ChainBleedv0.1 · open intel
← back to feed·PRIVATE-KEY2021-04-16 · 5y ago
Incident · SLOWMIST

Celsius

Information Leakage
Estimated loss
VERDICT —OUT OF SCOPE
Root cause is private-key / signer compromise — the on-chain contract behaved exactly as written. No pre-deployment source audit or bytecode review reaches the key-custody perimeter; this is operational-security territory (HSM/MPC hygiene, key rotation, hot-wallet isolation). Bytecode would show nothing wrong.
▰ METHOD
PRIVATE KEY
PRIVATE-KEY
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

Encrypted lending service Celsius has discovered a data breach in one of its third-party service providers, which has exposed the personal information of its customers. According to the email, the hacker gained access to the "third-party email distribution system" used by Celsius. Hackers use this information to send fraudulent emails and text messages to trick them into revealing the private keys of their funds. On April 14, Celsius users started reporting a fraudulent website claiming to be the official Celsius platform. Some users also receive text messages and emails claiming to be Celsius official, can link to the website, and prompt the recipient to enter sensitive information. It is reported that Celsius' competitor BlockFi suffered a similar data breach last spring. Attack method (per SlowMist): Information Leakage. Reported loss: -.

Primary source
https://www.coindesk.com/markets/2021/04/15/celsius-suffers-third-party-data-breach-customers-report-phishing-texts-emails/
Sourced from
slowmist
Technical record
chain
protocol
Celsius
bug_class
private-key
date_occurred
2021-04-16
loss_usd
source_id
sm:celsius::2021-04-16
Related — same bug class· private-key
2026-04-30
1mo ago
MULTI
Wasabi Perps
Admin Key Compromised
private-key
$5.50M
OUT OF SCOPE
2026-04-30
1mo ago
ETH
Wasabi Protocol
Private Key Leakage
private-key
$5.70M
OUT OF SCOPE
2026-04-29
1mo ago
Syndicate Labs
Private Key Leakage
private-key
$380.0K
OUT OF SCOPE
2026-04-21
1mo ago
SUI
Volo Vault
Admin Key Compromised
private-key
$3.50M
OUT OF SCOPE
2026-04-21
1mo ago
SUI
Volo Vaults
Private Key Leakage
private-key
$3.50M
OUT OF SCOPE
2026-04-16
1mo ago
MULTI
Grinex
Hot wallet hack
private-key
$15.00M
OUT OF SCOPE
ChainBleed — live web3 threat intelligence