{"id":400295,"date":"2025-07-30T17:51:38","date_gmt":"2025-07-30T12:21:38","guid":{"rendered":"https:\/\/dripp.zone\/news\/mpc-alone-cant-stop-multi-million-dollar-exchange-hacks-experts-warn-crypto-news\/"},"modified":"2025-07-30T18:42:23","modified_gmt":"2025-07-30T13:12:23","slug":"mpc-alone-cant-stop-multi-million-dollar-exchange-hacks-experts-warn-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/mpc-alone-cant-stop-multi-million-dollar-exchange-hacks-experts-warn-crypto-news\/","title":{"rendered":"MPC Alone Can\u2019t Stop Multi-Million Dollar Exchange Hacks, Experts Warn &#8211; Crypto News"},"content":{"rendered":"<p>Despite utilizing multi-party computation (MPC), exchanges remain exposed to breaches if internal systems and wallet infrastructure are assumed to be secure by default, according to Blockaid.<\/p>\n<div>\n<p>Crypto exchanges CoinDCX and BigONE lost a combined $71 million in separate incidents last week, both originating from what appear to be infrastructure-level failures that allowed attackers to access hot wallets.<\/p>\n<p>According to blockchain security firm Blockaid, neither case involved <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thedefiant.io\/tag\/smart-contracts\" target=\"__blank\" rel=\"noopener noreferrer \">smart contract<\/a> exploits. Instead, attackers seem to have bypassed controls at the wallet level due to assumptions that internal systems and signers were inherently secure.<\/p>\n<p>\u201cControl handed to attackers because the infrastructure assumed the signer was inherently safe,\u201d the firm wrote in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/blockaid_\/status\/1949885934628900909\" target=\"__blank\" rel=\"noopener noreferrer \">an X thread<\/a>.<\/p>\n<p>CoinDCX, based in India, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/smtgpt\/status\/1946597988660645900\" target=\"__blank\" rel=\"noopener noreferrer \">reportedly lost<\/a> $44 million from an operational liquidity wallet after attackers gained access to backend infrastructure.<\/p>\n<p>Meanwhile, BigONE, registered in the Seychelles, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thedefiant.io\/news\/hacks\/zachxbt-slams-bigone-for-scam-activitiy-after-hack\" target=\"__blank\" rel=\"noopener noreferrer \">lost roughly $27 million<\/a> in what it described as a supply chain attack. The incident appears to have involved the manipulation of backend server logic, which may have enabled unauthorized withdrawals without compromising private keys.<\/p>\n<h2>MPC Alone Is Not Enough<\/h2>\n<p>Blockaid argues that security frameworks relying solely on multisignature or multi-party computation \u2014 also known as MPC \u2014 setups are insufficient. The firm called on exchanges to adopt additional measures such as transaction simulation, policy enforcement, and intent verification during the signing process.<\/p>\n<p>In a commentary for The Defiant, Shahar Madar, vice president of security and trust products at <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thedefiant.io\/tag\/fireblocks\" target=\"__blank\" rel=\"noopener noreferrer \">Fireblocks<\/a>, a blockchain infrastructure provider known for its institutional-grade MPC solutions, said the incidents illustrate how infrastructure-level attacks can circumvent isolated security layers. He noted that while MPC is \u201ccritical for strong key management, it is only one layer of defense.\u201d <\/p>\n<p>&#8220;The attacks we have seen exploit weaknesses across the entire stack,\u201d Madar said, adding that the only way to stop them is with a \u201cfully integrated architecture.\u201d<\/p>\n<p>He pointed to the importance of combining MPC with secure infrastructure \u2014 such as hardware-based enclaves \u2014 and policy engines that enforce transaction approvals, wallet segregation, and real-time spending limits. According to Madar, when these layers are properly implemented, they can prevent the kind of unauthorized access seen in the CoinDCX and BigONE exploits.<\/p>\n<p>Blockaid says the latest breaches reflect a broader pattern of exchange-level incidents stemming from infrastructure compromise rather than on-chain vulnerabilities. The firm cited Q2 2024 data indicating that more than 65% of crypto-related losses \u2014 totaling around $500 million \u2014 were <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thedefiant.io\/news\/hacks\/crypto-hacks-total-usd74m-in-january-and-cefi-accounts-for-93-of-losses\" target=\"__blank\" rel=\"noopener noreferrer \">tied to centralized exchange<\/a> infrastructure.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Despite utilizing multi-party computation (MPC), exchanges remain exposed to breaches if internal systems and wallet infrastructure are assumed to be secure by default, according to Blockaid. Crypto exchanges CoinDCX and BigONE lost a combined $71 million in separate incidents last week, both originating from what appear to be infrastructure-level failures that allowed attackers to access [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":400301,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[274,273,272,244,266,271,268,270,269,267],"class_list":["post-400295","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-de-fi","tag-crypto-finance","tag-decentralized-finance","tag-liquidity","tag-metamask","tag-pancake","tag-slippage","tag-sushiswap","tag-tronlink","tag-trust-wallet","tag-uniswap"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/400295","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=400295"}],"version-history":[{"count":1,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/400295\/revisions"}],"predecessor-version":[{"id":400302,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/400295\/revisions\/400302"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/400301"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=400295"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=400295"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=400295"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}