Market Cap: $4.0274T -1.76%
Volume(24h): $138.1061B -19.28%
  • Market Cap: $4.0274T -1.76%
  • Volume(24h): $138.1061B -19.28%
  • Fear & Greed Index:
  • Market Cap: $4.0274T -1.76%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$115761.354377 USD

-1.37%

ethereum
ethereum

$4475.268687 USD

-2.95%

xrp
xrp

$2.997758 USD

-2.97%

tether
tether

$1.000517 USD

0.02%

bnb
bnb

$986.306400 USD

-0.03%

solana
solana

$239.777963 USD

-3.17%

usd-coin
usd-coin

$0.999885 USD

0.01%

dogecoin
dogecoin

$0.266431 USD

-5.31%

tron
tron

$0.344054 USD

-2.27%

cardano
cardano

$0.895891 USD

-3.84%

hyperliquid
hyperliquid

$56.136248 USD

-3.59%

chainlink
chainlink

$23.595739 USD

-4.88%

avalanche
avalanche

$33.902799 USD

-4.84%

ethena-usde
ethena-usde

$1.001134 USD

0.02%

sui
sui

$3.673881 USD

-5.41%

Cryptocurrency News Articles

Phemex shares its lessons learned from its unprecedented incursion.

Feb 27, 2025 at 11:58 pm

Even though leaders are susceptible to the risks of running a business online. Phemex, a hybrid exchange that features best-of-breed processes of both centralized and

Phemex shares its lessons learned from its unprecedented incursion.

Hybrid crypto exchange Phemex has shared some of the key lessons learned from its recent, unprecedented incursion by a serious threat actor.

The attack, which occurred at the end of January, saw the hacker, who has a history of crypto hacks and is considered to be extremely sophisticated, gain access to a small portion of Phemex’s hot wallet. The nature of the cyber-attack was complex and difficult to prevent.

These perpetrators have not been publicly identified by law enforcement, likely reside in a state that supports this kind of action and are probably insulated from any prosecution or other legal action.

However, despite the technical difficulties posed by the attack and the fact that it was targeted at one of the world’s largest hybrid exchanges, Phemex managed to contain the damage quickly and recover core functionality to users within 24 hours – possibly one of the fastest recoveries from a hack by any established crypto exchange. Following that, Phemex implemented a strict, manual review of deposit and withdrawal transactions to reinforce security and ensure no malicious transactions were being made in the immediate aftermath.

"We want to use this piece to address the incident, talk about how we handled it, and explain what we’ve done to prevent such incidents in the future," says Phemex CEO Federico Variola.

He stressed that, while the attack came from a highly sophisticated threat actor, the vast majority of user funds were never at risk and the exchange covered all users’ losses.

"We also resumed core operations as quickly as possible and immediately revamped our hot wallet security infrastructure to greatly minimize these security risks in the future."

[uuid]

The hybrid exchange's technical team has designed and implemented a new, more robust hot-wallet security infrastructure.

"A major lesson we’ve learned and reflected on is that Phemex has grown very fast during the latest bull market and some of our operating procedures lagged behind our growth," Variola says. "This cyber-attack showed that the kind of security measures that may have been serviceable for our previous size are no longer acceptable for our current scale."

Phemex's new structure is designed with a zero-trust architecture in mind and leverages cutting-edge Enclave technology. This includes AWS Nitro to achieve robust, chip-level security for hot wallets.

While that solves the immediate problem, it wouldn't put Phemex ahead of the hackers. So the team made moves to protect all wallets which any of its users might hold.

"We plan to employ a tiered-wallet system with cold wallets," Variola says. "It would also apply to hot wallets – which will hold a much smaller proportion of our funds moving forward."

The tiered system also applies to warm wallets, which combine hot wallets' internet connection, speed and efficiency with cold wallets' enhanced security and manual control.

Phemex is also increasing the workforce dedicated to infrastructure security, with different teams overseeing separate elements and fewer individuals having access to the entire system. From end to end, every task will be reviewed by industry-leading third parties.

That could slow down the pace of Phemex's service delivery by a step, but Variola's team is convinced it must be done.

"The operations of our exchange will be more complex using the new system, but this cannot be avoided because security is of highest priority," Variola says. "We are extremely confident in the new system and we’re applying for third-party certifications on these security standards."

Original source:coindesk

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Sep 20, 2025