CoinsPaid Faces Second Security Breach, Cybercriminals Steal $7.5 Million

In a disheartening turn of events, CoinsPaid, a prominent crypto payment gateway, has fallen victim to yet another security breach, marking its second in the last six months. This unfortunate incident comes hot on the heels of a previous hack in July 2023, where hackers managed to infiltrate the platform and abscond with a staggering $37 billion. As cybersecurity threats persist, businesses operating in the digital asset arena face mounting pressure to fortify their security measures.

Details of the Breach

Web3 security firm Cyvers was quick to detect unauthorized transactions, totaling nearly $7.5 million, within CoinsPaid’s system. It appears that the attacker exploited vulnerabilities within the platform, allowing them to swap around 97 million CPD tokens, equivalent to roughly $368,000, for ETH. Subsequently, the stolen funds were conveniently transferred to externally owned accounts (EOAs) and crypto exchanges, effectively obfuscating their path and complicating the recovery process for those affected.

Upon conducting further analysis, Cyvers uncovered yet more unauthorized transactions involving BNB, the native cryptocurrency of the Binance exchange. These additional transactions amounted to over $1 million, pushing the total stolen close to $7.5 million. This revelation compounds the severity of the breach, underscoring the sophistication and persistence of the cybercriminals responsible.

Background of CoinsPaid

CoinsPaid, an Estonian payment processor specialized in facilitating transactions involving digital assets, boasts an impressive track record. Having processed over 19 billion euros in crypto transactions, CoinsPaid has established itself as a trusted intermediary within the cryptocurrency ecosystem. However, these recent security breaches have undoubtedly shaken confidence in the platform’s security measures.

Previous Security Breach in July 2023

Merely six months prior to this most recent security breach, CoinsPaid fell victim to a devastating attack orchestrated by cybercriminals. The hackers ingeniously exploited the unsuspecting nature of one of the platform’s employees by luring them into a fake job interview. Carrying out their malicious intent, the hackers tricked the employee into downloading a malicious code, effectively granting them unrestricted access to CoinsPaid’s internal infrastructure, leading to the theft of over $37 billion.

CoinsPaid placed the blame for the previous breach on the North Korean state-backed Lazarus Group, a notorious cybercrime syndicate known for its involvement in various high-profile hacking incidents worldwide. By leveraging their extensive resources and sophisticated hacking techniques, the Lazarus Group managed to siphon an estimated $600 million worth of cryptocurrency in 2023 alone.

Lazarus Group’s Involvement in Crypto Hacks

The Lazarus Group’s nefarious exploits have made headlines in the crypto community throughout 2023. Their persistent targeting of digital asset platforms highlights the need for robust security protocols within the industry. As cryptocurrency continues to gain mainstream acceptance, organizations must remain vigilant and prioritize cybersecurity to protect their users’ assets.

Lack of Comment from CoinsPaid on the Recent Attack

As news of the recent security breach spread, CoinsPaid has yet to issue any statements or comments regarding the incident. This silence raises concerns about the platform’s commitment to transparency and leaves affected users and industry observers in limbo. Prompt and honest communication from CoinsPaid is vital at this critical juncture to maintain trust and assure customers that remedial measures are being taken.

The recurrence of security breaches at CoinsPaid underscores the ever-present threat faced by businesses operating in the crypto ecosystem. As the adoption of digital assets continues to rise, it is imperative that organizations remain proactive and implement robust security measures to protect user funds. The recent breaches at CoinsPaid serve as a stark reminder of the need for constant vigilance and stringent security protocols within the cryptocurrency industry. By prioritizing cybersecurity, both platforms and users can mitigate risks and foster a safer environment for conducting crypto transactions.

Explore more

Why Are Big Data Engineers Vital to the Digital Economy?

In a world where every click, swipe, and sensor reading generates a data point, businesses are drowning in an ocean of information—yet only a fraction can harness its power, and the stakes are incredibly high. Consider this staggering reality: companies can lose up to 20% of their annual revenue due to inefficient data practices, a financial hit that serves as

How Will AI and 5G Transform Africa’s Mobile Startups?

Imagine a continent where mobile technology isn’t just a convenience but the very backbone of economic growth, connecting millions to opportunities previously out of reach, and setting the stage for a transformative era. Africa, with its vibrant and rapidly expanding mobile economy, stands at the threshold of a technological revolution driven by the powerful synergy of artificial intelligence (AI) and

Saudi Arabia Cuts Foreign Worker Salary Premiums Under Vision 2030

What happens when a nation known for its generous pay packages for foreign talent suddenly tightens the purse strings? In Saudi Arabia, a seismic shift is underway as salary premiums for expatriate workers, once a hallmark of the kingdom’s appeal, are being slashed. This dramatic change, set to unfold in 2025, signals a new era of fiscal caution and strategic

DevSecOps Evolution: From Shift Left to Shift Smart

Introduction to DevSecOps Transformation In today’s fast-paced digital landscape, where software releases happen in hours rather than months, the integration of security into the software development lifecycle (SDLC) has become a cornerstone of organizational success, especially as cyber threats escalate and the demand for speed remains relentless. DevSecOps, the practice of embedding security practices throughout the development process, stands as

AI Agent Testing: Revolutionizing DevOps Reliability

In an era where software deployment cycles are shrinking to mere hours, the integration of AI agents into DevOps pipelines has emerged as a game-changer, promising unparalleled efficiency but also introducing complex challenges that must be addressed. Picture a critical production system crashing at midnight due to an AI agent’s unchecked token consumption, costing thousands in API overuse before anyone