en
Back to the list

KuCoin Exchange Hacked With Large BTC, ERC-20 and Other Tokens Withdrawn

source-logo  coinfomania.com 26 September 2020 05:24, UTC

Singapore-headquartered cryptocurrency exchange, KuCoin reported in the hours leading up to press time that it had suffered a security breach. The funds include part of BTC, ERC-20 and other tokens in KuCoin’s hot wallets that were transferred out of the exchange.

Following the KuCoin hack, the exchange is yet to disclose the total sum lost but confirmed that it “contained few parts of its total assets holdings.”

(1/4) We detected some large withdrawals since Sep 26 at 03:05 UTC+8. According to the latest internal security audit report, part of BTC, ERC-20 and other tokens in KuCoin’s hot wallets were transferred out of the exchange, which contained few parts of our total assets holdings

— KUCOIN (@kucoincom) September 26, 2020

In a hastily organized AMA session, KuCoin CEO Johnny Lyu provided further information regarding the incident, confirming that hackers stole the private key of the exchange’s hot wallets and that no user data was not leaked. Similar to the Binance hack in 2019, KuCoin will cover user losses from its insurance fund which is set up in 2018.

KuCoin Hack: Johnny Lyu Updates About Timeline and Reopening

Johnny Lyu provided a timeline for the incident which started at 2:51 am Singaporean time when the system provided its first alert from an in-house risk monitoring system.

The exchange subsequently received alert for abnormal withdrawals of XRP, and notice that its hot wallet is “running out of balance.” That notice was followed by a strange BTC transfer and that of other yet to be unnamed ERC-20 tokens.

The internal security team sought to provide some urgent solutions, including shutting down the wallet server. Even after the shutdown, though, there were still cases of abnormal transfer, leading to the conclusion that the exchange’s hot wallet private keys were leaked.

Within two hours after the initial alert, all remaining balances were moved to the exchange’s cold wallet, with KuCoin simultaneously reaching out to its clients and community. Other big exchanges including Binance, BitMAX, Bybit, Huobi, Beaxy, Bibox and others have been alerted to assist with tracking and hunting down the stolen funds.

Johnny Lyu also mentioned that KuCoin is also in contact with the International Police, our important clients and many industry experts to conduct an in-depth investigation into the incident.

A reward will be offered for information on this hacking event while the hackers address details will soon be made available to the public.

The CEO meanwhile preferred not to disclose the net value of the stolen funds in relation to the company’s crypto holdings. However, he assured that the “affected amount […] is a small amount for KuCoin and the exchange is going to take the loss.”

When Will KuCoin Reopen?

Regarding a potential reopening after the KuCoin hack, Johnny Lyu said in the AMA,

As they already found out the reason and we already come up with some solutions, we are going to rationally open with trust in the next week.

coinfomania.com