Crypto payment processor CoinsPaid suffered a security breach on July 22, 2023 that the company subsequently said removed $37.3 million in digital assets from its operational funds. The incident disrupted the platform, but CoinsPaid said customer assets remained intact.

The breach mattered because it struck infrastructure used to process cryptocurrency payments rather than a single smart contract or individual wallet. It demonstrated how an attacker who penetrated a centralized operator’s internal systems could cause blockchain withdrawals that appeared authorized to the platform, even without obtaining the private keys to its hot wallets.

What was knowable on July 22

CoinsPaid did not publicly disclose the breach or its estimated loss on July 22. Its first detailed company statement reviewed for this reconstruction was dated July 26, 2023. The historical record therefore supports July 22 as the incident date, but not as the date when customers or the wider market received a complete public account.

The July 26 statement said the attack affected platform availability and company revenue. CoinsPaid reported that services were being restored individually in a new secured environment following partial downtime. It also said an official report had been filed with an Estonian law-enforcement agency on July 25.

Those were company representations rather than an independent audit. CoinsPaid did not publish an asset-by-asset loss schedule, a valuation timestamp or the market prices used to calculate $37.3 million. The figure should consequently be read as the operator’s incident estimate, not as a verified cash loss or a cryptocurrency-market measurement.

The custody and processing distinction

CoinsPaid characterized the stolen assets as company operational funds and said client balances remained fully available. That distinction was important for a payment processor: customer obligations could remain payable even when the operator absorbed a loss from the infrastructure used to execute transactions.

However, the July 26 statement did not supply a reserve report, wallet-level reconciliation or independent assurance supporting the customer-funds claim. It also did not disclose the affected assets, networks or addresses. The surviving contemporaneous disclosure therefore establishes CoinsPaid’s position, not a complete external accounting of liabilities and reserves on July 22.

The incident also illustrated a limitation of public blockchains. Transactions can be traced after execution, but transparent settlement does not determine whether an instruction was legitimately authorized inside a company. Blockchain finality likewise does not reverse a transfer merely because the sender’s internal controls were compromised.

Why the attack mattered institutionally

The immediate significance was operational rather than a demonstrated market-price reaction. A payment platform had to interrupt parts of its service, migrate infrastructure and investigate asset movements while continuing to account for customer obligations.

No bitcoin, ether or other token return is attributed to the breach in this reconstruction. Crypto trades continuously across venues, and the reviewed records do not provide a defensible event-study window capable of separating this incident from other developments on July 22. Claims that the breach moved the broader market would therefore exceed the evidence.

The record instead exposed a concentrated security dependency: a platform’s wallet safeguards could remain technically intact while attackers manipulated the systems that generated apparently valid withdrawal requests. Separating signing keys from operational applications reduced one risk but did not eliminate compromised-instruction risk.

Later attribution and technical context

On August 7, 2023, CoinsPaid said its investigation found that an employee had responded to a purported Crypto.com job offer and installed a malicious test application. The company said attackers stole profiles and keys, opened a backdoor through a cluster vulnerability and reproduced legitimate blockchain-interaction requests. CoinsPaid maintained that the attackers had not acquired hot-wallet private keys. These details were not publicly available on July 22 and remain findings reported by the victim company.

On September 6, the FBI attributed approximately $60 million stolen from Alphapo and CoinsPaid on or about July 22 to DPRK cyber actors associated with Lazarus Group. That authoritative attribution corroborated the date and threat-actor context, but the FBI’s combined figure did not independently validate CoinsPaid’s specific $37.3 million estimate.

Primary sourceCoinsPaid — July 26 statement on the July 22 attack

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.