HostDeFi › Is Phemex safe
Is Phemex safe? The exchange that lost keys on sixteen chains in one morning
Phemex's file is the widest blast radius in this family's incident set: on January 23, 2025, an attacker drained its hot wallets across roughly sixteen blockchains in a near-simultaneous wave — ~$73–85 million by the time the small balances stopped moving. The simultaneity is the fingerprint: one internal key store, compromised once, fanning out across every chain it touched. What the file also shows is a venue that published proof of reserves the same day, staged withdrawals back inside nine days, and absorbed the loss against operational reserves.
What Phemex is
Phemex is a Singapore-headquartered centralized exchange founded 2019 — derivatives-first, ~5 million users, operating under registrations in the US (state-level), Canada, Turkey, and Lithuania by its own account. Custody is the standard custodial model with PoR published on demand — the venue's answer to the trust question, which January 2025 put to work immediately — PoR became an incident-response tool instead of a marketing page.
Its place in this family: the most recent large hot-wallet breach with a fully documented recovery timeline — and the incident whose on-chain signature told analysts more about the failure than the company's disclosure did — which is why this page cites the forensic record ahead of the press release, itself a data point about the venue's disclosure instincts.
January 23, 2025: the simultaneous multi-chain drain
At 11:30 UTC Phemex's operations team detected unusual outflows. Over the following hours — and in trailing small-balance drains over following weeks — the attacker extracted funds from hot wallets across roughly sixteen chains: Ethereum, Bitcoin, Solana, XRP, BNB Chain, Polygon, Avalanche, Arbitrum, Optimism, Base and more. Early tallies (Cyvers ~$29M) escalated through PeckShield (~$69M) to $73–85M as wallet-cluster tracking by SlowMist and Merkle Science caught the long tail.
The forensic inference that matters: per SlowMist and Halborn's post-mortems, the proximate cause was compromise of Phemex's hot-wallet private keys — and the simultaneous drain across sixteen independent signing pipelines makes a single operator-internal key-store compromise the only plausible read. One vault, many doors; the attacker found the vault.
The company's own disclosure stayed thinner — 'unusual activity,' affected devices 'identified and isolated,' matter reported to security firms and law enforcement — without a published root cause or public attribution, and without confirming the co-located-store inference the chain data made obvious. No user balances were affected per Phemex; cold wallets were untouched.
The response: PoR first, then the staged climb back
Same-day, Phemex published Proof of Reserves — the move worth noting because it converts 'trust us' into 'check our wallets' at the moment users most need it. Then the staged resumption, documented to the hour: ETH/USDT/USDC withdrawals back January 24 under manual review; BTC back January 25; Solana assets January 25; Arbitrum, Optimism, BSC, Polygon, Base January 26; full service by early February — about nine days end-to-end, with new deposit addresses and a rebuilt hot-wallet architecture monitored by a cybersecurity partner.
CEO Federico Variola's commitments ran in the family's standard shape — snapshot of user balances taken at noon UTC for a 'reward for your support and loyalty,' a compensation plan promised, all delivered through the CEO's own X account as the incident's unofficial newswire. Worth noting what got delivered when: withdrawals returned on the documented schedule with rebuilt hot-wallet architecture and named security-partner monitoring; the loyalty-reward and full compensation-plan detail trailed the announcement rather than leading it — a staging order worth remembering whenever 'compensation plan announced soon' is the operative phrase. The loss was absorbed against operational reserves; trading never halted.
What the incident actually prices
Two columns, both real. The damning column: a single internal key store apparently held signing material for sixteen chains — a concentration-of-failure that turned one compromise into a venue-wide drain, and a root-cause disclosure that never arrived publicly means users can't independently verify the architecture was redesigned rather than restarted. The exculpatory column: reserves demonstrably absorbed the loss, withdrawals returned in nine days, PoR went up while the incident was still fresh, and no user balance lost a cent in the largest multi-chain hot-wallet theft on this family's record.
The calibration vs. its cluster-mates: wider surface than BitMart, slower precision than CoinEx's rebuild, same reserves-cover outcome as Deribit at ~3x the take — the honest read is that Phemex passed the recovery test it arguably shouldn't have needed to take.
Where Phemex stands
In the breached-and-covered tier Phemex is the breadth-of-failure entry: the most chains ever drained in one compromise in this corpus, answered with competent rather than exemplary recovery — PoR same-day, nine-day staged restore, reserves absorbing the full ~$73–85M. The unclosed item is disclosure: no published root cause or attribution means 'fixed' is asserted rather than demonstrated. For users, the posture that prices honestly: a venue that proved it can pay for its mistakes, with a key-management question it hasn't publicly answered — and for a venue whose demonstrated failure mode was precisely a key-store, that unanswered question is the residual risk itself rather than a footnote. The treasury proved it could pay; the architecture has yet to prove publicly why it won't need to again — the distinction that separates this file from the clean ones.
Frequently asked questions
Was Phemex hacked?
Yes — January 23, 2025. Hot wallets were drained across ~16 blockchains in a near-simultaneous wave: ~$29M initially tracked, rising to ~$73–85M as SlowMist and Merkle Science mapped the full cluster. SlowMist/Halborn's read: compromised hot-wallet private keys, almost certainly from a single internal store — sixteen separate pipelines failing at once otherwise makes no sense.
Did Phemex users lose money?
No user balances were affected, per Phemex — the loss was absorbed against operational reserves, and trading never stopped. Withdrawals staged back over ~nine days (ETH/USDT/USDC Jan-24 through L2s Jan-26, full service by early February) on a rebuilt hot-wallet architecture. A 'compensation plan' plus a user-balance snapshot reward were announced by the CEO alongside the resumption.
Why did so many chains get hit at once?
The forensic consensus: key material for multiple chains was co-located in one internal store, so one compromise fanned out across every chain that store could sign for. It's the cleanest demonstration in this corpus of why hot-wallet architecture matters more than hot-wallet size — the blast radius isn't the float, it's whatever shares a key store.
What did Phemex do right?
Three things worth crediting: proof of reserves published the same day (checkable wallets instead of reassurance), a fully documented staged resumption inside nine days on rebuilt infrastructure, and reserves absorbing the full loss without touching user balances. The recovery grade is competent-plus; the prevention and disclosure grades are where the file stays open.
Has Phemex said who did it or how exactly?
No public root-cause report or attribution as of this page — the company cited 'unusual activity,' isolated affected devices, and referred the matter to security firms and law enforcement. On-chain analysts' inference (co-located key store, state-grade actor suspected by some trackers) is the most detailed account available — which leaves 'is it fixed' asserted rather than demonstrated, the same disclosure gap the Atomic Wallet file prices — with the crucial difference that Phemex's treasury demonstrably answered while Atomic's did not.
Phemex vs CoinEx — which recovery was better?
CoinEx's, on precision: dedicated pre-existing security fund, nine-day rebuild with a public incident timeline and named mechanism (private-key leak) disclosed promptly. Phemex matched the nine-day restore and the full cover but kept the mechanism undiscussed and the compensation terms vaguer. Both prove their treasuries were real; CoinEx additionally proved its disclosure was — and in this family disclosure is what lets a user verify the fix, not just believe the money.