Web3 & Enterprise·Jan 24, 2025
Phemex halts withdraws following $37M hack
Phemex, a Singapore-headquartered crypto derivatives trading platform, has halted withdrawals following a multi-million dollar hack.Photo by GuerrillaBuzz on UnsplashHot wallet compromisedIn a message to platform users published to social media, the project stated: “To ensure security, withdrawals have been temporarily suspended while we conduct an emergency inspection and strengthen wallet services. We sincerely apologize for the inconvenience. Withdrawals will be restored soon.” In further commentary, the project apologized for the disruption, assuring service users that its mission remains to provide a trusted trading environment, while outlining that it is working on putting together a compensation plan. It added that “Our ongoing business operations are fine,” and that “trading services continue as usual.” The digital assets were removed from the platform over multiple blockchains including Polygon, Arbitrum, the Base network and BNB. Blockchain analytics firm Lookonchain itemized some of the assets that are believed to have been stolen. They include 3.48 million USDC stablecoin, 3.42 million USDT stablecoin, 841 ETH valued at $2.7 million, 110,701 LINK valued at $2.69 million, 142 billion PEPE tokens valued at $2.12 million, 1.19 million FET tokens valued at $1.45 million and 29,509 AVAX tokens valued at $1.04 million. Initial reports put the loss at $31 million. However, Web3 security firm Cyvers later claimed that $37 million covers the full extent of the loss. Following deeper analysis, it found that both Bitcoin and TRON blockchains had also been impacted, resulting in the overall loss being increased by a further $6 million. Cold wallet assets are safeThe company’s CEO Federico Variola, published a post on X advising service users that all of the assets held within the company’s cold wallets remain safe. He included a link to the Phemex proof of reserves, encouraging customers to check it. In a follow-up post, he wrote: “We are currently carefully testing our system to reprise withdrawals as soon as possible. Due to the sophistication of the threat actor we cannot rush this stage. The estimated timeline to reprise full operations is within 24h, thank you for your support.” The XNET Foundation, a non-profit entity that develops decentralized wireless networks, said that it is actively working with the Phemex team on the production of an exploit report following the incident. It added that “It has been confirmed that tokens sent to the exchange for a launchpad pool were compromised as part of this exploit.” Ongoing problemCrypto hacking remains a major concern within the digital assets sector. Blockchain security firm PackShield reported recently that $1.3 billion had been laundered from crypto hacks in 2024. That statistic demonstrates that the problem is worsening as it accounts for a $342 million or 280% increase when compared with 2023. In December a Chainalysis report found that 61% of the hacking losses suffered in 2024 implicated the involvement of North Korean hackers. It estimated crypto hacking losses of $2.2 billion for 2024, based on losses associated with 303 hacking incidents.