(2020)

Cashaa

1000 BTC

Monetary Impact

$3,100,000

Month

July

Year

2020

Type

Exchange

Network

Bitcoin

Platform Status

Operational

Cause

Compromised Employee

Incident Review

On July 10, 2020, Cashaa, a UK-based crypto-friendly bank operating Bitcoin OTC services in India, was rocked by a swift and audacious theft of 337 BTC, valued at approximately $3.1 million, from its over-the-counter desk in East Delhi. The breach, detailed in a Cointelegraph report and Cashaa’s Telegram announcement, occurred when an OTC transaction manager’s personal computer, used after a company-issued device malfunctioned on July 8, was compromised by malware. This allowed hackers to seize control via active browser sessions, draining a Blockchain.com hot wallet—lacking multi-signature protection—in minutes, with funds funneled to the address 14RYUUaMW1shoxCav4znEh64xnTtL3a2Ek, per CertiK’s analysis. Cashaa, serving 100,000 monthly users per SimilarWeb, halted crypto transactions for 24 hours, filed a report with Delhi’s Cyber Crime Bureau, and shared the hacker’s wallet address, prompting exchanges like Binance and WazirX to blacklist it, as noted on Twitter by @CoinDCX.

No user funds were affected, but whispers of an inside job by a high-ranking executive swirled on Reddit, fueled by the single-signature wallet’s vulnerability and the employee’s suspension, though CEO Kumar Gaurav denied clear evidence, per Cointelegraph. The hack, one of 12 major breaches in 2020 totaling $3.78 billion per CipherTrace, saw no funds recovered in India’s unregulated crypto landscape. Social media, including posts from @UnitedCryptoEx, speculated hackers used coin-mixing to obscure trails. The incident, exposing lax internal controls, ignited calls for hardware security modules, mandatory multi-signature wallets, and employee cybersecurity training to bolster the crypto sector’s fragile credibility.

Have a hack to report? Contact us. or Share this report

UEEx makes trading easier

Join the official Telegram Channel

©2025, UEEx All Rights Reserved FINTRAC Registered