<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=XT.com_Exchange_Hot_Wallet_Breach</id>
	<title>XT.com Exchange Hot Wallet Breach - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=XT.com_Exchange_Hot_Wallet_Breach"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=XT.com_Exchange_Hot_Wallet_Breach&amp;action=history"/>
	<updated>2026-05-30T08:20:50Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=XT.com_Exchange_Hot_Wallet_Breach&amp;diff=6439&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/xtcomexchangehotwalletbreach.php}} {{Unattributed Sources}}  XT.com Logo/HomepageXT.com has operated a Seychelles-based exchange since 2018. On November 27th, 2024, their hot wallet was breached, and $1.7m worth of various assets were taken. The exchange immediately suspended withdrawals and provided updates. They also appear to have provided a highly pos...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=XT.com_Exchange_Hot_Wallet_Breach&amp;diff=6439&amp;oldid=prev"/>
		<updated>2025-01-18T00:45:40Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/xtcomexchangehotwalletbreach.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Xtcomexchange.jpg&quot; title=&quot;File:Xtcomexchange.jpg&quot;&gt;thumb|XT.com Logo/Homepage&lt;/a&gt;XT.com has operated a Seychelles-based exchange since 2018. On November 27th, 2024, their hot wallet was breached, and $1.7m worth of various assets were taken. The exchange immediately suspended withdrawals and provided updates. They also appear to have provided a highly pos...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/xtcomexchangehotwalletbreach.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Xtcomexchange.jpg|thumb|XT.com Logo/Homepage]]XT.com has operated a Seychelles-based exchange since 2018. On November 27th, 2024, their hot wallet was breached, and $1.7m worth of various assets were taken. The exchange immediately suspended withdrawals and provided updates. They also appear to have provided a highly positive account for CoinTelegraph, who published it without question (and with a disclaimer/attribution at the bottom). They have assured users of the platform that their assets are unaffected and reportedly re-enabled withdrawals.&amp;lt;ref name=&amp;quot;xtexchangetwitter-17252&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;veridiseinctwitter-17253&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;xtsupportzendesk-17254&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;xtcommedium-17255&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;instagram-17256&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;xtexchangetwitter-17257&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;xtexchangetwitter-17258&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;xtexchangetwitter-17259&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;xtexchangetwitter-17260&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cointelegraph-17261&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-17262&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-17263&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-17264&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-17265&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-17266&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;xt-17267&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;xt-17268&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;xtexchangetwitter-17269&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About XT.com ==&lt;br /&gt;
&amp;quot;XT.COM Exchange was established in 2018 and registered in Seychelles. It has operation centers in Seychelles, Europe and other countries and regions, and its business covers the world. The platform owns the global top-level domain name www.xt.com, currently has more than 7.8 million registered users, more than 1 million monthly active users, and more than 40 million user traffic in the ecosystem.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;XT.COM is a comprehensive trading platform that supports 800+ high-quality currencies and 1000+ trading pairs. It has a rich variety of transactions such as spot trading, futures trading, margin trading, OTC trading and buying cryptos with credit cards. XT provides users with the safest, most efficient and professional digital asset investment services.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;2024 was a transformative year for XT.COM, a year filled with groundbreaking events, strategic collaborations, and innovative product launches that elevated its position as a leader in the cryptocurrency industry. By driving community growth, enhancing user experience, and championing blockchain innovation, XT.COM not only solidified its reputation as one of the most influential crypto exchanges, but also opened new doors for its global user base.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;The cryptocurrency exchange XT has reportedly fallen victim to a hacking incident, resulting in the loss of approximately $1.7 million worth of crypto assets.&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - XT.com Exchange Hot Wallet Breach&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|November 27th, 2024 6:48:00 PM MST&lt;br /&gt;
|Unwavering Support Thanks&lt;br /&gt;
|The XT.com exchange wants &amp;quot;to take a moment to thank [their] incredible community for [their] unwavering support in the crypto journey. Together, [XT.com has] navigated the ups and downs of the market, and with [the community's] trust, [they] continue to innovate and push boundaries.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|November 27th, 2024 11:48:59 PM MST&lt;br /&gt;
|First Malicious Withdrawal&lt;br /&gt;
|The first withdrawal appears to remove 7,849,266.9462263 wQuil from the hot wallet.&lt;br /&gt;
|-&lt;br /&gt;
|November 28th, 2024 12:03:59 AM MST&lt;br /&gt;
|Last Malicious Withdrawal&lt;br /&gt;
|The final withdrawal appears to remove the remaining ethereum from the hot wallet.&lt;br /&gt;
|-&lt;br /&gt;
|November 28th, 2024 2:53:00 AM MST&lt;br /&gt;
|XT Exchange Statement&lt;br /&gt;
|XT Exchange releases their &amp;quot;XT Statement on Abnormal Transfer of Platform Wallet Assets&amp;quot; tweet, which states that users will not be affected by the incident. However, withdrawals are disabled and many users report being unable to withdraw their funds.&lt;br /&gt;
|-&lt;br /&gt;
|November 28th, 2024 3:04:43 AM MST&lt;br /&gt;
|Website Final Version&lt;br /&gt;
|The official announcement on the XT Exchange website is updated to the final version.&lt;br /&gt;
|-&lt;br /&gt;
|November 28th, 2024 6:14:00 AM MST&lt;br /&gt;
|Live Broadcasting&lt;br /&gt;
|The XT Exchange team is live on a broadcast for users.&lt;br /&gt;
|-&lt;br /&gt;
|November 28th, 2024 7:24:00 AM MST&lt;br /&gt;
|Withdrawals Back Online&lt;br /&gt;
|The XT Exchange reports that they've identified the issue and withdrawals are starting to come back online, with the expectation that all withdrawals will be back online within 24 hours.&lt;br /&gt;
|-&lt;br /&gt;
|November 28th, 2024 9:48:00 AM MST&lt;br /&gt;
|CoinTelegraph Thanks&lt;br /&gt;
|XT Exchange thanks CoinTelegraph for a positive press release about the &amp;quot;robust response to abnormal wallet asset transfers&amp;quot;.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount lost has been estimated at $1,700,000 USD.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;Today, XT.COM identified an abnormal transfer of assets from the platform wallet with the on-chain address 0xdb3ded7731c781224ec292e2163d9554c094fd7c. Our technical team is currently conducting an urgent investigation. The amount involved in this incident is approximately 1 million USDT across 12 different currencies. These assets are owned by the platform and will not in any way harm the interests of our customers or users.&lt;br /&gt;
&lt;br /&gt;
Since inception, XT.COM has always upheld a user-centric approach, maintaining strict and standardized platform fund management while prioritizing the security of user assets. We have established asset reserve funds 1.5 times greater than those of users on the exchange. Additionally, we plan to launch the Merkel Tree Asset Proof System in mid-December to further enhance transparency and security.&lt;br /&gt;
&lt;br /&gt;
Over the past 6 years, we express our gratitude for the support and companionship of our valued users. Every challenge along our growth journey has only made us stronger. XT.COM remains committed to its founding principles and aims to be a trusted and conscientious exchange within the industry.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;We are aware of concerns regarding recent abnormal asset transfers. Rest assured, users' assets remain safe and unaffected. The affected assets belong to the exchange, and we’re taking immediate action, including launching a Merkle Tree Proof of Reserves by mid-December to enhance transparency.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The first step XT.COM took in response to the abnormal activity was the immediate isolation of the affected systems. This critical move helped to prevent further unauthorized access or data breaches, thereby containing the issue quickly before it could escalate.&lt;br /&gt;
&lt;br /&gt;
By isolating these systems, XT.COM ensured the protection of its broader platform infrastructure and user accounts from potential threats.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;To mitigate additional risks, the platform made the decision to temporarily suspend all coin withdrawals. This precautionary action minimized the potential for further losses, securing the integrity of assets while allowing the team to conduct a detailed investigation into the incident.&lt;br /&gt;
&lt;br /&gt;
Users were promptly informed about the withdrawal suspension, with XT.COM’s team providing consistent updates to maintain transparency.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;XT.COM’s seasoned security team immediately launched a thorough investigation to identify the root cause of the abnormal transfer. This investigation was critical to understanding how and why the incident occurred in order to develop a strategic response plan and ensure that such occurrences are avoided in the future.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;From the moment the incident was detected, XT.COM stayed committed to open communication. The platform quickly informed its users and the wider community about the nature of the abnormal transfer and outlined the key steps being taken to address the situation.&lt;br /&gt;
&lt;br /&gt;
Through its announcements, XT.COM prioritized keeping stakeholders informed, ensuring that users felt reassured and aware of the ongoing effort to resolve the matter.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;This publication is provided by the client. Cointelegraph does not endorse and is not responsible for or liable for any content, accuracy, quality, advertising, products, or other materials on this page. Readers should do their own research before taking any actions related to the company. Cointelegraph is not responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods, or services mentioned in the press release.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;The hacker has converted the funds into 461.58 ETH and deposited them into the address 0xB43f…8F83.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;We sincerely apologize for the temporary suspension of withdrawals on Nov 28, 2024. Our team identified and fixed an issue to ensure user asset security. Withdrawal services will gradually resume starting 00:00 (UTC) on Nov 29, 2024, with full restoration within 24 hours. User assets remain safe throughout the process. Thank you for your understanding and continued support. #XT&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;xtexchangetwitter-17252&amp;quot;&amp;gt;[https://twitter.com/XTexchange/status/1862072439154569282 @XTexchange Twitter] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;veridiseinctwitter-17253&amp;quot;&amp;gt;[https://twitter.com/VeridiseInc/status/1864218556982022339 @VeridiseInc Twitter] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;xtsupportzendesk-17254&amp;quot;&amp;gt;[https://xtsupport.zendesk.com/hc/en-us/articles/40528847749657-XT-COM-Statement-on-Abnormal-Transfer-of-Platform-Wallet-Assets https://xtsupport.zendesk.com/hc/en-us/articles/40528847749657-XT-COM-Statement-on-Abnormal-Transfer-of-Platform-Wallet-Assets] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;xtcommedium-17255&amp;quot;&amp;gt;[https://medium.com/@XT_com/xt-com-in-2024-milestones-that-shaped-the-crypto-world-0f6d8a71139e XT.COM in 2024: Milestones That Shaped the Crypto World | by XT Exchange | Dec, 2024 | Medium] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;instagram-17256&amp;quot;&amp;gt;[https://www.instagram.com/xt.com_exchange/ https://www.instagram.com/xt.com_exchange/] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;xtexchangetwitter-17257&amp;quot;&amp;gt;[https://twitter.com/XTexchange/status/1862127289561211232 @XTexchange Twitter] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;xtexchangetwitter-17258&amp;quot;&amp;gt;[https://twitter.com/XTexchange/status/1862122807360164033 @XTexchange Twitter] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;xtexchangetwitter-17259&amp;quot;&amp;gt;[https://twitter.com/XTexchange/status/1862126769593262456 @XTexchange Twitter] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;xtexchangetwitter-17260&amp;quot;&amp;gt;[https://twitter.com/XTexchange/status/1862176701331251323 @XTexchange Twitter] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cointelegraph-17261&amp;quot;&amp;gt;[https://cointelegraph.com/press-releases/xtcoms-robust-response-to-abnormal-wallet-asset-transfers https://cointelegraph.com/press-releases/xtcoms-robust-response-to-abnormal-wallet-asset-transfers] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-17262&amp;quot;&amp;gt;[https://etherscan.io/tx/0xf7bcede1e045f08afc24c665247ba1e551355cd00d4d34c70705ca16b617bb79 Ethereum Transaction Hash (Txhash) Details | Etherscan] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-17263&amp;quot;&amp;gt;[https://etherscan.io/tx/0x96aa5049fd265dbaf2c18d5be71d6967d4bd2db3ad67491a9d8d0e997cd9f01f Ethereum Transaction Hash (Txhash) Details | Etherscan] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-17264&amp;quot;&amp;gt;[https://etherscan.io/tokentxns?a=0x4cb62577e5f4ac1f7bf4ceda7230958c087996c8&amp;amp;ps=100 Token Transfer | Etherscan] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-17265&amp;quot;&amp;gt;[https://etherscan.io/address/0xdb3ded7731c781224ec292e2163d9554c094fd7c#tokentxns Address 0xdb3ded7731c781224ec292e2163d9554c094fd7c | Etherscan] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-17266&amp;quot;&amp;gt;[https://etherscan.io/tx/0xb5fc541e3fc08c928cf068e1c0c8eb0b9ca8dd805fcd7ef670dcaf91cffa4f64 Ethereum Transaction Hash (Txhash) Details | Etherscan] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;xt-17267&amp;quot;&amp;gt;[https://www.xt.com/en Crypto Exchange | Bitcoin Exchange | Buy/Sell Bitcoin, Ethereum, and Altcoins | XT.com] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;xt-17268&amp;quot;&amp;gt;[https://www.xt.com/en/aboutUs About Us | XT.com] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;xtexchangetwitter-17269&amp;quot;&amp;gt;[https://twitter.com/XTexchange/status/1862328225340498018 @XTexchange Twitter] (Accessed Jan 17, 2025)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>