Skip to content
Back to journal
CoinDCX24 Aug 2026

Was the CoinDCX Hack Customer Money? What Actually Got Taken in July 2025

No, the July 2025 CoinDCX hack did not touch customer funds. It took 44.3 million dollars from an operational wallet. Customer funds stayed in cold storage.

RudraResearch note 5 min read
Two rectangular compartments pressed out of one dark neumorphic surface, one sealed and unbroken, the other cracked open along one edge, beside the text One wallet breached, one untouched, the custody line held

The point

No. Hackers took 44.3 million dollars from CoinDCX in July 2025, and none of it was customer money. The stolen funds came out of an internal operational wallet, the account CoinDCX used to manage liquidity with a partner exchange. Customer holdings sat in cold storage the whole time, untouched. CoinDCX said it absorbed the full loss from its own treasury reserves. On the question that brought most readers here, the honest answer favours CoinDCX.

What "customer funds" and "operational wallet" actually mean

Every crypto exchange holds two different kinds of crypto, and the difference decides whose money is at risk when something goes wrong.

Customer funds are what you deposited. The exchange owes them back to you on demand, in full, whenever you ask to withdraw. An operational or liquidity wallet is different. It is the exchange's own working capital. The exchange uses it to move crypto quickly between itself and its trading partners, so that buy and sell orders settle without delay.

CoinDCX's own account of the breach named the affected wallet as an account "used only for liquidity provisioning on a partner exchange," kept apart from where customer deposits sit. This is the custody model working as intended. The two pools of money stay apart on paper and in practice. A breach in one does not automatically become a loss in the other.

The same wallet separation question applies wherever you hold crypto, including inside a Qatobit basket.

What worked: the wall between customer money and the breach

Three things happened in the right order, and each one is checkable.

CoinDCX said customer assets stayed in cold wallets and were never touched. Cold storage means the keys are not connected to the internet, so a server breach elsewhere cannot reach them.

The company said it isolated the affected operational account as soon as the breach was found. That kept the exposure limited to a single account.

CoinDCX said the entire 44.3 million dollar loss would be absorbed from its own treasury reserves. No customer bore any part of the cost. That is the plainest evidence the separation was real. The company is the one paying for the mistake.

What did not work: how the attacker got in

The breach did not start with a smart contract flaw or a cracked wallet address. It started with a person.

According to police investigators, the attackers used a fake freelance job offer to get a CoinDCX employee to install malware on a work laptop. That malware gave them a way into the internal systems used to manage CoinDCX's liquidity operations. From there, Halborn's post-mortem found the attackers drained the wallet across multiple transactions inside about five minutes.

This is a variant of the same phishing tactics retail investors are warned about, aimed at an employee instead of a customer. The weakest point in most breaches is a person being tricked.

CoinDCX also was not the one to spot it first. An outside researcher flagged the unusual wallet activity roughly seventeen hours before CoinDCX said anything in public. The affected wallet also had not appeared in the exchange's own proof of reserves documentation before the breach. Both are fair criticisms, and both are separate from the question of whose money was at risk.

The custody separation checklist: five checks that work on any platform

You do not need to be a security researcher to check this yourself, on CoinDCX, on any competitor, or on Qatobit.

Does the platform name its wallets separately, in public?

CoinDCX's own disclosure specified plainly that the breached wallet was an operational account. A platform that can say this precisely, in the middle of a crisis, has almost certainly built the separation long before the crisis.

Is the proof of reserves live, or a snapshot from last quarter?

Proof of reserves only tells you something if it is checkable right now, rather than a static PDF from three months ago. A live figure you can check today is a different claim from a one time audit.

What share of assets sits in cold storage versus a hot wallet?

There is no universal right answer. More cold storage is safer and slower. More in a hot wallet is faster and more exposed. What matters is whether the platform tells you the split at all.

When something goes wrong, does the disclosure say which wallet was hit?

CoinDCX's statement named the wallet type immediately. That specificity is itself informative. A vaguer statement, one that never says whose funds were exposed, tells you less about the platform's own understanding of its risk.

Who absorbs a loss on the operational side, you or the platform?

This is the question that decides everything else. Qatobit's own accounting works on the same principle. Customer holdings sit in institutional custody, kept apart from any operational account, with reserves published live rather than on request. The structure itself is the point.

The tension underneath: speed needs a hot wallet, safety wants cold storage

No exchange runs entirely on cold storage. Withdrawals, market making, and moving crypto between trading partners all need funds that can move in seconds. That means some crypto always has to sit in a wallet connected to the internet.

That tradeoff is a normal part of running an exchange, rather than evidence that crypto itself is unsafe. Any platform holding your money is also running an operational business behind it, exposed to its own risks.

If you are about to choose a platform for the first time, the same custody question belongs on your checklist before the price does. Ask where the split sits, and ask whether the answer is written down anywhere before you need it to be true.

Frequently asked questions

Was any customer money taken in the CoinDCX hack?

No. CoinDCX said the 44.3 million dollars taken in July 2025 came from an internal operational wallet used for liquidity. Customer funds stayed separately in cold storage and were not affected.

How much was stolen in the CoinDCX hack, and when?

CoinDCX lost 44.3 million dollars, taken across multiple transactions inside about five minutes on July 18, 2025, according to Halborn's post-mortem.

How did the attackers get into CoinDCX's systems?

Police investigators said the attackers used a fake freelance job offer to get a CoinDCX employee to install malware on a work laptop. That gave them access to the systems managing the exchange's liquidity operations.

Did CoinDCX customers pay for the loss?

No. CoinDCX said it absorbed the full 44.3 million dollar loss from its own treasury reserves. Customer funds and fees were untouched.

What did CoinDCX offer for the return of the stolen funds?

On July 21, 2025, CoinDCX said it would pay up to 25 percent of any recovered funds to whoever helps trace and retrieve the stolen crypto.

Crypto investments are subject to market risk. Not financial advice.

“A better allocation begins with a better explanation.”

Qatobit principle

Published construction. Fixed cadence. Versioned control.