published its own figure. How the keys were obtained has not been disclosed, and no actor has been identified. Some commentary at the time speculated about North Korean involvement given the run of exchange hacks that month, but no security firm or government body has published an attribution for this incident.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Attacker addresses

  • 0x74530e81E9f4715c720b6b237f682CD0e298B66C

Sources

  1. RemitanoPrimary · retrieved 2026-08-01
  2. MariblockSecondary · retrieved 2026-08-01
  3. CryptoPotatoSecondary · retrieved 2026-08-01
  4. crypto.newsSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Remitano hack — September 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/remitano
https://itokenly.com/hacks/remitano

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.