Cryptocurrency exchange DragonEx disclosed on March 25, 2019 that an attack had removed digital assets belonging to both its customers and the platform. DragonEx said the intrusion occurred on March 24 and closed its services while it investigated. It did not disclose how much had been stolen, which assets were affected or how its systems had been compromised.

The announcement was consequential because it converted an unexplained service interruption into a custody incident involving customer property. It also exposed the limited information available to users of a centralized exchange when withdrawals, trading and access could be halted by the operator without an independently verified accounting of reserves or losses.

What DragonEx said

The surviving contemporaneous record comes from reports reproducing an announcement posted to DragonEx’s official Telegram channel. According to those reports, DragonEx said hackers had transferred and stolen customer and platform crypto assets. The company claimed that it had already retrieved part of the property and would try to recover the remainder.

DragonEx also said it had informed authorities in Estonia, Thailand, Singapore and Hong Kong and was assisting police. Those statements described the company’s actions; no public agency confirmation available on March 25 independently established the scope of each reported investigation.

The exchange said all platform services would remain closed and promised a fuller account of the losses and recovery effort within one week. It further said it would accept responsibility for customer losses regardless of the recovery result. That was a contemporaneous company commitment, not evidence that customers had already been reimbursed or that DragonEx possessed sufficient resources to cover the shortfall.

The crucial figure was missing

No defensible loss total was available on March 25. The announcement did not identify wallet addresses, enumerate the affected cryptocurrencies or provide transaction-level evidence that could support an independent valuation. Those omissions prevent a reliable event-day calculation.

That distinction matters in a market operating continuously across many venues. Even with a complete token inventory, a dollar estimate would require a stated valuation timestamp, price source and treatment of illiquid assets. None was supplied in the initial disclosure. Reports published after the announcement therefore correctly described the amount as unknown rather than converting speculation into a balance-sheet fact.

The company’s claim that some assets had been retrieved was similarly unquantified. Without addresses, transaction identifiers or an asset schedule, readers could not determine what “retrieved” meant, whether funds had been frozen by another venue, or what proportion of the claimed loss remained under the attacker’s control.

Why the disclosure mattered

DragonEx’s response illustrated both an advantage and a weakness of centralized crypto markets. An operator could suspend services quickly and coordinate with other exchanges or investigators, but customers depended on that same operator for the first account of what happened. Public blockchains could later help trace identified transfers, yet transparency at the ledger layer did not automatically disclose which wallets belonged to the exchange or how customer liabilities compared with remaining assets.

The institutional issue on March 25 was therefore broader than the size of one theft. The disclosure highlighted custody concentration, cross-border enforcement and the absence of standardized incident reporting. A promise to investigate could not substitute for a reconciled asset inventory, a technical post-mortem or verified evidence of customer repayment.

Later context, kept separate

Later records clarified—but did not recreate—what was knowable on March 25. A September 2019 United Nations Security Council panel report listed a reported DragonEx theft of $9 million and discussed the incident in its examination of North Korean cyber activity. In January 2020, Chainalysis estimated the theft at roughly $7 million and attributed the operation to the Lazarus Group, describing malware delivered through a fabricated trading-software company.

Those later estimates use different figures, and the available records do not establish a common valuation timestamp or methodology that reconciles them. They should not be projected backward as a verified March 25 loss total. On the event date, the defensible conclusion remained narrower: DragonEx had disclosed stolen customer and platform assets, closed its services and had not quantified the damage.

Primary sourceUN Security Council Panel of Experts report S/2019/691

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.