NexFlow › Is CoinEx safe
Is CoinEx safe? The exchange that treated a $70M theft like a billing problem
CoinEx owns the tidiest incident file in this family: September 2023, leaked hot-wallet private keys, ~$70 million out, Lazarus Group suspected — and a response so procedural it reads like a runbook: same-day shutdown, industry freeze coordination, nine-day wallet rebuild, staged resumption with new deposit addresses, and a dedicated User Asset Security Foundation absorbing 100% of the loss. The wrinkle worth your attention sits before the hack: CoinEx settled with the New York AG that June and exited the entire US market.
What CoinEx is
CoinEx is a Hong Kong-based centralized exchange founded 2017, operated by Vino Global Limited — a mid-tier venue in the long-tail listing class: hundreds of assets, contract trading, its own CET token and CoinEx Smart Chain. The venue it is not: a regulated-market operator. Its registrations are offshore-class, which is exactly the posture its US settlement later confirmed. Custody is standard custodial — the exchange holds keys — with a named institutional feature that turns out to matter: a pre-funded User Asset Security Foundation, one of the earliest dedicated cover pools in this tier, publicly pledged to absorb exactly the loss that later arrived.
Two records define its safety answer for this family: the September 2023 hot-wallet theft, and the regulatory file that landed three months before it.
February–June 2023: the regulatory event first
In February 2023 the New York Attorney General sued CoinEx under the Martin Act for operating as an unregistered securities and commodities broker-dealer while marketing itself as an 'exchange' to New York users. The June 15 consent order resolved it: $1.7M+ recovered — $1,172,971.50 in refunds to 4,691 New York investors plus $600K+ in penalties — CoinEx banned from offering securities/commodities in New York, and the company publicly withdrew its platform from the entire United States. The AG's framing deserves quoting in substance: CoinEx had called itself an 'exchange' without registering as one — the misrepresentation, not the trading, was the violation.
Worth stating precisely because of what it is and isn't: a registration-and-representation offense, not a custody failure — but a material one for the 'is it safe' question, because a venue that exited an entire US jurisdiction over licensing is telling you which regulatory posture it chose.
September 12, 2023: the hot-wallet drain
At 21:20 UTC+8, CoinEx's risk-control system flagged anomalous withdrawals from several hot-wallet addresses. The preliminary cause it disclosed: leakage of the hot wallet private keys. Estimated loss ~$70 million — ETH, BTC, TRX, MATIC, SOL and more across wallets — which the company correctly noted was 'a small portion' of total assets, a sentence every breached venue writes and only the well-reserved ones get to mean. Elliptic's tracing pointed at North Korea's Lazarus Group; CoinEx named no culprit itself.
The response ran like a checklist: same-day emergency shutdown of hot-wallet servers and full deposit/withdrawal suspension; remaining assets moved to secure addresses; freeze requests out to exchanges and wallets industry-wide; stolen-asset detail disclosed publicly on day two; wallet system fully rebuilt September 14–21; withdrawals resumed September 21 for ten majors with new deposit addresses required. Nine days from drain to staged reopening — among the fastest full recoveries in this corpus — a nine-day arc from drain to staged reopening that only Binance's 2019 cycle beats on this family's record, executed while the venue was simultaneously absorbing the Lazarus attribution news cycle.
The cover: a fund, not a tweet
The distinction this page draws against BitMart's file: CoinEx pledged 100% compensation through a mechanism that already existed — the User Asset Security Foundation bore the loss institutionally rather than as an ad-hoc treasury decision, and per-coin compensation plans were formulated asset-by-asset with public tracking. Users were not made to chase an email address. The company also announced a separate Risk-Prevention Fund afterward — the incident converted its reserve posture from implicit to structured.
That is the cover reflex as infrastructure rather than promise: the answer was in the architecture before the question was asked.
The honest residual list
Three items stay on the record. One: the keys leaked at all — the mechanism (private-key compromise) is the same family of failure as BitMart's, and 'it was only $70M' describes the float, not the control. Two: the Lazarus attribution means the attacker was state-grade, which reframes 'could it happen again' — the defense is post-incident reconstruction, and the fund is sized to outcomes like this one rather than guaranteed against the next — though 'sized to the last incident' is still more structure than most venues offer. Three: the US exit is a standing regulatory fact — a venue that left an entire market under an AG consent order prices differently on jurisdiction risk than a venue fighting to stay.
Where CoinEx stands
In the breached-and-covered tier, CoinEx is the execution pole: among the largest thefts absorbed without user loss, the fastest documented rebuild-to-resumption, and a dedicated fund whose purpose was fulfilled rather than invented after the fact — balanced against a private-key leak that shouldn't have happened and a deliberate retreat from US regulation. The verdict shape: proven recovery machinery, mid-tier licensing posture, and a pre-funded answer to the question that ruins venues that have to improvise it. For the user's actual decision — 'do I trust the venue, and do I trust the jurisdiction it chose' — the two halves score differently, and this page keeps them separate on purpose — always.
Frequently asked questions
Was CoinEx hacked?
Yes — September 12, 2023. Leaked hot-wallet private keys let an attacker drain ~$70M across multiple chains; Elliptic's analysis pointed at Lazarus Group (CoinEx named no culprit). The hot wallets hit were 'a small portion' of total assets; user balances were covered in full by the exchange's security fund.
Did CoinEx users lose money?
No — the CoinEx User Asset Security Foundation absorbed 100% of the loss, with per-coin compensation formulated and tracked publicly. That is the structural difference this page highlights: the cover was a pre-existing funded mechanism, not a post-incident promise. Deposits/withdrawals resumed September 21 — nine days after the drain — with rebuilt wallets and new deposit addresses.
Why did CoinEx leave the US?
Regulatory, not security: the NY AG sued in February 2023 under the Martin Act for unregistered securities/commodities brokerage while holding itself out as an 'exchange.' The June 2023 consent order cost $1.7M+ (including $1.17M refunded to 4,691 NY investors), banned CoinEx from NY securities/commodities activity, and CoinEx withdrew from the US market entirely — a jurisdiction posture to weigh alongside its custody record.
How fast did CoinEx recover?
Nine days to staged resumption: same-day shutdown and asset re-securing (Sep-12), public disclosure (Sep-14), wallet system rebuilt Sep 14–21, withdrawals reopened Sep-21 for ten majors requiring new deposit addresses. Among documented exchange recoveries in this corpus that's top-tier speed — comparable to Binance's 2019 one-week cycle and far ahead of BitMart's uneven month-plus.
Is CoinEx regulated?
Lightly, by this family's standard. It holds registrations in some jurisdictions but exited the entire US under an AG consent order — the honest characterization is 'offshore mid-tier with a filed regulatory record,' not 'licensed venue.' For users in restricted jurisdictions the answer is simpler: it left rather than comply, which tells you how it prices compliance against market access.
CoinEx vs the never-breached tier?
Different evidence, not strictly worse. Kraken/Bitstamp/bitFlyer show unbreached records under supervision; CoinEx shows a breached record with the best-documented recovery mechanics in its tier — a funded security pool, nine-day rebuild, full cover. The user's real question — 'if it fails, who eats it?' — CoinEx answered with actual money on a schedule, which is more evidence than an untested clean record provides.