South Korean cryptocurrency exchange GDAC disclosed on April 10, 2023 that assets had been transferred without authorization from its hot-wallet system, and that it had suspended deposits and withdrawals while responding to the breach. GDAC said the transferred assets represented approximately 23% of everything it held in custody.

The disclosure was the consequential event for April 10 even though GDAC placed the underlying intrusion at about 7 a.m. Korea Standard Time on April 9. The distinction matters: users and counterparties learned of the event on April 10, when the exchange announced the loss, stopped wallet services and sought help from law enforcement, cybersecurity authorities, exchanges and token issuers.

What GDAC reported

The asset list attributed to GDAC comprised 60.80864074 bitcoin, 350.50 ether, 10 million WEMIX and 220,000 USDT. GDAC said the assets went to an unidentified wallet. It reported blocking its deposit-and-withdrawal wallet system and related servers, requesting a police cyber investigation, seeking technical support from the Korea Internet & Security Agency and notifying Korea’s Financial Intelligence Unit.

Those points were company claims on April 10, not completed findings by investigators. GDAC did not publicly establish the method of compromise in the contemporaneous reports reviewed for this reconstruction. It also did not give a firm time for restoring withdrawals. WEMIX, the issuer of the largest token amount in the disclosed basket, separately acknowledged on April 10 that GDAC had announced unauthorized withdrawals including WEMIX and said it was monitoring the situation.

Korea JoongAng Daily reported that GDAC disclosed the event about 34 hours after the time the newspaper attributed to the exchange. That lag increased the importance of the operational response: an exchange security event is not only a question of tokens moving on public ledgers, but also of when customers are informed and when counterparties can act on freeze requests.

The loss estimate had a moving denominator

Contemporaneous dollar descriptions clustered around $13 million to $13.6 million, but those figures were estimates rather than a single audited loss number. Korea JoongAng Daily described about 18 billion won, or $13.6 million, in its headline account while also saying the listed assets were worth around 20 billion won at roughly 7 a.m. on April 9. The Block used approximately $13 million.

The difference reflects a basic limitation in valuing a multi-asset transfer. Bitcoin, ether and WEMIX traded continuously; USDT was designed to track the dollar but could vary; and reports could use different venues, exchange rates and observation times. Coinburn therefore treats the token quantities as the stronger measurement and the fiat values as contemporaneous approximations.

The 23% figure also came from GDAC. It described the transferred assets as a share of assets under custody, not as an independently audited share of customer liabilities. The surviving event-day record does not by itself establish GDAC’s solvency, the ultimate loss borne by customers or how much could be frozen or recovered.

What could and could not be concluded

The verified April 10 development was that GDAC announced a large hot-wallet breach, halted wallet services and reported the incident to Korean authorities. The evidence did not yet identify an attacker, establish an attack vector or prove final recoveries. Calling the event a smart-contract exploit or a private-key theft on April 10 would have gone beyond the exchange’s disclosed record.

The episode nevertheless mattered beyond GDAC’s ranking among exchanges. A hot wallet exists to support routine transfers, so compromising it can turn a technical failure into an immediate liquidity and confidence problem. The service suspension was protective, but it also meant customers could not freely move assets while the investigation remained open.

Later forensic context

On April 14, CertiK reported that Ethereum-network activity likely began at 18:36 UTC on April 8 and assessed a private-key compromise as highly likely, while expressly calling that conclusion unconfirmed. That later analysis helps frame the investigation but does not change what was knowable from GDAC’s April 10 disclosure.

Primary sourceWEMIX — Notice on GDAC Exchange Hack Alert

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.