📈 Get daily crypto insights that make you smarter about your money

Lykke Exchange Suffers $22 Million Security Breach: How Attackers Exploited Wallet Infrastructure on June 4

The cryptocurrency security landscape faced another significant challenge on June 4, 2024, when UK-based exchange Lykke disclosed a major security breach resulting in the theft of over $22 million in digital assets. The incident, which saw attackers drain 158 Bitcoin (BTC) and 2,161 Ethereum (ETH) from the exchange’s hot wallet, underscores the persistent vulnerabilities plaguing centralized cryptocurrency platforms even as the industry matures.

The Exploit Mechanics

According to the exchange’s official disclosure, the attack occurred on June 4, targeting Lykke’s wallet infrastructure directly. The attacker executed unauthorized withdrawals totaling approximately $22 million at prevailing market prices, with Bitcoin trading near $70,500 and Ethereum around $3,800 at the time of the breach. The stolen funds were moved to two specific wallet addresses: a Bitcoin address receiving 158 BTC and an Ethereum address receiving 2,161 ETH.

The breach was not immediately disclosed by Lykke itself. Instead, web3 security researcher operating under the pseudonym @somaxbt publicly revealed the incident on June 9, five days after the initial attack. The researcher noted that the exchange appeared to be attempting to conceal the security breach, stating that the Lykke team was “still trying to hide this fact” despite the significant losses incurred.

Only after the public disclosure did Lykke formally acknowledge the attack on June 10, confirming that both Lykke UK and Lykke Corp AG had suffered the infrastructure breach. The exchange stated that affected systems were “immediately shut down to limit damage” and that security breaches had been “thoroughly examined and fully addressed.”

Affected Systems

The attack specifically targeted Lykke’s hot wallet infrastructure, the component of an exchange’s system that maintains internet connectivity to facilitate real-time trading and withdrawals. Hot wallets, while essential for operational liquidity, represent the most vulnerable point in any exchange’s security architecture because they are inherently connected to the internet.

Following the breach, Lykke halted all withdrawals and deposits as a “preventive measure,” with the platform remaining “inactive until further notice” according to a notice posted on its website. The internal investigation reportedly identified the IP addresses of the attacker, though the exchange did not specify the exact technical vector used to compromise the wallet systems.

Lykke, founded by Richard Olsen, had marketed itself as a zero-fee cryptocurrency exchange, positioning its low-cost trading model as a competitive advantage. The breach raises questions about whether cost-cutting measures in exchange operations may have compromised security investments.

The Mitigation Strategy

In its public statement, Lykke emphasized its “solid capital reserves and a diverse portfolio” while assuring customers that “clients’ funds are safe and will be recovered.” The exchange pledged to work toward full reimbursement of affected users through its financial reserves.

However, the track record of exchange recovery promises in the cryptocurrency industry is mixed. While some platforms like DMM Bitcoin, which suffered a $300 million hack just days earlier on May 31, have committed to full reimbursement through capital raising efforts including a planned $320 million fundraising round, others have failed to deliver on similar promises.

Industry best practices for centralized exchange security include implementing multi-signature wallet architectures, maintaining the vast majority of funds in cold storage with only minimal liquidity in hot wallets, deploying real-time transaction monitoring systems, conducting regular penetration testing, and establishing insurance funds to cover potential losses. The scale of the Lykke breach suggests that one or more of these safeguards may have been inadequate.

Lessons Learned

The Lykke hack represents the second-largest crypto theft in Q2 2024, contributing to quarterly losses totaling $430 million across all crypto hacks and scams — more than double the $204 million lost in Q2 2023. June 2024 alone saw $48.7 million in losses with zero funds recovered.

Key takeaways from this incident include the critical importance of timely breach disclosure. The five-day delay between the attack and public acknowledgment erodes user trust and prevents other platforms from taking defensive measures. Additionally, the incident highlights that even smaller exchanges handling tens of millions in assets remain attractive targets for sophisticated attackers.

For users, the breach reinforces the fundamental principle that funds held on centralized exchanges remain subject to counterparty risk. Hardware wallets, multi-signature arrangements, and self-custody solutions continue to provide the strongest protection against exchange-level security failures.

User Action Required

Any individuals with funds on the Lykke platform should monitor official communications for updates on withdrawal restoration and reimbursement plans. Users across all centralized exchanges should review their custody arrangements, consider moving long-term holdings to cold storage, enable all available security features including two-factor authentication, and diversify across multiple platforms to limit exposure to any single point of failure. The Lykke breach serves as a timely reminder that in cryptocurrency, security is not a feature but a continuous practice.

Disclaimer: This article is for informational purposes only and does not constitute financial advice. Always conduct your own research before making investment decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Lykke Exchange Suffers $22 Million Security Breach: How Attackers Exploited Wallet Infrastructure on June 4”

  1. 158 btc and 2161 eth stolen and lykke waited 5 days to disclose. thats not a security breach, thats a trust breach

    1. the fact that a random security researcher had to break the news says everything about lykke’s transparency

      1. @somaxbt has been catching exploits before the exchanges themselves for years now. independent researchers are basically the real security layer at this point

        1. independent researchers do it for free too. exchanges should be funding bug bounties that match what these people save them

          1. rekt_researcher

            hotwallet_w somaxbt doing free work that exchanges pay security firms 6 figures for and still miss. the incentive structure here is backwards

    2. 5 days to disclose a $22m hot wallet drain. in defi we see alerts in seconds. centralized exchanges still think they can control the narrative

      1. delayed_dao 5 days to disclose is criminal. defi protocols post incident reports within hours. centralized exchanges still think hiding the damage is a valid strategy

  2. 5 day disclosure delay on a 22M hack. lykke was probably hoping nobody would notice. blockchain doesnt let you hide unfortunately for them

  3. Fatima Alrashid

    $22 million stolen from hot wallets in 2024. We keep having the same conversation about centralized exchanges and custody.

    1. hot wallets in 2024 holding 158 btc is just reckless. any exchange with more than 50 btc in a single hot key is asking for trouble

      1. the threshold depends on withdrawal volume. a high traffic exchange needs liquidity in the hot wallet. the real issue is no timelock or withdrawal limit on the key

      2. 50 btc threshold is arbitrary though. the issue is key management and withdrawal controls, not the amount sitting in the hot wallet

        1. exactly this. multisig with timelocked withdrawals wouldve stopped this entirely. the amount in the hot wallet is secondary to having zero rate limiting on the key

      3. Ravi B. 158 BTC in a hot wallet in 2024 is negligent. even small exchanges should have moved to HSM backed cold storage by then. the tech has been available for years

        1. satoshi_cold_

          Mira K. HSM backed cold storage has been standard since 2018. Lykke holding 158 BTC in a hot key in june 2024 is pure negligence, not a sophisticated attack

  4. somaxbt has caught like 6 exchange breaches before the exchanges themselves. the fact that one researcher on twitter is faster than entire security teams at these companies is wild

  5. 158 btc to one address and 2161 eth to another. at least the blockchain makes it easy to track where it goes. small consolation

  6. somaxbt caught 6 exchange breaches before the exchanges admitted them. one researcher on twitter outpaces entire security teams. the incentive structure is completely backwards

  7. hsm_cost_myth_

    people blaming Lykke for no HSM are missing that fireblocks charges 500k a year minimum. small exchanges literally cannot afford proper key infra

  8. somaxbt found it 5 days before Lykke said anything. at that point the BTC was already mixed through at least 3 services. the disclosure delay helped the attacker not the users

    1. cold_storage_priest_

      hot_wallet_darwin_ fr. any exchange keeping 8 figures on a hot wallet after everything we learned from Mt Gox thru FTX deserves zero sympathy

  9. took 5 days for anyone to notice. makes you wonder how many smaller exchanges are sitting on holes nobody found yet

  10. disclosure_lag_

    5 days between the hack and public disclosure. thats not a security failure thats a PR decision. lykke hoped nobody would notice 22M gone

  11. 158 BTC on a hot wallet in June 2024 is just negligent. every exchange above 50 BTC daily volume had moved to HSM by 2022. Lykke skipped basic security

    1. Johan S. fireblocks at 500k/year is the excuse but Lykke had 22M in assets. they could afford it and chose not to

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$63,992.00-1.5%ETH$1,874.80-2.0%SOL$75.83-1.0%BNB$599.81-0.7%XRP$1.01-1.9%ADA$0.1907-2.5%DOGE$0.0699+0.3%DOT$0.8042+0.5%AVAX$6.48+0.2%LINK$8.34+1.8%UNI$3.94-2.2%ATOM$1.40+2.1%LTC$45.13-0.7%ARB$0.0809+3.5%NEAR$1.61-0.1%FIL$0.7020-0.2%SUI$0.6860-0.6%BTC$63,992.00-1.5%ETH$1,874.80-2.0%SOL$75.83-1.0%BNB$599.81-0.7%XRP$1.01-1.9%ADA$0.1907-2.5%DOGE$0.0699+0.3%DOT$0.8042+0.5%AVAX$6.48+0.2%LINK$8.34+1.8%UNI$3.94-2.2%ATOM$1.40+2.1%LTC$45.13-0.7%ARB$0.0809+3.5%NEAR$1.61-0.1%FIL$0.7020-0.2%SUI$0.6860-0.6%
Scroll to Top