CoinDCX disclosed on July 19, 2025, that an internal operational account used for liquidity provisioning on a partner exchange had been compromised. Event-day reporting estimated the loss at approximately $44 million, a figure the Indian cryptocurrency exchange subsequently described in its first incident report as roughly $44 million in USDT proceeds.

Co-founder and chief executive Sumit Gupta attributed the incident to what he called a sophisticated server breach. He said the affected account was separate from the wallets holding customer assets and that CoinDCX would absorb the exposure from its treasury reserves. Those statements were the company’s contemporaneous account, not an independently completed forensic finding.

The disclosure mattered because it exposed risk outside the customer-custody layer. An exchange can isolate customer deposits in cold storage while retaining substantial online balances for market-making, settlement and liquidity management. Compromise of an operational account can therefore create a large corporate loss even if the exchange’s assertion that customer wallets were untouched proves accurate.

What was established on July 19

Gupta’s July 19 statement confirmed that one operational account had been compromised, that the account supported liquidity on a partner exchange and that CoinDCX had isolated it. He said customer-asset wallets were not affected, services remained operational and the company was working with the partner to block and recover assets.

The Block reported on July 19 that blockchain investigator ZachXBT had identified the affected wallet after an alert attributed to security firm Cyvers. Its report placed the loss near $44 million and said CoinDCX disclosed the breach roughly 17 hours after the attack began. The identity of the attacker, the precise intrusion method and the prospects for recovery were unresolved on July 19.

The $44 million figure was an approximate loss estimate, not a measured change in CoinDCX’s market value or a broad cryptocurrency-market indicator. No reliable event-window evidence established that the breach caused a particular move in bitcoin, ether or the wider market, so no such price claim is made here.

Segregation became the central test

CoinDCX’s response rested on a distinction between an operational account and customer custody. Gupta said the exposure would be fully absorbed by company reserves. That assurance reduced the immediate question from whether depositors had directly lost assets to whether the exchange could substantiate its segregation, reserves and containment claims.

At the close of July 19, those claims remained management representations. The public record did not yet include an independent forensic report, a complete reconciliation of affected assets or proof that every customer liability remained fully backed. The exchange’s continued operation was observable, but continued service alone could not verify the composition or sufficiency of its reserves.

The episode also carried particular weight in India because it occurred almost exactly one year after the July 18, 2024, WazirX exploit, which contemporaneous reporting valued above $230 million. The proximity did not establish any connection between the incidents, and no attribution linking the CoinDCX breach to the WazirX attackers was available on July 19, 2025.

Later clarification

CoinDCX’s incident report, posted on July 20, said approximately $44 million in USDT proceeds had moved through multiple hops and ended in two wallets. It reiterated that customer assets were held in segregated cold wallets, said the company had notified India’s Computer Emergency Response Team on July 19 and stated that trading, Indian-rupee deposits and Indian-rupee withdrawals remained operational.

On July 21, CoinDCX also confirmed the approximate loss to TechCrunch and described the traced assets as 4,443 ETH and 155,830 SOL after transfers across Solana and Ethereum. Those asset details clarify the record after July 19; they were not part of the initial event-day disclosure. The later statements strengthened confirmation of the loss amount but did not substitute for an independent forensic conclusion about root cause, attribution or the status of every customer liability.

Primary sourceSumit Gupta — July 19, 2025 CoinDCX security-incident statement

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.