FTX
In the early hours of November 12, 2022 — about 24 hours after FTX filed for Chapter 11 bankruptcy — cryptoassets began leaving FTX-controlled wallets without authorization. Elliptic's blockchain trace put the outflow at roughly $477 million; U.S. prosecutors later described it in court filings as "over $400 million." The breach landed on an exchange that was already insolvent, turning a liquidity collapse into a criminal case as well.
How the attack worked
For over a year the cause was officially unclear — FTX's own bankruptcy counsel and Bahamian regulators gave conflicting accounts of whether this was an external hack, an inside job, or an asset seizure by local authorities. In January 2024 the U.S. Department of Justice supplied the answer: the funds were taken through a SIM-swapping scheme. Attackers had a mobile carrier port a phone number tied to FTX's infrastructure onto a SIM card they controlled, letting them intercept the SMS-based codes protecting access to internal systems. That access was enough to move assets out of FTX's Ethereum-based wallets and, per Elliptic, to mint roughly $280 million in new FTT tokens that had never previously existed — a step no outside attacker could take without control over FTX's own token contract. The stolen ETH, FTT, USDT and PAXG were then run through decentralized exchanges (Uniswap, 1inch, CowSwap) and converted mostly into ETH and DAI, with part of the balance later bridged toward Bitcoin via RenBridge — a laundering pattern Arkham Intelligence called hasty rather than professionally planned.
What happened next
Issuers froze what they could reach: about $100 million in USDT and PAXG was blocked before it could move further. Within days, on-chain investigators traced roughly $339 million of the remaining balance sitting largely untouched across ETH, DAI, BNB and other tokens, and noted the attacker had used a KYC-verified Kraken account to pay gas fees — a trail that later helped investigators attribute the theft. The DOJ indicted three individuals in January 2024 for running the SIM-swap operation; available sources do not establish that the stolen assets themselves were seized or returned to FTX's bankruptcy estate. FTX did not survive regardless of the hack: the exchange had already filed for bankruptcy the day before, and creditor recoveries later came from selling remaining corporate assets, not from clawing back this specific theft.
What this means
- SIM-swap access to phone-based verification can compromise infrastructure-level accounts, not just individual user wallets — carrier-side authentication is a systemic weak point unrelated to smart-contract or wallet security.
- A collapsing exchange is a uniquely attractive target: chaos, reduced staffing, and a public bankruptcy filing mark exactly the moment internal controls are least likely to be watched closely.
- Minting new tokens as part of a "hack" (here, FTT) is a strong signal of privileged internal access rather than a pure external exploit — worth noting whenever an incident is described only as an "unauthorized transfer" without specifying the access level involved.
- Fast conversion through DEXs and cross-chain bridges within hours remains the default laundering playbook; issuer-side freezes (as with USDT/PAXG here) are still the fastest recovery lever available, but they only work for centralized, freezable tokens.
On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.