Cashaa said on July 11, 2020 that a bitcoin wallet used by the cryptocurrency company had been compromised and that more than 336 BTC had been transferred to an address it identified publicly. The disclosure made a large operational-security failure visible on Bitcoin’s ledger while leaving important questions about the intrusion, wallet ownership and customer exposure unresolved.
The central fact is deliberately narrow: Cashaa attributed the transfers to an unauthorized compromise. The blockchain records transfers, but it does not by itself prove who controlled the sending wallets, who controlled the receiving address or how credentials were obtained.
What Cashaa reported
Cashaa’s public notice identified the receiving address and said it had informed the cybercrime department in Delhi and cryptocurrency exchanges so they could watch for movement of the bitcoin. Contemporaneous reporting based on a media brief from chief executive Kumar Gaurav said the company halted cryptocurrency-related transactions. It also relayed Cashaa’s preliminary position that users were not affected.
Those were company claims on July 11, not independently established conclusions. The cited press account said Cashaa filed a cybercrime report under acknowledgment number 20807200031555, but the underlying police report was not available in the records reviewed for this reconstruction. Nor did the event-day material establish whether the compromised assets belonged to Cashaa, clients or a mix of both.
The distinction mattered. A blockchain transfer can be independently observed, yet an assertion that it was theft depends on off-chain evidence: control of the keys, authorization records, device logs and custody arrangements.
The transaction record
A technical review published by CertiK on July 16 separated the activity into two stages. It attributed a 1.059770800 BTC transfer on July 10 to a first incident, then identified 335.91312085 BTC transferred from eight addresses on July 11 to the same receiving address. Added together, those amounts equal 336.97289165 BTC, explaining why some reports rounded the loss to 336 BTC and others to 337 BTC.
CertiK tied the suspicious activity to Bitcoin blocks 638606 and 638692 and described the total as about $3.1 million at the time its July 16 analysis was written. That dollar figure is a retrospective estimate using an unspecified price source and snapshot; it should not be read as an exact July 11 execution value. Bitcoin trades continuously across venues, and the transfers themselves did not represent market sales.
The CertiK report also contains an internal clock-label inconsistency: one passage says 12:10 a.m. UTC and another says 12:10 p.m. UTC for July 11. This reconstruction therefore relies on the calendar date and cited blocks, not the disputed hour.
Why the incident mattered
The event was an institutional custody story more than a Bitcoin protocol failure. Nothing in the surviving evidence indicates that Bitcoin’s consensus rules were broken. Instead, Cashaa’s account and CertiK’s later analysis pointed toward compromise of an employee computer or wallet-access environment. CertiK said the precise vulnerability had not been disclosed and treated malware or an internal operational failure as possibilities, not proven causes.
That distinction was important in 2020 as exchanges and crypto-finance companies asked customers to trust centralized operational controls around bearer assets. Once validly signed transactions were confirmed, Bitcoin provided no built-in administrator capable of reversing them. Prevention, key segregation, approval controls and incident response therefore sat with the custodian.
What remained unknown
As of July 11, the attacker’s identity, the exact intrusion method, the legal ownership of every transferred coin and the prospect of recovery were unverified. Cashaa’s report that customers were unaffected also required later balance-sheet or forensic confirmation. Later tracing can clarify where outputs moved, but it cannot by itself establish culpability or prove that an exchange receiving funds knew their origin.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

