📈 Get daily crypto insights that make you smarter about your money

How Social Engineering and Hot Wallet Exploits Fueled a Devastating Week for Crypto Security

The week of September 14, 2023, will be remembered as one of the most damaging stretches for cryptocurrency security in recent memory. Within days, three major incidents — the Vitalik Buterin SIM swap attack, the Remitano hot wallet breach, and the CoinEx hack attributed to North Korean operators — collectively drained tens of millions of dollars from the ecosystem. Bitcoin traded at approximately $26,540 while Ethereum hovered around $1,627, masking the turbulence unfolding behind the scenes.

The Exploit Mechanics

The attacks relied on fundamentally different vectors but shared a common theme: exploiting trust. On September 9, Ethereum co-founder Vitalik Buterin had his X (formerly Twitter) account compromised through a SIM swapping attack. The attacker social-engineered T-Mobile into transferring Buterin’s phone number to a device under their control, bypassing SMS-based two-factor authentication. The compromised account then posted a fraudulent NFT minting link that directed followers to a phishing site. Users who connected their wallets lost a combined $700,000 in cryptocurrency and non-fungible tokens.

Days later, on September 14, peer-to-peer exchange Remitano discovered that its hot wallets on both the Ethereum and TRON blockchains had been drained of approximately $2.7 million. The breach originated from a compromised private key, reportedly exposed through a third-party data leak. The attacker moved swiftly, siphoning 1,359,253 USDT, 208,188 USDC, 34.4 ETH, and 104,360 ANKR tokens on Ethereum, along with 537,915 USDT and 3,750,700 TRX on TRON.

The CoinEx hack, initially reported at $27 million but later revised to approximately $55 million, followed a similar playbook: compromised hot wallet private keys. Blockchain investigator ZachXBT linked the CoinEx attack to the same Lazarus Group wallets used in the Stake.com heist, which the FBI attributed to North Korean state-sponsored actors.

Affected Systems

The scope of these attacks was staggering. Buterin’s SIM swap affected individual users who trusted his account — Ethereum’s most prominent public figure. The Remitano breach impacted a peer-to-peer exchange serving users across multiple developing nations. CoinEx, a Hong Kong-based exchange, saw its entire hot wallet infrastructure compromised, forcing a complete suspension of deposits and withdrawals.

On the Ethereum blockchain alone, the Remitano attacker moved funds through address 0x74530e81e9f4715c720b6b237f682cd0e298b66c, converting stolen USDC and ANKR to 163 ETH before transferring proceeds to HitBTC. Tether’s rapid response team froze approximately $1.4 million in USDT on the attacker’s TRON address, preventing further losses but highlighting the centralized counterparty risk inherent in stablecoins.

The Mitigation Strategy

Tether’s intervention in the Remitano case demonstrated the value of rapid response protocols. By freezing the attacker’s addresses within hours, approximately $1.9 million in USDT was preserved. Remitano responded by suspending all deposits and withdrawals, migrating remaining user funds to cold wallets, deactivating old wallet addresses, and advising users to generate new deposit addresses.

For the Buterin SIM swap, the incident reignited discussions about eliminating SMS-based 2FA entirely. Buterin himself confirmed the attack vector and urged the community to adopt hardware security keys and passkeys instead of phone-based authentication. The attack exposed how even the most technically sophisticated individuals remain vulnerable to social engineering.

CoinEx took the drastic step of shutting down its entire hot wallet server infrastructure, transferring remaining assets to secure addresses, and engaging external security experts to conduct a full forensic investigation.

Lessons Learned

The convergence of these incidents underscores several critical lessons for the crypto industry. First, SMS-based two-factor authentication remains a fundamental vulnerability. Every exchange and high-profile individual should migrate to hardware security keys or time-based one-time passwords. Second, hot wallet private keys require the same level of protection as cold storage — multi-signature arrangements, hardware security modules, and strict access controls are non-negotiable.

Third, third-party data leaks can cascade into catastrophic breaches. Remitano’s compromise originated not from a direct attack but from sensitive data exposed through an external partner. Regular security audits should extend beyond internal systems to include all third-party integrations and vendors.

User Action Required

Individual users should immediately audit their own security practices. Disable SMS-based 2FA on all crypto-related accounts and replace it with authenticator apps or hardware keys. Verify that exchange accounts use unique, strong passwords not shared with any other service. Consider moving significant holdings to hardware wallets rather than keeping funds on exchanges, where hot wallet vulnerabilities remain an ever-present risk. The events of this week prove that no target is too prominent — or too small — for determined attackers.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any financial decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “How Social Engineering and Hot Wallet Exploits Fueled a Devastating Week for Crypto Security”

    1. Mateo Ruiz 55M from CoinEx alone and BTC barely moved. the market has gotten disturbingly good at pricing in hacks

  1. had my number ported in 2022. took me 3 days to get it back. T-Mobile did not even flag it as suspicious. the telco security layer is a joke

    1. simswap_survivor 3 days to recover your own number is insane. carriers should require in-person verification for any SIM swap but they wont because it adds friction

  2. The CoinEx attribution to North Korean operators matches the pattern from the Treasury advisory. These are not random hackers, they are state-funded.

    1. treasury_watch_kep

      state backed crews treating exchange hot wallets as a sanctions proof revenue stream is the grimmest part. the 55M from CoinEx was a slow quarter for them

      1. 55M from CoinEx was apparently a slow quarter. same stretch Remitano hot wallets got hit too, they were speedrunning every vector that month

  3. $55M from CoinEx, $700K from Vitaliks followers, $2.7M from Remitano. all preventable with basic opsec. the industry refuses to learn

  4. Vitalik getting SIM swapped and the industry collectively shrugged says everything about crypto opsec culture. if the creator of Ethereum gets hit nobody is safe

    1. if the creator of Ethereum can get SIM swapped then every crypto founder is a target. projects need to treat social account security like they treat multisig

  5. the T-Mobile social engineering playbook is identical every time. call center reps are the weakest link in every SIM swap chain

    1. Jana K. exactly. someone at T-Mobile got tricked into porting VITALIKs number. if they can get him they can get anyone

      1. telco_rage_ 3 days to recover a phone number while someone drains your exchange accounts. carriers have zero liability which means zero incentive to fix this

        1. zero liability is the whole problem. telcos eat none of the fraud cost so port-out requests are just queue items to them. one FCC rule could fix this and it still hasnt happened

          1. the port-out freeze rule has been proposed how many times now. carriers lobby it down every cycle because fixing it costs them a call center

          2. got my number ported out in 2022, three days of hell to unwind it. the sim swap playbook was public knowledge and carrier staff basically handed people over

      2. rekt_diaries 700K from one phishing link on Vitaliks account. one post, one link, and people connected their wallets in seconds. the speed of social engineering attacks is the real threat

        1. Emilija S. one post one link 700K gone. the speed of social engineering attacks makes every other security layer irrelevant once the trust is established

    2. Jana K. the call center rep angle is the real vulnerability. someone making 15 an hour at T-Mobile is not a security checkpoint. FIDO2 kills this attack vector entirely

      1. telco_rage_ a YubiKey costs 45 dollars and eliminates SIM swapping entirely. exchanges that still allow SMS 2FA in 2026 are choosing convenience over user funds

        1. fido_only_ a 45 dollar YubiKey vs 700K lost on one phishing link. the ROI on hardware keys is infinite and somehow people still use SMS 2FA

  6. vitaliks follower list was basically a hot wallet. one fake mint link, 700K gone, no exploit needed. social engineering beats every audit

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,821.00-1.9%ETH$2,460.49-1.6%SOL$101.13-2.9%BNB$716.19-4.5%XRP$1.38-3.5%ADA$0.2127-3.3%DOGE$0.0852-6.1%DOT$1.10-6.6%AVAX$7.73-2.8%LINK$11.84-2.3%UNI$6.02-9.9%ATOM$1.79-5.7%LTC$52.22-3.8%ARB$0.1483-11.2%NEAR$2.41-7.7%FIL$0.8069-4.8%SUI$0.7616-6.2%BTC$77,821.00-1.9%ETH$2,460.49-1.6%SOL$101.13-2.9%BNB$716.19-4.5%XRP$1.38-3.5%ADA$0.2127-3.3%DOGE$0.0852-6.1%DOT$1.10-6.6%AVAX$7.73-2.8%LINK$11.84-2.3%UNI$6.02-9.9%ATOM$1.79-5.7%LTC$52.22-3.8%ARB$0.1483-11.2%NEAR$2.41-7.7%FIL$0.8069-4.8%SUI$0.7616-6.2%
Scroll to Top