$1 700 000 USD

NOVEMBER 2024

GLOBAL

XT.COM

DESCRIPTION OF EVENTS

"XT.COM Exchange was established in 2018 and registered in Seychelles. It has operation centers in Seychelles, Europe and other countries and regions, and its business covers the world. The platform owns the global top-level domain name www.xt.com, currently has more than 7.8 million registered users, more than 1 million monthly active users, and more than 40 million user traffic in the ecosystem."

 

"XT.COM is a comprehensive trading platform that supports 800+ high-quality currencies and 1000+ trading pairs. It has a rich variety of transactions such as spot trading, futures trading, margin trading, OTC trading and buying cryptos with credit cards. XT provides users with the safest, most efficient and professional digital asset investment services."

 

"2024 was a transformative year for XT.COM, a year filled with groundbreaking events, strategic collaborations, and innovative product launches that elevated its position as a leader in the cryptocurrency industry. By driving community growth, enhancing user experience, and championing blockchain innovation, XT.COM not only solidified its reputation as one of the most influential crypto exchanges, but also opened new doors for its global user base."

 

"Today, XT.COM identified an abnormal transfer of assets from the platform wallet with the on-chain address 0xdb3ded7731c781224ec292e2163d9554c094fd7c. Our technical team is currently conducting an urgent investigation. The amount involved in this incident is approximately 1 million USDT across 12 different currencies. These assets are owned by the platform and will not in any way harm the interests of our customers or users.

 

Since inception, XT.COM has always upheld a user-centric approach, maintaining strict and standardized platform fund management while prioritizing the security of user assets. We have established asset reserve funds 1.5 times greater than those of users on the exchange. Additionally, we plan to launch the Merkel Tree Asset Proof System in mid-December to further enhance transparency and security.

 

Over the past 6 years, we express our gratitude for the support and companionship of our valued users. Every challenge along our growth journey has only made us stronger. XT.COM remains committed to its founding principles and aims to be a trusted and conscientious exchange within the industry."

 

"We are aware of concerns regarding recent abnormal asset transfers. Rest assured, users' assets remain safe and unaffected. The affected assets belong to the exchange, and we’re taking immediate action, including launching a Merkle Tree Proof of Reserves by mid-December to enhance transparency."

 

"The first step XT.COM took in response to the abnormal activity was the immediate isolation of the affected systems. This critical move helped to prevent further unauthorized access or data breaches, thereby containing the issue quickly before it could escalate.

 

By isolating these systems, XT.COM ensured the protection of its broader platform infrastructure and user accounts from potential threats."

 

"To mitigate additional risks, the platform made the decision to temporarily suspend all coin withdrawals. This precautionary action minimized the potential for further losses, securing the integrity of assets while allowing the team to conduct a detailed investigation into the incident.

 

Users were promptly informed about the withdrawal suspension, with XT.COM’s team providing consistent updates to maintain transparency."

 

"XT.COM’s seasoned security team immediately launched a thorough investigation to identify the root cause of the abnormal transfer. This investigation was critical to understanding how and why the incident occurred in order to develop a strategic response plan and ensure that such occurrences are avoided in the future."

 

"From the moment the incident was detected, XT.COM stayed committed to open communication. The platform quickly informed its users and the wider community about the nature of the abnormal transfer and outlined the key steps being taken to address the situation.

 

Through its announcements, XT.COM prioritized keeping stakeholders informed, ensuring that users felt reassured and aware of the ongoing effort to resolve the matter."

 

"This publication is provided by the client. Cointelegraph does not endorse and is not responsible for or liable for any content, accuracy, quality, advertising, products, or other materials on this page. Readers should do their own research before taking any actions related to the company. Cointelegraph is not responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods, or services mentioned in the press release."

 

"The hacker has converted the funds into 461.58 ETH and deposited them into the address 0xB43f…8F83."

 

"We sincerely apologize for the temporary suspension of withdrawals on Nov 28, 2024. Our team identified and fixed an issue to ensure user asset security. Withdrawal services will gradually resume starting 00:00 (UTC) on Nov 29, 2024, with full restoration within 24 hours. User assets remain safe throughout the process. Thank you for your understanding and continued support. #XT"

 

Explore This Case Further On Our Wiki

XT.com has operated a Seychelles-based exchange since 2018. On November 27th, 2024, their hot wallet was breached, and $1.7m worth of various assets were taken. The exchange immediately suspended withdrawals and provided updates. They also appear to have provided a highly positive account for CoinTelegraph, who published it without question (and with a disclaimer/attribution at the bottom). They have assured users of the platform that their assets are unaffected and reportedly re-enabled withdrawals.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2019 - 2025 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.