Social engineering of an employee laptop gave server-side access to an internal operational wallet, which was segregated from customer custody.
Customer funds were unaffected. The exchange absorbed the loss from its own treasury.
Segregation worked exactly as intended and contained the blast radius. The lost funds also sat outside the scope of any reserve attestation, which is worth understanding about what attestations cover.
These are the custody configurations structurally exposed to this kind of event. It describes the failure class, not any individual holder.
Whether your own arrangement sits in one of those groups is the question our Custody Independence Standard is designed to answer, and the four questions in Is your custody setup actually safe? walk through it.
Exchange incident report
Figures are as reported by the named sources. Proof of Custody has not independently reproduced the underlying analysis.
Proof of Custody, "CoinDCX" incident record, proofofcustody.io/incidents/coindcx-2025Social engineering of an employee laptop gave server-side access to an internal operational wallet, which was segregated from customer custody. Reported loss: ~$44M.
Segregation worked exactly as intended and contained the blast radius. The lost funds also sat outside the scope of any reserve attestation, which is worth understanding about what attestations cover.
This class of failure could reach: bitcoin left on an exchange. It describes the failure class rather than any individual holder.