This is yet another reason why storing large amount of funds on exchanges is a bad idea. It appears Kucoin exchange has been hacked. For the past 7 hours, Over $150m in Ethereum and other erc20 tokens have been withdrawn to an unknown wallet here:
https://etherscan.io/address/0xeB31973E0FeBF3e3D7058234a5eBbAe1aB4B8c23Bitcoin outflows were moved to Bitfinix.
Kucoin's Responses Their telegram chat has gone haywire since then as worried users have been asking about an update. Alicia (Head of VIP at Kucoin) replied:
Things doesn't add up here. If the funds were being moved by Kucoin, they wouldn't be investigating. It's either you or not. Users have reported seeing empty balances and currently withdrawal and deposits has been disabled. Since we have different DeXs available now, the hacker can easily unload all those funds.
While this isn't a "confirmed" hack yet, this is a friendly reminder to everyone who still stores loads of funds on exchanges. Your funds are a lot more safer when they're stored in your private wallet. I will keep updating the thread.
Update 1:Looks like the hacker is cashing out using
shitcoins available in decentralized exchanges. If this is a joke by Kucoin, then it's an interesting one
Update 2: Hack ConfirmationKucoin just confirmed the hack:
We detected some large withdrawals since September 26, 2020 at 03:05:37 (UTC+8). According to the latest internal security audit report, part of Bitcoin, ERC-20 and other tokens in KuCoins hot wallets were transferred out of the exchange, which contained few parts of our total assets holdings. The assets in our cold wallets are safe and unharmed, and hot wallets have been re-deployed.
We are locating the reason for the incident, and will keep you updated once it is confirmed. Please rest assured that if any user fund is affected by this incident, it will be covered completely by KuCoin and our insurance fund.
To ensure the security of users assets, we will conduct a thorough security review. The deposit and withdrawal service will be suspended during the period. We will restore the service gradually after ensuring a safe state. We will keep you updated.
As "The Peoples Exchange", we will take full responsibility and maintain transparency. To keep you updated regarding the latest updates, our CEO Johnny Lyu will update more details through a livestream at 12:30 (UTC+8), September 26, 2020. Please submit your questions here if you have any.
We greatly appreciate your understanding and support.
The KuCoin Team
Update 3: More funds are being moved. Hack still on.
Update 4:In response to the hack, Kucoin's CEO hosted a livestream to discuss details of the hack:
https://www.kucoin.com/news/en-kucoin-ceo-livestream-recap-latest-updates-about-security-incidentUpdate 5:Tether Treasury has frozen over $20M tethers that were stolen. They're still about $120M of movable funds + some projects have agreed to invalidate some stolen tokens from their supply:
https://www.kucoin.com/news/en-kucoin-ceo-livestream-recap-latest-updates-about-security-incident
The bottom line is, Kucoin will refund the stolen funds thanks to their insurance.
Well that is really true. Not your keys, not your crypto, not your money. This is why I opted last year to just use a crypto wallet where I can just swap/exchange my crypto inside the wallet. Although the fees are high, it's still very convenient for me and I am very sure that my assets are safe with me. These decentralized platforms like Uniswap are what we need now and not these CEXs.