<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Phemex_Hot_Wallet_Access_Control_Vulnerability</id>
	<title>Phemex Hot Wallet Access Control Vulnerability - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Phemex_Hot_Wallet_Access_Control_Vulnerability"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Phemex_Hot_Wallet_Access_Control_Vulnerability&amp;action=history"/>
	<updated>2026-04-18T21:50:06Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Phemex_Hot_Wallet_Access_Control_Vulnerability&amp;diff=6476&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/phemexhotwalletaccesscontrolvulnerability.php}} {{Unattributed Sources}}  Phemex Logo/HomepagePhemex is a crypto trading platform offering a variety of services to users, including spot trading, contract trading, and margin trading. The platform suffered a major hack on January 23, 2025, resulting in a $69m+ loss due to a security breach in their hot wallets. Th...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Phemex_Hot_Wallet_Access_Control_Vulnerability&amp;diff=6476&amp;oldid=prev"/>
		<updated>2025-01-27T20:19:52Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/phemexhotwalletaccesscontrolvulnerability.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Phemex.jpg&quot; title=&quot;File:Phemex.jpg&quot;&gt;thumb|Phemex Logo/Homepage&lt;/a&gt;Phemex is a crypto trading platform offering a variety of services to users, including spot trading, contract trading, and margin trading. The platform suffered a major hack on January 23, 2025, resulting in a $69m+ loss due to a security breach in their hot wallets. Th...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/phemexhotwalletaccesscontrolvulnerability.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Phemex.jpg|thumb|Phemex Logo/Homepage]]Phemex is a crypto trading platform offering a variety of services to users, including spot trading, contract trading, and margin trading. The platform suffered a major hack on January 23, 2025, resulting in a $69m+ loss due to a security breach in their hot wallets. The attacker exploited vulnerabilities across 16 different blockchains, draining wallets from Ethereum to Solana, Avalanche, and others. Despite quick responses to suspend withdrawals and reassure users about cold wallet security, the attack revealed serious flaws in Phemex’s multi-chain strategy and access control. PeckShield and Cyvers detected suspicious transfers, but the attack was too swift, with funds being drained across multiple chains simultaneously. The breach exposed the risks of not properly securing hot wallets and highlighted the potential dangers of multi-chain support without robust security measures. The exchange promised a compensation plan but faces significant criticism for its handling of wallet management and multi-chain custody.&amp;lt;ref name=&amp;quot;rektnews-17574&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;phemex-17575&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;federico0xtwitter-17576&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;federico0xtwitter-17577&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;federico0xtwitter-17578&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;federico0xtwitter-17579&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;federico0xtwitter-17580&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;peckshieldtwitter-17581&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;peckshieldalerttwitter-17582&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-17583&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-17584&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-17585&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-17586&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;phemexofficialtwitter-17587&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;hackenclubtwitter-17588&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cyversalertstwitter-17589&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cryptooadytwitter-17590&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;theblock-17591&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Phemex ==&lt;br /&gt;
Phemex is a crypto trading platform offering a variety of services to users, including spot trading, contract trading, and margin trading. The platform supports multiple methods for buying crypto, such as P2P trading, bank transfers (SWIFT, ACH, SEPA), and credit/debit cards with low fees. Phemex offers users up to $4,800 in welcome rewards and provides access to over 372 contract pairs and 454 spot pairs, with leverage up to 100x and minimal fees. Additionally, users can earn passive income through Phemex Earn, with up to 18.8% APY on crypto savings and staking options in the Launchpool.&lt;br /&gt;
&lt;br /&gt;
The platform is recognized for its user-friendly experience, and is trusted by prominent individuals and media outlets. It also has partnerships with institutions like Dauphine University for DeFi research. Phemex prioritizes security, transparency, and a smooth trading experience, offering a mobile app for trading on the go.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
Phemex, a crypto exchange, suffered a major hack on January 23, 2025, resulting in over $69 million being drained from its hot wallets across multiple blockchains due to an access control breach.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Phemex Hot Wallet Access Control Vulnerability&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|January 23rd, 2025 4:49:47 AM MST&lt;br /&gt;
|USDC Withdrawal Transaction&lt;br /&gt;
|The USDC withdrawal on ethereum blockchain, the first of many withdrawal transactions from the hot wallet.&lt;br /&gt;
|-&lt;br /&gt;
|January 23rd, 2025 5:18:00 AM MST&lt;br /&gt;
|PeckShield Alert Tweet Posted&lt;br /&gt;
|PeckShield posts an alert on Twitter/X about suspicious withdrawals from Phemex.&lt;br /&gt;
|-&lt;br /&gt;
|January 23rd, 2025 5:52:00 AM MST&lt;br /&gt;
|Proof Of Reserves Announcement&lt;br /&gt;
|Phemex's CEO Federico Variola rushes to Twitter/X to announce that the cold wallets remain secure. They &amp;quot;can be checked by everyone here&amp;quot; just as long as you already have an account and identify your interest by logging in.&lt;br /&gt;
|-&lt;br /&gt;
|January 23rd, 2025 6:12:00 AM MST&lt;br /&gt;
|Hacken Shares Initial Details&lt;br /&gt;
|In a post tweet, Hacken starts sharing an analysis of the attack, with some of the notbale transfers and the exploiter address.&lt;br /&gt;
|-&lt;br /&gt;
|January 23rd, 2025 11:16:00 AM MST&lt;br /&gt;
|Currently Testing Withdrawal System&lt;br /&gt;
|The CEO reports that they are currently testing out their withdrawal system. However, due &amp;quot;to the sophistication of the threat actor we cannot rush this stage&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
|January 24th, 2025 1:00:00 AM MST&lt;br /&gt;
|Withdrawals Resuming Shortly&lt;br /&gt;
|The CEO announces that they &amp;quot;estimate to resume USDT and USDC withdrawals in approximately 6 hours from now&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
|January 24th, 2025 5:58:00 AM MST&lt;br /&gt;
|PeckShield Loss Estimate Published&lt;br /&gt;
|PeckShield publishes a list of hacked assets, with a total loss estimate of $69.1m USD.&lt;br /&gt;
|-&lt;br /&gt;
|January 24th, 2025 6:58:00 AM MST&lt;br /&gt;
|Reports Of Progressive Withdrawals&lt;br /&gt;
| The CEO reports that the platform is &amp;quot;progressively restoring USDT and USDC withdrawals&amp;quot; and that all requests &amp;quot;will be manually reviewed by [their] security team, so please be patient with the queue time&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
|January 26th, 2025 5:52:00 AM MST&lt;br /&gt;
|Have Patience For Transactions&lt;br /&gt;
|The CEO posts an update that they are &amp;quot;processing all failed txs and have added support for several chains, you can follow up with customer support via live chat if any tx has not been credited yet&amp;quot;.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;Early security analysis by Hacken points to an access control breach that handed the attacker complete control over Phemex's hot wallets.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
Hacken reports they were &amp;quot;hacked for ~$30M&amp;quot; in an early tweet.&lt;br /&gt;
&lt;br /&gt;
PeckShield reports $69.1m.&lt;br /&gt;
&lt;br /&gt;
$73 million according to Rekt.&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $69,089,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;PeckShield rang the first alarm bell early on January 23rd, spotting suspicious outflows that would make a bank robber blush.&lt;br /&gt;
&lt;br /&gt;
Within minutes, Cyvers' systems were lighting up like a Christmas tree, detecting over $29 million in suspicious transfers across multiple chains, but this was just the preview.&lt;br /&gt;
&lt;br /&gt;
The protocol's response followed the familiar centralized exchange playbook - suspend withdrawals first, ask questions later.&lt;br /&gt;
&lt;br /&gt;
Phemex's CEO Federico Variola rushed to Twitter with the standard &amp;quot;our cold wallets are safe&amp;quot; reassurance, as if that somehow made the hot wallet massacre any less painful.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Hello everyone, as we look into a report on one of our cold wallets rest assured our cold wallets remain safe and can be checked by everyone here, will post more updates shortly&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;Hello all, we are currently carefully testing our system to reprise withdrawals as soon as possible. Due to the sophistication of the threat actor we cannot rush this stage. The estimated timeline to reprise full operations is within 24h, thank you for your support.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Hello all, we are progressively restoring USDT and USDC withdrawals, all reqs will be manually reviewed by our security team, so please be patient with the queue time. We have also taken a snapshot of all users' balances as of 12pm UTC for a reward for your support and loyalty, more on this soon. BTC withdrawals will be enabled soon, BTC wallets were unaffected&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Hello all, we are processing all failed txs and have added support for several chains, you can follow up with customer support via live chat if any tx has not been credited yet.  &lt;br /&gt;
All operations are thoroughly checked by our team, so please be patient, all txs will be credited. Next we will work with several third parties to certify that our systems are secure, thank you all for your support.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
The total amount recovered is unknown.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;rektnews-17574&amp;quot;&amp;gt;[https://rekt.news/phemex-rekt/ Rekt - Phemex - Rekt] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;phemex-17575&amp;quot;&amp;gt;[https://phemex.com/ Phemex: Buy, Sell, &amp;amp; Secure Your Crypto | Trade BTC &amp;amp; Derivatives] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;federico0xtwitter-17576&amp;quot;&amp;gt;[https://twitter.com/Federico0x/status/1882411493280649237 @Federico0x Twitter] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;federico0xtwitter-17577&amp;quot;&amp;gt;[https://twitter.com/Federico0x/status/1882700089807765668 @Federico0x Twitter] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;federico0xtwitter-17578&amp;quot;&amp;gt;[https://twitter.com/Federico0x/status/1883498301275980094 @Federico0x Twitter] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;federico0xtwitter-17579&amp;quot;&amp;gt;[https://twitter.com/Federico0x/status/1882790130743697433 @Federico0x Twitter] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;federico0xtwitter-17580&amp;quot;&amp;gt;[https://twitter.com/Federico0x/status/1882492744410492947 @Federico0x Twitter] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;peckshieldtwitter-17581&amp;quot;&amp;gt;[https://twitter.com/peckshield/status/1882402547744534675 @peckshield Twitter] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;peckshieldalerttwitter-17582&amp;quot;&amp;gt;[https://twitter.com/PeckShieldAlert/status/1882775043148837332 @PeckShieldAlert Twitter] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-17583&amp;quot;&amp;gt;[https://etherscan.io/tx/0xcf345cddde4286f7e2d37e9783f5e8c33f47a125a23370423596f92f3b884b62 Ethereum Transaction Hash (Txhash) Details | Etherscan] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-17584&amp;quot;&amp;gt;[https://etherscan.io/tokentxns?a=0x5b34414e95a8b8d0b16a39baf5b97cec1d517e22&amp;amp;ps=100&amp;amp;p=4 Token Transfer | Etherscan] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-17585&amp;quot;&amp;gt;[https://etherscan.io/tokentxns?a=0x50be13b54f3eebbe415d20250598d81280e56772 Token Transfer | Etherscan] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-17586&amp;quot;&amp;gt;[https://etherscan.io/address/0x50be13b54f3eebbe415d20250598d81280e56772 Phemex&lt;br /&gt;
(0x50be13b54f3eebbe415d20250598d81280e56772) | Address 0x50be13b54f3eebbe415d20250598d81280e56772 | Etherscan] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;phemexofficialtwitter-17587&amp;quot;&amp;gt;[https://twitter.com/Phemex_official @Phemex_official Twitter] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;hackenclubtwitter-17588&amp;quot;&amp;gt;[https://twitter.com/hackenclub/status/1882416222274556415 @hackenclub Twitter] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cyversalertstwitter-17589&amp;quot;&amp;gt;[https://twitter.com/CyversAlerts/status/1882407857447997803 @CyversAlerts Twitter] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cryptooadytwitter-17590&amp;quot;&amp;gt;[https://twitter.com/CryptooAdy/status/1882754717530607909 @CryptooAdy Twitter] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;theblock-17591&amp;quot;&amp;gt;[https://www.theblock.co/post/336754/north-korea-hack-group-possibly-behind-70-million-phemex-exploit-experts-say https://www.theblock.co/post/336754/north-korea-hack-group-possibly-behind-70-million-phemex-exploit-experts-say] (Accessed Jan 27, 2025)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>