Crypto Exchange Deribit Hacked for $28M in Bitcoin, Ethereum, USDC
Crypto futures and options exchange Deribit suffered a security breach on Tuesday around midnight, with hackers making off with nearly $28 million from the exchange’s hot wallet.
Exchanges often use hot wallets to process withdrawals instantly. These kinds of wallets come with high risk, however, as their private keys are stored in a company’s servers to sign withdrawal transactions.
In a statement on Twitter, the Panama-based exchange stated that their hot wallet got hacked for $28 million, but the client assets and cold storage addresses were not affected.
Deribit hot wallet compromised, but client funds are safe and loss is covered by company reserves
Our hot wallet was hacked for USD 28m earlier this evening just before midnight UTC on 1 November 2022.
While nearly $28 million has been stolen by the hacker, Deribit noted that “the hack is isolated to their BTC, ETH, and USDC hot wallets.”
The hacker made 691 BTC and 9,111.59 ETH from the hack, with the USDC nabbedbeing quickly converted to Ethereum. The funds are now held in two wallets across Bitcoin and Ethereum. The funds are not moved to any mixer (or) laundering service as of this writing.
The company has assured users that they’re still in a “financially sound position” and its reserves cover the loss without affecting the insurance fund.
Insurance fund
The insurance fund will not be impacted, the loss will be paid by company reserves. Deribit remains in a financially sound position and ongoing operations will not be impacted.
Deribit stated that “they are performing ongoing security checks” and have halted withdrawals from the exchange.
The company has also advised against depositing new funds. Deribit said that the “Deposits already sent will still be processed, and after the required number of confirmations, they will be credited to accounts.”
We have raised the minimum number of confirmations for the moment causing a delay in crediting funds. Until we open wallets again we request you not to send new deposits.