Mixin Network: The $200M Cloud Heist
The cloud provider got hacked. $200M walked out the door.

Most crypto hacks target smart contracts or exchange infrastructure directly. Mixin Network got hit through something much more basic and much harder to audit from the outside: its cloud service provider.
In the early morning of September 23, 2023, Hong Kong time, attackers compromised the database of Mixin's cloud provider and used that access to drain approximately $200 million in crypto assets from the network, later itemized as roughly 59,854 ETH, 891 BTC, and about $23.57 million in USDT, taken across multiple blockchains in a single coordinated attack.
Mixin Network marketed itself as a "free, lightning-fast, and decentralized network for transferring digital assets." The irony of storing the keys to that supposedly decentralized network on a centralized, third-party cloud service was not lost on the crypto community once the details came out. Founder Feng Xiaodong announced the breach publicly on September 25, immediately suspended deposits and withdrawals, and brought in Google's incident response team and blockchain security firm SlowMist to investigate. Mixin offered the attacker a $20 million bug bounty for the return of the stolen funds. Nobody ever took them up on it.
The attack highlighted a vulnerability most projects don't think about until it's too late. You can audit your smart contracts, run multi-signature wallets, and implement every on-chain security measure available, but if your actual keys ultimately live on AWS, Google Cloud, or any centralized infrastructure provider, your real security ceiling is that provider's weakest link, not your own code.
Mixin's compensation plan split the loss into tiers. Users would be repaid up to 50% of their losses in stablecoins directly, with the remainder issued as tokenized claims called Mixin Debt Tokens, split across three categories: MDTu, MDTb, and MDTe, representing different classes of affected assets, each intended to be bought back over time using company earnings. As of an October 2025 update, Mixin said it intended to fully repay the roughly $23 million represented by MDTu by September 23, 2026, exactly three years after the breach, but had not set any repayment schedule at all for the MDTb or MDTe tranches.
The stolen funds sat almost entirely untouched for more than two years, a common pattern for large hacks where attackers wait out the initial wave of on-chain surveillance before attempting to cash out. That changed on February 12, 2026, when a wallet tagged by Arkham Intelligence and tracked by analytics platform Lookonchain finally stirred, moving roughly 2,000-2,200 ETH, worth around $3.85 million, into a fresh address that immediately forwarded the funds to Tornado Cash in about 20 separate transactions. Shortly after, three newly created wallets received a combined amount from the mixer and sold the tokens at roughly $1,933 per ETH. It was the first meaningful movement from the hacker's wallets since the original breach, and it left open the question of how much of the remaining haul might follow the same path.
Mixin did not shut down after the exploit. The project says it still manages more than $1 billion in assets under management and serves over 1 million customers across its wallet, custody, and trading infrastructure products, continuing to operate even as its native XIN token took a roughly 25% hit in the immediate aftermath of the hack and its debt to affected users remains only partially resolved.
The Aftermath
No suspects identified as of April 2026. Mixin offered users 50% compensation in stablecoins with the remainder as tokenized bond claims. The $20M bounty went unclaimed. In February 2026, a wallet tied to the hack woke up after two years of dormancy and moved $3.8 million in ETH to Tornado Cash. The attacker still has access to stolen funds. The stolen haul included 59,854 ETH, 891 BTC, and roughly $23.57 million in USDT.
COMMENTS