Exchange says third-party back-end tool flaw led to theft of about 103 million XRP and 31,890 ETH worth about $357 million
A crypto exchange reported a major theft linked to a vulnerable third-party backend tool that allowed forged wallet-approval instructions, resulting in the loss of ~103M XRP and 31,890 ETH (revised to ~$357M). Withdrawals remain paused due to uncertainty that the exploit is fully remediated, increasing counterparty and liquidity risk. Attack infrastructure resembles VPN patterns tied to North Korea-linked groups, reinforcing sector security concerns.
AI Insight · XRP/USDTAI Insight
▼ Bearish
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
An exchange said a vulnerability in a third-party back-end tool allowed forged instructions to bypass its wallet approval process, resulting in the theft of about 103 million XRP and 31,890 ETH worth about $357 million. The estimate was slightly revised up from a previous $351.6 million. It has suspended withdrawals because it is not yet certain the flaw has been fully patched and fears resuming withdrawals prematurely could lead to another theft. The attacker IP characteristics match VPN patterns commonly used by known North Korea-linked hacking groups, the exchange said.