BigONE disclosed a USD 27 million security incident
BigONE reported that a third-party supply-chain attack modified operating logic and enabled unauthorized transfers from hot wallets, with losses estimated at approximately USD 27 million.
Reviewed event layer
Browse reviewed exchange incidents and lifecycle disruptions linked back to entity dossiers and supporting evidence.
Page 4 of 20 · showing 76–100 of 485
Leading recorded types
BigONE reported that a third-party supply-chain attack modified operating logic and enabled unauthorized transfers from hot wallets, with losses estimated at approximately USD 27 million.
GMX disabled GMX v1 trading and GLP mint/redeem functionality on Arbitrum and Avalanche after the exploit, while stating or reporting that GMX v2 was unaffected.
GMX v1 / GLP on Arbitrum was exploited for about USD 42 million, with the attacker later offered a white-hat bounty and some funds reportedly returned.
Purchases through the Anycoin platform stopped and eligible European customers were automatically migrated to Finst by the end of June 2025.
Bitvavo announced that the Dutch Authority for the Financial Markets had authorised Bitvavo B.V. as a crypto-asset service provider under the European Markets in Crypto-Assets Regulation.
Coinbase announced that Coinbase Luxembourg S.A. had received authorization from Luxembourg's CSSF as a crypto-asset service provider under MiCA, supporting regulated service provision across the EU and EEA through the Luxembourg entity.
Nobitex said it pulled its website and app offline while reviewing unauthorized access to its systems and hot wallet infrastructure after the attack.
Nobitex was attacked by hackers identifying as Predatory Sparrow / Gonjeshke Darande, with roughly USD 90 million in crypto assets transferred to inaccessible or burned addresses and source-code exposure threatened.
Nobitex suffered a major security incident in June 2025. Public reporting and blockchain analysis described more than $90 million in crypto assets being transferred to inaccessible addresses in an apparently politically motivated attack.
Austria's Financial Market Authority granted Bybit EU GmbH authorization as a crypto-asset service provider under MiCAR for custody, exchange, placing, and transfer services, supporting Bybit's regulated EEA platform rollout.
Cetus halted trading / paused smart-contract activity while investigating the exploit and coordinating recovery through Sui validators, the Sui Foundation, and security partners.
Cetus Protocol suffered a major exploit on May 22, 2025, with reports estimating about USD 223 million to USD 260 million drained from Sui/Aptos liquidity pools and more than USD 160 million of assets later frozen or recovered through the Sui ecosystem response.
The announced eXch shutdown date was May 1, 2025, marking the terminal date used by HEI for the exchange entity.
KUNA's closure roadmap set April 30, 2025 as the complete cessation date for the platform after earlier deposit, exchange, and withdrawal deadlines.
Authorities stated that the seizure action shut down the eXch platform before the operators' announced 2025-05-01 closure date.
The Frankfurt public prosecutor's cybercrime unit and the BKA seized the Germany-based server infrastructure of eXch and confiscated cryptocurrency assets, with support from the Dutch FIOD.
eXch announced that it would cease operations on May 1, 2025, describing a management decision to cease and retreat in the hostile legal and surveillance environment.
eXch said it had become the target of an active transatlantic operation amid allegations that Lazarus Group used the platform to launder funds from the Bybit hack; earlier reporting said eXch denied being a mixer but acknowledged processing a small portion of funds from the incident.
ApeX removed the remaining Pro trading liquidity and disabled Pro deposit functions as users were directed to migrate to ApeX Omni.
KiloEx paused operations / trading for roughly ten days while preparing recovery and compensation measures after the oracle-manipulation attack.
KiloEx suffered an approximately USD 7 million price-oracle manipulation exploit across multiple chains, including Base, BNB Chain, and Taiko exposure.
Public closure text stated Mercatox would cease responding to user inquiries on 2025-04-01.
OKX temporarily suspended its decentralized exchange aggregator after consulting regulators, citing efforts to prevent further misuse by Lazarus-linked activity and to apply security upgrades during heightened EU/MiCA scrutiny of its Web3 service.
DMM Bitcoin service ended on March 8, 2025 after customer assets and accounts were transferred to SBI VC Trade.
Garantex suspended services after Tether blocked wallets on the platform, with international enforcement activity and web-infrastructure seizure following in the same period.