CoinsPaid Faces Second Security Breach, Cybercriminals Steal $7.5 Million

In a disheartening turn of events, CoinsPaid, a prominent crypto payment gateway, has fallen victim to yet another security breach, marking its second in the last six months. This unfortunate incident comes hot on the heels of a previous hack in July 2023, where hackers managed to infiltrate the platform and abscond with a staggering $37 billion. As cybersecurity threats persist, businesses operating in the digital asset arena face mounting pressure to fortify their security measures.

Details of the Breach

Web3 security firm Cyvers was quick to detect unauthorized transactions, totaling nearly $7.5 million, within CoinsPaid’s system. It appears that the attacker exploited vulnerabilities within the platform, allowing them to swap around 97 million CPD tokens, equivalent to roughly $368,000, for ETH. Subsequently, the stolen funds were conveniently transferred to externally owned accounts (EOAs) and crypto exchanges, effectively obfuscating their path and complicating the recovery process for those affected.

Upon conducting further analysis, Cyvers uncovered yet more unauthorized transactions involving BNB, the native cryptocurrency of the Binance exchange. These additional transactions amounted to over $1 million, pushing the total stolen close to $7.5 million. This revelation compounds the severity of the breach, underscoring the sophistication and persistence of the cybercriminals responsible.

Background of CoinsPaid

CoinsPaid, an Estonian payment processor specialized in facilitating transactions involving digital assets, boasts an impressive track record. Having processed over 19 billion euros in crypto transactions, CoinsPaid has established itself as a trusted intermediary within the cryptocurrency ecosystem. However, these recent security breaches have undoubtedly shaken confidence in the platform’s security measures.

Previous Security Breach in July 2023

Merely six months prior to this most recent security breach, CoinsPaid fell victim to a devastating attack orchestrated by cybercriminals. The hackers ingeniously exploited the unsuspecting nature of one of the platform’s employees by luring them into a fake job interview. Carrying out their malicious intent, the hackers tricked the employee into downloading a malicious code, effectively granting them unrestricted access to CoinsPaid’s internal infrastructure, leading to the theft of over $37 billion.

CoinsPaid placed the blame for the previous breach on the North Korean state-backed Lazarus Group, a notorious cybercrime syndicate known for its involvement in various high-profile hacking incidents worldwide. By leveraging their extensive resources and sophisticated hacking techniques, the Lazarus Group managed to siphon an estimated $600 million worth of cryptocurrency in 2023 alone.

Lazarus Group’s Involvement in Crypto Hacks

The Lazarus Group’s nefarious exploits have made headlines in the crypto community throughout 2023. Their persistent targeting of digital asset platforms highlights the need for robust security protocols within the industry. As cryptocurrency continues to gain mainstream acceptance, organizations must remain vigilant and prioritize cybersecurity to protect their users’ assets.

Lack of Comment from CoinsPaid on the Recent Attack

As news of the recent security breach spread, CoinsPaid has yet to issue any statements or comments regarding the incident. This silence raises concerns about the platform’s commitment to transparency and leaves affected users and industry observers in limbo. Prompt and honest communication from CoinsPaid is vital at this critical juncture to maintain trust and assure customers that remedial measures are being taken.

The recurrence of security breaches at CoinsPaid underscores the ever-present threat faced by businesses operating in the crypto ecosystem. As the adoption of digital assets continues to rise, it is imperative that organizations remain proactive and implement robust security measures to protect user funds. The recent breaches at CoinsPaid serve as a stark reminder of the need for constant vigilance and stringent security protocols within the cryptocurrency industry. By prioritizing cybersecurity, both platforms and users can mitigate risks and foster a safer environment for conducting crypto transactions.

Explore more

Mabl Enhances Failure Analysis for Enterprise DevOps

When a critical test suite collapses minutes before a major deployment window closes, quality engineering teams often find themselves trapped in a high-pressure race against the clock to decipher cryptic error logs. Software delivery speed frequently hits a wall because traditional automation identifies that a break occurred without explaining why. This leaves engineers sifting through fragmented data to find a

How Will Copado Agentia Transform Salesforce DevOps?

The relentless pressure to deliver flawless enterprise software at breakneck speeds has finally pushed traditional manual release management toward a breaking point of unsustainable complexity. As organizations grapple with thousands of metadata components and overlapping dependencies, the necessity for a smarter approach has become undeniable. Copado Agentia represents this pivotal shift, introducing a suite of AI agents specifically engineered to

EEOC Sues Construction Firm for National Origin Bias

The intersection of cultural identity and professional advancement has recently become a volatile flashpoint in the American construction industry, revealing deep-seated biases that challenge traditional definitions of discrimination. When Robert Gutierrez, a Mexican-American employee at Advanced Technology Group in Rio Rancho, New Mexico, accepted a promotion in June 2023, he likely viewed the milestone as a reward for his dedication

Is Reaper the New Face of macOS Malware Threats?

The rapid evolution of sophisticated cyber threats targeting the macOS ecosystem has reached a critical juncture with the emergence of a new malware variant known as Reaper. This particular strain represents a significant departure from traditional macOS threats by specifically engineering its delivery and execution methods to bypass modern security protocols like those found in Tahoe 26.4. Unlike its predecessors,

Windows 11 Update Will Allow Users to Remap the Copilot Key

The landscape of personal computing is currently undergoing its most radical transformation in decades as hardware manufacturers attempt to bridge the gap between traditional productivity and generative artificial intelligence. Microsoft has recently signaled a major shift in its strategy by announcing that users will soon have the ability to remap the dedicated Copilot key, a physical addition that was initially