The decentralized application FixedFloat falls victim to a $26 million hack

Related

Digital Reserve成为2026香港Web3嘉年华二级展位赞助商

Digital Reserve已确认加入2026香港Web3嘉年华,将作为二级展位赞助商为大会提供支持 Digital Reserve 是一家澳洲持牌的加密货币出入金与交易平台,深耕行业多年、穿越多轮牛熊周期,凭借对华人市场的深刻理解、完善的银行通道与高质量服务,持续为专业客户提供稳定、顺畅的数字资产流动解决方案。更多信息: https://digitalreserve.net/ 香港Web3嘉年华是由万向区块链实验室与HashKey Group联合推出的Web3活动品牌,由W3ME承办,自2023年起于每年4月在香港会议展览中心举办,聚焦行业热点话题与政策趋势,是亚洲规模最大、最受关注的Web3行业盛会之一。 2026香港Web3嘉年华将于4月20日-23日在香港会议展览中心盛大举行。自2023年首届举办以来,香港Web3嘉年华已飞速成长为全球最具影响力的加密峰会之一,为全球东西方交流构建了一个高规格、高质量、高纵深的平台。过往三届盛会累计吸引超10万名现场参会者,汇聚超350个前沿项目参加,邀请超1200位演讲嘉宾分享,并衍生超400场周边活动,成功构建了一个以大会为核心、辐射全港的活力生态圈。 目前,香港特别行政区财政司司长陈茂波,香港证监会中介机构部执行董事叶志衡,万向区块链董事长、Hashkey Group董事长兼CEO肖风,香港特别行政区立法会议员(科技创新界)邱达根,Solana Foundation总裁Lily Liu,MatrixPort创始合伙人及首席商务官Cynthia Wu,Animoca...

卓锐证券成为2026香港Web3嘉年华白金赞助商

Hong Kong, 5th March 2026, 卓锐证券已确认加入2026香港Web3嘉年华,将作为白金赞助商为大会提供支持。 卓锐证券(香港)有限公司(中央编号:BRE865)是香港证监会认可持牌法团,持有第1、2、4、5、9类牌照。作为全港增速TOP1的持牌虚拟资产券商*,卓锐证券专注构建合规安全的交易生态,实现传统资产与加密货币的无缝流动。通过自主研发的一站式交易平台“ZR”,投资者只需一个账户,即可借助AI赋能的机构级视野,灵活配置股票、ETF及加密货币。了解更多:https://www.zr.hk/ 香港Web3嘉年华是由万向区块链实验室与HashKey Group联合推出的Web3活动品牌,由W3ME承办,自2023年起于每年4月在香港会议展览中心举办,聚焦行业热点话题与政策趋势,是亚洲规模最大、最受关注的Web3行业盛会之一。 2026香港Web3嘉年华将于4月20日-23日在香港会议展览中心盛大举行。自2023年首届举办以来,香港Web3嘉年华已飞速成长为全球最具影响力的加密峰会之一,为全球东西方交流构建了一个高规格、高质量、高纵深的平台。过往三届盛会累计吸引超10万名现场参会者,汇聚超350个前沿项目参加,邀请超1200位演讲嘉宾分享,并衍生超400场周边活动,成功构建了一个以大会为核心、辐射全港的活力生态圈。 目前,香港特别行政区财政司司长陈茂波,香港证监会中介机构部执行董事叶志衡,万向区块链董事长、Hashkey Group董事长兼CEO肖风,香港特别行政区立法会议员(科技创新界)邱达根,Solana Foundation总裁Lily Liu,MatrixPort创始合伙人及首席商务官Cynthia...

Sui stablecoin USDsui debuts as new backbone for on-chain payments and DeFi

Backed by institutional-grade infrastructure and strong demand for digital...

Share

A few days ago, the decentralized non-KYC application FixedFloat suffered a hack attack on its infrastructure, resulting in losses of 26 million dollars.

According to the auditing and blockchain analysis company PeckShield, a total of 1728 ETH and 409 BTC were stolen: some of the money was then laundered by passing through decentralized mixers and coinjoin transactions.

FixedFloat has stated that user funds are safe and that the hack did not compromise the financial stability of the crypto exchange application.

All the details below.

Vulnerability in FixedFloat’s structure: the decentralized application suffers a $26 million hack in BTC and ETH

On Saturday, February 17th, the decentralized cryptocurrency exchange application FixedFloat was the victim of a hack that caused losses of 26 million dollars in BTC and ETH.

It all started when several users reported experiencing frozen transactions and missing funds in their accounts; shortly after, it was discovered through on-chain analysis that several million dollars had been drained to various unrecognized external wallets.

Although it is not yet clear how the attack occurred, the FixedFloat team promptly explained that it was a “small technical issue” at the time of the incident.

The same has announced that the funds will be refunded to the platform users and that the hack did not compromise the financial stability of the company.

Anyway, at the time of writing the article the decentralized application remains inactive and in maintenance mode, but it will be reopened in an unspecified future, as soon as it is certain to be safe to use.

Here is what was reported on X by Fixed FixedFloat following the hack:

The decentralized exchange is known for its non-KYC services, which do not require registration under the classic “Know Your Customer” procedure, allowing a competitive advantage in terms of privacy.

By offering the possibility of remaining anonymous and allowing transactions in Bitcoin through Lightning Network to its customers, FixedFloat has attracted a wide range of users from the United States.

Partly, the characteristic of anonymity and the lack of internal controls favored the malicious hacker attack, who did not have to provide their personal data to access the application.

According to the cybersecurity and blockchain analysis company PeckShield, the theft amounts to precisely 1728 ETH, worth 4.85 million dollars, and 409 BTC, worth almost 21 million dollars.

Most of the ether from the hack has already been transferred to a wide range of decentralized exchanges on the Ethereum blockchain.

FixedFloat has reported that they are working with law enforcement, blockchain forensic companies, and cryptocurrency exchanges to track down the hackers, who have not yet contacted the exchange. 

The company has stated that it will honor all its payment obligations as soon as it resumes operations and is certain that the exchange will be safe to use again.

Part of the stolen BTC from the hack were recycled through a coinjoin operation

While the ETH stolen from the hack of the decentralized application FixedFloat have been easily moved to dozens of different addresses and circulated through the Ethereum blockchain, the BTC that are part of the same loot are about to be recycled with coinjoin transactions.

We remind you that coinjoin is a type of Bitcoin operation, theorized for the first time by Gregory Maxwell in 2013, in which several BTC payments are combined into a single transaction, making it difficult to determine which addresses have spent which amount.

Similar to what happens with decentralized mixers like Tornado Cash, coinjoin transactions are combined together to make a single transaction in a joint pool, from which depositors can then request back their “pooled” and anonymous funds.

In our case, the hacker exploited a kind of mixer that uses a method to increase privacy similar to coinjoin, where several BTC have already been exchanged.

In particular, we can affirm that according to what was explained by a researcher web3 on X, part of the stolen funds, to be precise 2.7544 BTC, have flowed into the address

34F2Jjmzo4N3kz3zVVBbqr3nn6NkvQvNjA, which belongs to the CEX TradeOgre.

This money could represent the commission paid by the malicious actor to use the mixer, which seems to be linked to the Whirpool application that implements an advanced privacy system.

It is believed that 166 out of the 409 BTC stolen from the decentralized application FixedFloat have already passed through the Whirpool mixer.

Incidents like this are commonplace in cryptographic environments, especially in non-KYC ones that somehow protect the anonymity of hackers.

According to the on-chain forensic research company Chainalysis, despite the numerous incidents recorded in 2023 hacks and exploits are decreasing compared to the previous year, when there was a boom in thefts.

Overall, the value of hacked funds has decreased by about 54.3% compared to 2022 with a total stolen amount of approximately 1.7 billion dollars, mainly derived from DeFi applications hacks.

applicazione decentralizzata hack