Many OKX Users Lose Funds Due to Identity Theft

The incident involving OKX users losing assets due to a two-factor authentication (2FA) security vulnerability has revealed new developments.

Azcnews Many Okx Users Lose Funds Due To Identity Theft

According to a post on its Chinese X account on June 12th, the cryptocurrency exchange OKX confirmed a data breach that resulted in the theft of user assets. “The issue is currently under investigation by the authorities, and we cannot provide further details at this time,” the exchange stated in the post.


Earlier, on June 10th, two OKX users reported a security vulnerability on social media, claiming it allowed hackers to access their accounts and drain their wallets. Blockchain security firm SlowMist identified similarities between the incidents, noting that a new API key was created after users received SMS alerts from Hong Kong to verify that the account holder was conducting the transactions.

On June 10th, Web3 security group Dilation Effect asserted that attackers exploited a security flaw in OKX, allegedly allowing users to disable Google Authenticator (GA) or SMS verification without triggering the 24-hour withdrawal suspension system for certain activities.

However, the exchange has denied this claim after conducting an investigation, refuting the speculations about a security flaw in its verification system. OKX stated, “This incident is not related to the choice of Google Authenticator or SMS verification.” Instead, they suggested that the breach might have occurred because malicious actors forged OKX users’ documents, thus obtaining sensitive information and bypassing identity verification measures.

In a recent X post, OKX mentioned that they have compensated and will continue to compensate affected users. According to a report by Wu Blockchain on June 12th, the two users whose accounts were compromised have received full reimbursement from the exchange. To prevent future incidents, OKX announced that it will mandate the use of Google Authenticator for all transactions.


The exact number of users whose identities were stolen and accounts drained has not yet been disclosed by OKX. However, the amount of money involved appears substantial. Recently, a hacker breached the account of Crypto Lala, the operations manager of the Singapore-based market maker QuantMatter, and stole $11.6 million from the wallet.

This theft occurred on May 30, 2024, according to the post. Despite the account being secured with offline Google Authenticator (GA), the cause of the hack remains unclear and requires further investigation.

The hacker added whitelisted addresses and converted the stolen funds into BTC, ETH, USDC, and USDT. Subsequently, the hacker transferred all the funds to an on-chain wallet address. Currently, the money remains in that wallet without any signs of movement.


“The hacker had full access to my account. They converted everything to ETH and withdrew all my funds within 25 minutes. I noticed this through one of my sub-accounts. When I checked my main account, all the money had been stolen,” the post revealed.

Speculations suggest that the hacker may have used offline GA verification to steal the funds, indicating that the GA information of the market maker was compromised.

The true cause of the incident, the estimated number of affected users, and the extent of the damages remain unclear. However, this incident serves as a wake-up call for the security systems of centralized exchanges utilizing Google Authenticator. It highlights the need for stricter security measures to better protect users in the Web3 space.

(88 votes)

1.1/5

(88 votes)
  1. Avatar of
    Anonymous

    Wow

  2. Avatar of
    Anonymous

    okx监守自盗啊,还在这糊弄人呢

  3. Avatar of Ali
    Ali

    نوش جان هکر.این صرافی و همه صرافی‌هایی که به ناحق مردم مظلوم ایران را از حقشان محروم کرده یا می‌کنند به دلیل نقض عدالت از عذاب خداوند نمی‌توانند فرار کنند و به این طريق تابان سختی را میدهند

Comments are closed.

Latest

Government Set To Reopen After 7 Weeks Of Shutdown 2

News | Editor Choice | Policy & Regulations

Government Set to Reopen After 7 Weeks of Shutdown

After more than seven weeks of paralysis due to the budget crisis, the U.S. government is set to reopen as the House of Representatives passes a historic spending bill, ready for President Donald Trump’s signature.

China Accuses The U.s. Of Masterminding A $13 Billion Bitcoin Theft

News | Bitcoin | Editor Choice

China Accuses the U.S. of Masterminding a $13 Billion Bitcoin Theft

China has sent shockwaves across global markets after accusing the U.S. of orchestrating a $13 billion Bitcoin theft, turning the world’s largest cryptocurrency into the latest flashpoint in the tech rivalry between the two superpowers.

Deposit 15 Usdt And Get 15 Usdt On Bingx

Airdrops | Editor Choice

Deposit 15 USDT and get 15 USDT on BingX

To welcome new traders and thank our loyal users, BingX is launching a special deposit bonus campaign with total rewards of up to 3,000 USDT.

James Wynn Goes “all In” On Shorting Bitcoin After 12 Liquidations

News | Bitcoin | Editor Choice

James Wynn Goes “All-In” on Shorting Bitcoin After 12 Liquidations

High-leverage trader James Wynn has gone “all-in” betting on Bitcoin dropping below $92,000, despite being liquidated 12 times in just 12 hours, leaving the crypto community closely watching his high-risk moves.

Trump Considers Giving Americans $2,000 From Tariff Revenues

News | Editor Choice | Policy & Regulations

Trump Considers Giving Americans $2,000 from Tariff Revenues

President Donald Trump has shaken up U.S. politics once again, announcing a plan to hand out $2,000 per American from tariff revenues—an audacious move seen as his latest bid to capture voter enthusiasm ahead of the election.

Screenshot 2025 10 20 091338