Community Trust ScoreVerified
Indian cryptocurrency exchange CoinDCX has suffered a significant security breach, resulting in a loss of over $44 million. The attack, which took place on July 18, 2025, targeted the exchange’s internal operations account, but customer funds reportedly remain unaffected.
The breach was first brought to light by on-chain investigator ZachXBT, who revealed the incident nearly 17 hours after it occurred. The crypto sleuth posted on Telegram that a suspicious transfer of approximately $44.2 million had been traced back to CoinDCX. Shortly after, the platform’s co-founder, Sumit Gupta, confirmed the breach and provided further details.
According to Gupta, the attacker exploited a vulnerability in the server to gain access to an internal CoinDCX account. This account was specifically used to provide liquidity on a partner trading platform and did not store any customer deposits.
“I confirm that CoinDCX wallets storing customer assets were unaffected and remain completely safe,” Gupta said in a statement. He assured the community that the incident was swiftly contained and that the losses were isolated to just one account. All damages, he added, would be covered by the company’s treasury, ensuring there would be no financial impact on users.
Exchange Operations Continue Uninterrupted
Despite the scale of the breach, CoinDCX stated that its trading operations were not disrupted. Deposits and withdrawals on the platform continued to function as normal, providing some reassurance to its user base during a time of heightened concern over digital asset security.
To manage the fallout, the company has hired third-party cybersecurity specialists to analyze the incident and strengthen their security protocols. CoinDCX is also working closely with its partner exchange in an effort to trace and recover the stolen funds.
“We’re doing everything possible to track these assets and coordinate with law enforcement and exchanges that might come into contact with the attacker’s wallet,” said Gupta.
Another Blow to India’s Crypto Confidence
The CoinDCX breach comes almost exactly one year after WazirX—another major Indian crypto exchange—was compromised in a separate hack that saw roughly $235 million vanish. Despite WazirX announcing in April 2025 that it would resume operations, it has yet to fully reopen its platform.
These high-profile attacks have raised serious concerns about security in India’s crypto industry, especially as the country moves toward clearer regulation and increasing adoption. Users and industry observers alike are urging platforms to invest more heavily in safeguarding digital assets and tightening internal protocols.
Rising Global Losses from Crypto Hacks
CoinDCX’s hack is part of a much broader trend of cybercrime affecting the global crypto landscape. In the first half of 2025 alone, hackers have reportedly stolen over $2.1 billion from various platforms. One of the largest incidents this year was the February breach of the Bybit exchange, which lost $1.5 billion—a hack also flagged early by ZachXBT.
These numbers underscore the ongoing vulnerability of even well-established crypto platforms and highlight the need for comprehensive security reforms across the industry.
What’s Next for CoinDCX?
For now, CoinDCX has managed to calm immediate fears by confirming the safety of user funds and continuing normal operations. However, trust must be rebuilt. How quickly the platform recovers—both financially and reputationally—will depend on the outcome of its ongoing investigation and its ability to implement stronger safeguards moving forward.
Gupta and his team have not released a timeline for when they expect to complete the recovery process, but the public’s response will likely be influenced by how transparent and proactive CoinDCX remains in the coming weeks.
As the Indian crypto space grows, these incidents serve as a stark reminder: while digital assets may offer financial innovation, they also come with high-stakes risks that must be managed with the utmost seriousness.




