CoinsPaid Faces Second Security Breach, Cybercriminals Steal $7.5 Million

In a disheartening turn of events, CoinsPaid, a prominent crypto payment gateway, has fallen victim to yet another security breach, marking its second in the last six months. This unfortunate incident comes hot on the heels of a previous hack in July 2023, where hackers managed to infiltrate the platform and abscond with a staggering $37 billion. As cybersecurity threats persist, businesses operating in the digital asset arena face mounting pressure to fortify their security measures.

Details of the Breach

Web3 security firm Cyvers was quick to detect unauthorized transactions, totaling nearly $7.5 million, within CoinsPaid’s system. It appears that the attacker exploited vulnerabilities within the platform, allowing them to swap around 97 million CPD tokens, equivalent to roughly $368,000, for ETH. Subsequently, the stolen funds were conveniently transferred to externally owned accounts (EOAs) and crypto exchanges, effectively obfuscating their path and complicating the recovery process for those affected.

Upon conducting further analysis, Cyvers uncovered yet more unauthorized transactions involving BNB, the native cryptocurrency of the Binance exchange. These additional transactions amounted to over $1 million, pushing the total stolen close to $7.5 million. This revelation compounds the severity of the breach, underscoring the sophistication and persistence of the cybercriminals responsible.

Background of CoinsPaid

CoinsPaid, an Estonian payment processor specialized in facilitating transactions involving digital assets, boasts an impressive track record. Having processed over 19 billion euros in crypto transactions, CoinsPaid has established itself as a trusted intermediary within the cryptocurrency ecosystem. However, these recent security breaches have undoubtedly shaken confidence in the platform’s security measures.

Previous Security Breach in July 2023

Merely six months prior to this most recent security breach, CoinsPaid fell victim to a devastating attack orchestrated by cybercriminals. The hackers ingeniously exploited the unsuspecting nature of one of the platform’s employees by luring them into a fake job interview. Carrying out their malicious intent, the hackers tricked the employee into downloading a malicious code, effectively granting them unrestricted access to CoinsPaid’s internal infrastructure, leading to the theft of over $37 billion.

CoinsPaid placed the blame for the previous breach on the North Korean state-backed Lazarus Group, a notorious cybercrime syndicate known for its involvement in various high-profile hacking incidents worldwide. By leveraging their extensive resources and sophisticated hacking techniques, the Lazarus Group managed to siphon an estimated $600 million worth of cryptocurrency in 2023 alone.

Lazarus Group’s Involvement in Crypto Hacks

The Lazarus Group’s nefarious exploits have made headlines in the crypto community throughout 2023. Their persistent targeting of digital asset platforms highlights the need for robust security protocols within the industry. As cryptocurrency continues to gain mainstream acceptance, organizations must remain vigilant and prioritize cybersecurity to protect their users’ assets.

Lack of Comment from CoinsPaid on the Recent Attack

As news of the recent security breach spread, CoinsPaid has yet to issue any statements or comments regarding the incident. This silence raises concerns about the platform’s commitment to transparency and leaves affected users and industry observers in limbo. Prompt and honest communication from CoinsPaid is vital at this critical juncture to maintain trust and assure customers that remedial measures are being taken.

The recurrence of security breaches at CoinsPaid underscores the ever-present threat faced by businesses operating in the crypto ecosystem. As the adoption of digital assets continues to rise, it is imperative that organizations remain proactive and implement robust security measures to protect user funds. The recent breaches at CoinsPaid serve as a stark reminder of the need for constant vigilance and stringent security protocols within the cryptocurrency industry. By prioritizing cybersecurity, both platforms and users can mitigate risks and foster a safer environment for conducting crypto transactions.

Explore more

How Is AI Closing the Gap in Customer Conversations?

The digital footprints of modern commerce often leave behind a trail of binary data, but the most profound truths about a brand’s health remain locked within the messy, emotional, and often unpredictable nuance of human speech. While organizations have spent decades perfecting the art of the post-transactional survey, they have largely ignored the goldmine of information vibrating through the phone

How Does CRM Fragmentation Drain Your Sales Productivity?

High-performing sales representatives often spend more time acting as digital detectives than closing deals because their customer data lives in ten different places at once. This digital fragmentation forces teams into a perpetual juggling act where navigating a labyrinth of browser tabs becomes the primary mode of operation. When information about a single lead is scattered across disparate platforms, preparing

How to Transform Real Estate CRMs Into High-Yield Assets

The relentless hum of a high-performance computer often masks the silent financial drain of a real estate professional’s most expensive and underutilized digital tool. Most real estate practitioners pay significant monthly fees for advanced Customer Relationship Management platforms, yet many treat these sophisticated engines like digital filing cabinets. While the technology promises to streamline operations and maximize revenue, the reality

AI Reshapes Technical Hiring and Entry-Level Pipelines

The once-reliable path of starting as a junior analyst and slowly climbing the corporate ladder has been fundamentally disrupted by the rapid integration of sophisticated autonomous systems that now manage routine tasks with superhuman speed. Hiring managers are no longer looking for people to organize spreadsheets; they are seeking architects of the future. This shift marks the definitive transition toward

AI Recruitment Tools Invent and Reinforce Their Own Biases

When a recruiting algorithm selects a candidate not because of their skills but because it hallucinated a success pattern out of thin air, the fundamental promise of meritocratic automation begins to crumble. This shift marks a departure from the era when developers merely feared that machines would inherit human prejudices; today, the concern is that they are actively manufacturing their