Security incident · 2020-07-11
Cashaa
According to the public DefiLlama incident dataset, Cashaa (Bitcoin) suffered a security incident on 2020-07-11, with about $3.1M reported lost.
| Date | 2020-07-11 |
|---|---|
| Reported loss | $3.1M |
| Chain | Bitcoin |
| Target type | CEX |
| Technique class | Frontend & Infrastructure |
| Technique | Key Leaked via Infrastructure |
| Bridge incident | No |
| Within 2020 | #20 by loss that year, 0.1% of all reported losses that year |
How this kind of attack works
The website, domain or hosting was hijacked, and users signed transactions that sent funds to the attacker from a page that looked normal.
Would a pre-payment check have helped
When a frontend or domain is hijacked the payee address is freshly generated and on no list, but the hijacked host is often already in public phishing feeds, so endpoint screening catches part of this class.
Other incidents with the same technique
- Mixin Network2023-09-23 · $200.0M
- Badger DAO2021-12-02 · $120.0M
- Atomic Wallet2023-06-03 · $100.0M
- NiceHash2017-12-08 · $64.0M
- SwissBorg2025-09-09 · $41.5M
- IRA Financial / Gemini2022-02-12 · $36.0M

