FixedFloat’s system was hacked during the night beginning February 16, 2024, resulting in the theft of $26.1 million from the automatic cryptocurrency exchange’s operating liquidity, according to the company’s later incident account.

The compromise mattered because it affected a service that promoted rapid, account-free exchanges across Bitcoin, Ethereum and other networks. It also demonstrated that describing a service as non-custodial did not eliminate infrastructure risk: FixedFloat said it did not retain customer balances, yet it maintained liquidity that attackers could reach after compromising company systems.

The chronology requires an important qualification. FixedFloat did not publicly disclose the attack when it began. The company later acknowledged that it initially withheld the information while trying to secure its systems and limit losses. Consequently, the hack belongs to the February 16 record, but its cause, scale and attribution were not all knowable to users on February 16.

What the company ultimately confirmed

FixedFloat placed the incident during the “night of February 16–17,” without specifying a timezone, start time or discovery time. It characterized the event as an external attack enabled by vulnerabilities and insufficient security in its infrastructure. Attackers obtained access to some service functions, the company said.

That account supports a system compromise, but it is not a technical postmortem. FixedFloat did not identify the vulnerable component, explain how access was obtained, publish indicators of compromise or establish whether credentials, servers or internal administrative tools were involved.

The company said only its liquidity was stolen and asserted that user funds remained safe because it did not store customer balances. More than 30 orders were temporarily interrupted when the exchange was taken offline, according to its later update. FixedFloat subsequently said those orders had been completed. Those statements were company claims rather than findings independently established on February 16.

FixedFloat also described itself as an automatic, non-custodial centralized exchange service. That distinction matters because contemporaneous reports sometimes called it a decentralized exchange. Its own account indicates that centralized service infrastructure remained part of the attack surface.

What the chain record added

Later forensic reporting associated the incident with movements of approximately 409 BTC and 1,728 ETH. At contemporaneous asset prices, The Block estimated the two transfers at $21.17 million and $4.85 million, respectively, for a combined estimate near $26.1 million.

Those dollar figures were snapshot valuations, not cash proceeds or a consolidated loss calculation. The surviving report did not provide the exact BTC and ETH price timestamps, trading venues or conversion methodology. FixedFloat independently supplied the rounded $26.1 million total but likewise did not publish a valuation time or asset-by-asset reconciliation.

Etherscan now labels the associated Ethereum address as the “FixedFloat Drainer,” and a Bitcoin explorer preserves activity for the address cited in incident reporting. Explorer labels and journalistic attribution are useful investigative records, but they are not themselves cryptographic proof that every transaction involving an address resulted from this compromise. Public blockchains establish transfers and timestamps; connecting addresses to an organization or attacker requires additional evidence.

Later context and unresolved questions

FixedFloat eventually resumed operations and said it was cooperating with law enforcement, forensic companies and exchanges. Its public update still withheld detailed security information and promised a fuller report after the investigation.

For the February 16 record, the defensible conclusion remains narrow: FixedFloat later confirmed that its system was compromised overnight and that $26.1 million of service liquidity was stolen. The available evidence did not establish the attacker’s identity, the precise exploit path, the complete transfer sequence or an independently audited loss total.

Primary sourceFixedFloat post-incident account and service-restoration notice

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.