ChainBleedv0.1 · open intel
← back to feed·ETHPRIVATE-KEY2020-09-26 · 5y ago
Incident · SLOWMIST

KuCoin

Wallet Stolen
Estimated loss
$150.00M
VERDICT —OUT OF SCOPE
Root cause is private-key / signer compromise — the on-chain contract behaved exactly as written. No pre-deployment source audit or bytecode review reaches the key-custody perimeter; this is operational-security territory (HSM/MPC hygiene, key rotation, hot-wallet isolation). Bytecode would show nothing wrong.
▰ METHOD
PRIVATE KEY
PRIVATE-KEY
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

KuCoin exchange issued an announcement stating that KuCoin detected large withdrawals of Bitcoin and ERC-20 tokens in multiple hot wallets in the early morning of the 26th, and the deposit and withdrawal services have been suspended. KuCoin stated that the total amount involved in the KuCoin platform accounts for a relatively low proportion of the total funds held on the KuCoin platform, and the assets in the KuCoin cold wallet are not affected. At the same time, KuCoin has redeployed the hot wallet for the first time. KuCoin officially stated that if any user suffers losses in this incident, KuCoin and its insurance fund will be fully borne by KuCoin. KuCoin has now started a comprehensive internal security review. During this period, the deposit and withdrawal services will be suspended. The specific opening time will be Further notice. Kucoin said it will announce more details as soon as possible. As previously reported, starting at 2:49 am Beijing time on September 26, Etherscan marked the address of the cryptocurrency exchange KuCoin to transfer a large number of tokens, including MKR, USDT, OCEN, etc., to a new address beginning with 0xeb31973e0f. Including 11,486 Ethereum, 19,788,586 USDT, 525,405 Gladius (GLA), 77,874 Hawala (HAT), 21,660,274 Ocean Token (OCEAN), 8,893,428 Chroma (CHR), 30,452,178 Ampleforth Network (AMPL), 198,678 Ankr (ANKR) etc. Attack method (per SlowMist): Wallet Stolen. Reported loss: $ 150,000,000.

Primary source
https://www.zdnet.com/article/kucoin-cryptocurrency-exchange-hacked-for-150-million/
Sourced from
slowmist
Technical record
chain
ethereum
protocol
KuCoin
bug_class
private-key
date_occurred
2020-09-26
loss_usd
$150,000,000
source_id
sm:kucoin::2020-09-26
Related — same bug class· private-key
2026-04-30
1mo ago
MULTI
Wasabi Perps
Admin Key Compromised
private-key
$5.50M
OUT OF SCOPE
2026-04-30
1mo ago
ETH
Wasabi Protocol
Private Key Leakage
private-key
$5.70M
OUT OF SCOPE
2026-04-29
1mo ago
Syndicate Labs
Private Key Leakage
private-key
$380.0K
OUT OF SCOPE
2026-04-21
1mo ago
SUI
Volo Vault
Admin Key Compromised
private-key
$3.50M
OUT OF SCOPE
2026-04-21
1mo ago
SUI
Volo Vaults
Private Key Leakage
private-key
$3.50M
OUT OF SCOPE
2026-04-16
1mo ago
MULTI
Grinex
Hot wallet hack
private-key
$15.00M
OUT OF SCOPE
ChainBleed — live web3 threat intelligence