Deribit $28 Million Hot Wallet Hack Analysis
2022-11-08 • Quill Audits •
https://quillaudits.medium.com/deribit-28-million-hot-wallet-hack-analysis-quillaudits-1ae00c6b946d
QuillAudits analyzed Deribit’s November 2022 hot-wallet compromise, in which attackers drained about $28 million from BTC, ETH, and USDC hot wallets. Deribit paused withdrawals, said client assets and cold-storage addresses were unaffected, and covered the loss from company reserves. The source lists Deribit and attacker wallet addresses and notes that the public cause had not been confirmed, while describing possible hot-wallet compromise paths such as online malware, seed-phrase leakage, social engineering, or keyloggers. This source does not attribute the incident to Lazarus or another DPRK actor; it is best treated as cryptocurrency-exchange incident context unless supported by separate attribution evidence.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | blockchair.com | 2022-11-08 | 2023-04-05 |
| URL | https://insights.deribit.com/ex… | 2022-11-08 | 2022-11-08 |
| DOMAIN | insights.deribit.com | 2022-11-08 | 2022-11-08 |