Phemex loses $69 million in the year's first big exchange breach
Hot wallets on Ethereum, Solana, XRP and Bitcoin were drained in minutes; analysts tied the theft to North Korea, while the exchange said its cold storage stayed safe.
On 23 January 2025, the Singapore-based exchange Phemex was drained of about $69.1 million — at the time the largest crypto theft of the year, per crypto.news. The losses spanned several blockchains at once: roughly $20 million in Ethereum assets, $17 million on Solana, $13 million in XRP and $5.3 million in Bitcoin, according to figures cited by crypto.news. Halborn later put the total nearer $73 million across as many as sixteen chains.
The breach hit the exchange's hot wallets — the internet-connected wallets platforms use for everyday withdrawals. CEO Federico Variola said the company's cold wallets, which hold most customer funds offline, 'remain safe,' per crypto.news. The pattern of a sudden, coordinated sweep across many chains points to compromised private keys rather than a single smart-contract flaw.
Halborn's analysis argued the deeper failure was operational: if the keys for many separate hot wallets are generated or stored the same way, one compromise cascades across all of them. Multi-signature controls, it noted, would have meant that no single stolen key could move funds on its own.
The Lazarus fingerprint
Security analysts at Hacken linked the attack to North Korea, per crypto.news; Halborn likewise attributed it to the Lazarus Group, citing the systematic, multi-chain execution. A telltale detail: the thieves rapidly converted stolen USDT and USDC into ETH. Stablecoins can be frozen by their issuers on flagged addresses, per crypto.news; native assets like ETH cannot, so speed of conversion is a hallmark of state-linked laundering.
Phemex said stablecoin withdrawals were being progressively restored under manual review and that a compensation plan would follow, per crypto.news. Variola also published a proof-of-reserves to show the exchange remained solvent, per Halborn.
What it means for your money
You cannot patch another company's hot wallet. You can, however, limit how much of your own money sits inside one at any moment.
- Keep only what you actively trade on any exchange; move long-term holdings to a wallet whose keys you control.
- Treat 'not your keys, not your coins' as a rule, not a slogan — an exchange breach is your loss until the platform chooses to cover it.
- Expect fake 'Phemex compensation' or 'reactivate your account' messages after a hack; verify only through official channels.
- Turn on withdrawal allowlists and hardware-based 2FA so a stolen password alone cannot move funds.
The Phemex breach set the tone for a punishing year in which state-linked groups repeatedly went after exchange infrastructure — the hot wallets, key-management systems and insiders that sit between users and their coins — rather than the harder target of individual cold storage.
— Sources: [crypto.news](https://crypto.news/hackers-steal-70m-from-phemex-in-2025s-largest-attack-so-far/) · [Halborn](https://www.halborn.com/blog/post/explained-the-phemex-hack-january-2025)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING