CoinsPaid Faces Second Security Breach, Cybercriminals Steal $7.5 Million

In a disheartening turn of events, CoinsPaid, a prominent crypto payment gateway, has fallen victim to yet another security breach, marking its second in the last six months. This unfortunate incident comes hot on the heels of a previous hack in July 2023, where hackers managed to infiltrate the platform and abscond with a staggering $37 billion. As cybersecurity threats persist, businesses operating in the digital asset arena face mounting pressure to fortify their security measures.

Details of the Breach

Web3 security firm Cyvers was quick to detect unauthorized transactions, totaling nearly $7.5 million, within CoinsPaid’s system. It appears that the attacker exploited vulnerabilities within the platform, allowing them to swap around 97 million CPD tokens, equivalent to roughly $368,000, for ETH. Subsequently, the stolen funds were conveniently transferred to externally owned accounts (EOAs) and crypto exchanges, effectively obfuscating their path and complicating the recovery process for those affected.

Upon conducting further analysis, Cyvers uncovered yet more unauthorized transactions involving BNB, the native cryptocurrency of the Binance exchange. These additional transactions amounted to over $1 million, pushing the total stolen close to $7.5 million. This revelation compounds the severity of the breach, underscoring the sophistication and persistence of the cybercriminals responsible.

Background of CoinsPaid

CoinsPaid, an Estonian payment processor specialized in facilitating transactions involving digital assets, boasts an impressive track record. Having processed over 19 billion euros in crypto transactions, CoinsPaid has established itself as a trusted intermediary within the cryptocurrency ecosystem. However, these recent security breaches have undoubtedly shaken confidence in the platform’s security measures.

Previous Security Breach in July 2023

Merely six months prior to this most recent security breach, CoinsPaid fell victim to a devastating attack orchestrated by cybercriminals. The hackers ingeniously exploited the unsuspecting nature of one of the platform’s employees by luring them into a fake job interview. Carrying out their malicious intent, the hackers tricked the employee into downloading a malicious code, effectively granting them unrestricted access to CoinsPaid’s internal infrastructure, leading to the theft of over $37 billion.

CoinsPaid placed the blame for the previous breach on the North Korean state-backed Lazarus Group, a notorious cybercrime syndicate known for its involvement in various high-profile hacking incidents worldwide. By leveraging their extensive resources and sophisticated hacking techniques, the Lazarus Group managed to siphon an estimated $600 million worth of cryptocurrency in 2023 alone.

Lazarus Group’s Involvement in Crypto Hacks

The Lazarus Group’s nefarious exploits have made headlines in the crypto community throughout 2023. Their persistent targeting of digital asset platforms highlights the need for robust security protocols within the industry. As cryptocurrency continues to gain mainstream acceptance, organizations must remain vigilant and prioritize cybersecurity to protect their users’ assets.

Lack of Comment from CoinsPaid on the Recent Attack

As news of the recent security breach spread, CoinsPaid has yet to issue any statements or comments regarding the incident. This silence raises concerns about the platform’s commitment to transparency and leaves affected users and industry observers in limbo. Prompt and honest communication from CoinsPaid is vital at this critical juncture to maintain trust and assure customers that remedial measures are being taken.

The recurrence of security breaches at CoinsPaid underscores the ever-present threat faced by businesses operating in the crypto ecosystem. As the adoption of digital assets continues to rise, it is imperative that organizations remain proactive and implement robust security measures to protect user funds. The recent breaches at CoinsPaid serve as a stark reminder of the need for constant vigilance and stringent security protocols within the cryptocurrency industry. By prioritizing cybersecurity, both platforms and users can mitigate risks and foster a safer environment for conducting crypto transactions.

Explore more

Advancing Drug Discovery Through HTS Automation and Robotics

The technological landscape of modern drug discovery has been fundamentally altered by the maturation of High-Throughput Screening automation that now dictates the pace of global health innovation. In the high-stakes environment of pharmaceutical research, processing a library of millions of compounds by hand is no longer a feasible task; it is a mathematical impossibility. While traditional pipetting once defined the

NPF Calls for Modernizing the Slow RCMP Hiring Process

The safety of a nation depends on the people willing to protect it, yet thousands of capable Canadians are currently stranded in a bureaucratic limbo that stretches for nearly a year. While over 46,000 citizens have raised their hands to serve in the Royal Canadian Mounted Police, a staggering backlog is preventing these volunteers from ever reaching the front lines.

How Did Aleksei Volkov Fuel the Global Ransomware Market?

The sentencing of Aleksei Volkov marks a significant milestone in the ongoing battle against the specialized layers of the cybercrime ecosystem. As an initial access broker, Volkov served as a critical gateway, facilitating devastating attacks by groups like Yanluowang against major global entities. This discussion explores the mechanics of his operations, the nuances of international cyber-law enforcement, and the shifting

Who Is Handala, the Cyber Group Linked to Iranian Intelligence?

The digital landscape of 2026 faces a sophisticated evolution in state-sponsored espionage as the group known as Handala emerges as a primary operative arm of the Iranian Ministry of Intelligence and Security. This collective has transitioned from a niche threat into a formidable force by executing complex hack-and-leak operations that primarily target journalists, political dissidents, and international opposition groups. The

NetScaler Security Vulnerabilities – Review

The modern digital perimeter is only as resilient as the specialized hardware guarding its gates, yet recent discoveries in NetScaler architecture suggest that even the most trusted sentinels possess catastrophic blind spots. As organizations consolidate their networking stacks, the NetScaler application delivery controller has moved from being a simple load balancer to the primary gatekeeper for enterprise resource management. This