Skip to content
Yieldo

Mixin Network

$200.0M
Funds stolen
Funds returned
23 Sep 2023
Date of incident
Technique
Database Breach
Classification
Frontend & Infrastructure
Target type
Other
Affected chains
Mixin
Source
No public source link

On September 23, 2023, Mixin Network — a cross-chain custody and messaging protocol — lost roughly $200 million in cryptocurrency after attackers breached the database of its cloud service provider. The company disclosed the breach two days later and suspended deposits and withdrawals while it investigated (TechCrunch). It became the largest single crypto theft reported that year, ahead of the March 2023 Euler Finance exploit (Rekt).

How the attack worked

Mixin's architecture custodies user assets across several blockchains — Bitcoin, Ethereum and various tokens — but stores the operational data behind its hot wallets in an off-chain cloud database rather than on-chain. Attackers didn't touch a smart contract, a bridge, or blockchain consensus: they broke into that cloud provider's database directly, which matches our classification of this incident as a database attack rather than an on-chain exploit. Once inside, moving the funds out required nothing more sophisticated than ordinary transfers — no flash loan, no oracle manipulation, no on-chain signature forgery. On-chain tracing puts the drained funds at roughly $94 million in ETH, $23.5 million in USDT swapped into DAI, and $23 million in BTC, with the remainder spread across other assets Mixin held in custody (Rekt). The mechanism illustrates a recurring pattern in "decentralized" custody products: the chain itself stays intact while the centralized backend that manages keys and balances becomes the real attack surface.

What happened next

Founder Feng Xiaodong said in a livestream that the team could only vouch for about half of user assets as safe; depositors outside that guarantee received "tokenized liability claims" rather than a full refund (Unchained). Mixin brought in Google's Mandiant and the security firm SlowMist to investigate, and separately offered a $20 million bounty — about 10% of the loss — for the return of the stolen funds, with no public record of the attacker accepting it. No arrests or identification of the attacker have been reported. The stolen funds mostly sat dormant afterward: roughly two and a half years later, a wallet tied to the hack moved $3.85 million in ETH into Tornado Cash across 20 transactions, the first sign of activity since the theft (CoinCentral). As far as public sources show, none of the $200 million has been recovered or returned by the attacker; Mixin's 50% guarantee was funded from its own resources, not from restitution.

What this means

  • Any protocol that custodies assets across chains through a centralized backend — key management, balance ledgers, signing infrastructure — inherits that backend's security, regardless of how decentralized the on-chain layer is marketed to be.
  • Users have no way to audit a project's cloud security from outside; the only visible signal is usually the vendor's own claim of "enterprise-grade infrastructure," which says nothing about who can reach the database.
  • A partial compensation guarantee (Mixin's "50%") is not insurance — it is a discretionary promise funded from the protocol's own balance sheet, revisable if losses turn out worse than the initial estimate.
  • Stolen funds can stay dormant for years and still surface through mixers like Tornado Cash; a hack going quiet in the news is not evidence the case is closed.

On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.