Deribit Pauses Withdrawals Following $28M Hot Wallet Hack

  • The hack took place around midnight on 1 November, when a malicious actor was able to access Deribit’s hot wallets and steal $28 million worth of BTC, ETH, and USDC.
  • The company noted that client assets were safe, as they were kept in cold storage, and that the loss will be covered by its own reserves.
deribit

Shutterstock

Cryptocurrency derivatives exchange Deribit has suffered from a hack that saw $28 million worth of tokens being drained from its hot wallet, the company said in a Twitter thread on 2 November.

According to the announcement, the hack took place before midnight on 1 November, compromising Deribit’s Bitcoin (BTC), Ether (ETH), and USD Coin (USDC) hot wallets, which contained tokens worth around $28 million. The exchange has since halted all withdrawals on the platform — including those from third-party custodians Copper, Clearloop, and Cobo — and is currently performing ongoing security checks.

Withdrawals will remain closed until Deribit is 100% sure that the vulnerability has been removed, and that the platform is once again safe for use. The exchange has also assured users that their digital assets were safe as Deribit had a policy to keep 99% of all client funds in cold store — which were not affected by the hack — to limit the impact of “these type of events”. It also noted that any losses will be covered by the company reserves as to not affect its insurance funds.

The crypto derivatives exchange is the latest in a long list of companies to be impacted by malicious actors targeting crypto platforms this year. October was especially bad, becoming the biggest month for crypto crime ever, with $718 million being stolen across 11 hacks and exploits in its first two weeks alone.

Discussion
Related Coverage
Unibot to Compensate Users Affected by Exploit
  • Popular Telegram bot Unibot, which is used to snipe trades on Uniswap, became a victim of a token approval exploit earlier today, when it was switching to a new router.
  • After confirming the exploit, Unibot assured users that their keys and wallets were safe, and that the project will compensate all affected users.
October 31, 2023, 3:01 PM
unlock

Shutterstock

Balancer Exploited After Giving Warning
  • DeFi protocol Balancer confirmed it was exploited almost a week after disclosing a critical vulnerability affecting several of its boosted pools.
  • The platform did its best to mitigate some of the risks but was unable to pause the affected pools, and an estimated $980,000 in DAI were stolen in an attack.
Kroll Data Breach Compromises FTX, BlockFi Customer Information
  • A cyber security incident at bankruptcy service provider Kroll has resulted in the exposure of “non-sensitive” customer data for claimants involved in the FTX and BlockFi cases.
  • Both companies confirmed that account passwords, systems, and funds remained safe, but warned customers to be on the lookout for phishing scams.