The Hack
Hackers targeted India-based crypto exchange CoinDCX by luring employee Rahul Agarwal with a fake part-time job offer. Malware was installed on CoinDCX’s internal device, allowing the attackers to gain access to the company's wallet. They then transferred approximately 44 million worth of cryptocurrency to six different wallets. Indian police is currently investigating the incident.
CoinDCX's Response
Crypto Investor Protection Fund (CIPF): Following last year’s WazirX hack—after which users were not fully compensated—CoinDCX had launched a $6 million CIPF to protect users in such emergencies. However, this fund appears inadequate against a $44 million loss.
Recovery Bounty: CoinDCX has also announced a recovery bounty programme, offering 25% of any recovered amount to those who assist in asset recovery. This significant reward could even incentivise the hacker to turn into a white-hat.
My Perspective
CoinDCX’s internal security raises serious questions. Why was an employee allegedly looking for side work allowed access to critical systems? Why hasn’t CoinDCX been able to identify the recipients of the withdrawn funds, despite mandatory KYC? This may well be an inside job.