Mixin Network lost $200M when its cloud vendor's database was breached
The September 2023 breach ranked as the year's single largest crypto theft on Rekt's leaderboard — and it began not with a smart-contract bug, but with a compromised third-party cloud vendor.
In the early hours of September 23, 2023, Hong Kong time, the database of Mixin Network's cloud service provider was attacked by hackers, according to the company's own statement as reported by TechCrunch. The intruders used that access to reach the funds Mixin held in its hot wallets. By the time the network went public, roughly $200 million was gone.
Mixin's loss was the single biggest crypto theft of 2023, edging past the next-largest loss of the year on Rekt's leaderboard, TechCrunch reported. Elliptic put the stolen haul at about $95.3 million in ether, $23.7 million in bitcoin and $23.6 million in tether — all of it drained through one compromised supplier rather than a flaw in Mixin's own code.
The vendor was the weak link
Mixin is a cross-chain network that custodies assets on behalf of users. The attack did not exploit the network's own smart contracts; it exploited the database of an outside cloud provider that sat between Mixin and its wallets, per the company's account. Custodial platforms routinely lean on such vendors, which means their real security perimeter extends far beyond the code they write themselves. Once that database was compromised, the attacker had what it needed to move funds out.
Mixin engaged Google's Mandiant incident-response team and the crypto-security firm SlowMist to investigate, TechCrunch reported, and it suspended deposits and withdrawals. The attackers, Elliptic noted, converted stolen tether into Dai — a stablecoin that, unlike tether, cannot be frozen by its issuer.
For users, the consequences were stark. Founder Feng Xiaodong's initial plan covered only half of affected balances, with the remainder left to a further 'solution' the network said it would announce later, per TechCrunch. Elliptic said it moved quickly to label the thief's wallets so exchanges could try to block the funds.
What it means for you
- Custodial risk is vendor risk. Leave coins on a platform and you inherit the security of every third party it relies on — including cloud vendors you will never see named.
- 'Not your keys, not your coins' is not a slogan. Assets you do not self-custody can vanish through a breach you had no way to detect.
- Watch for freeze-resistant laundering. Thieves increasingly swap stolen stablecoins into non-freezable assets within minutes, and recovery odds drop fast.
- A compensation promise is not a guarantee. A pledge to refund half is a partial, discretionary measure, not restored funds.
Mixin's breach is a reminder that 2023's largest single loss came through back-office plumbing, not a headline exploit. The safest coins in a self-custodied wallet are the ones no vendor's database can ever reach.
— Sources: [Elliptic](https://www.elliptic.co/blog/mixin-network-hacked-for-200-million) · [TechCrunch](https://techcrunch.com/2023/09/25/hackers-steal-200-million-from-crypto-company-mixin/)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING