Home/Blog/Crypto Payment Processor Hacks: 2024-2025
Security6 min read·Mar 12, 2026·Updated Aug 30, 2026

Crypto Payment Processor Hacks: 2024-2025.

Between 2023 and 2025, custodial crypto payment processors and exchanges lost over $1.8 billion to hackers. Every major incident shared the same root cause: the processor held customer and merchant funds in centralized wallets. Here's the complete timeline.

Custodial crypto payment processor hacks: the ledger

//Custodial processor and exchange incidents, 2023-2025 · newest first · updated August 2026compiled
DateCompanyTypeAmountWhat was drained and how
February 2025BybitExchange$1.46 billionHot wallet infrastructure compromised by the Lazarus Group
May 2024DMM BitcoinExchange$308 million (4,502.9 BTC)Hot wallet system compromised despite multi-signature controls
January 2024CoinsPaidPayment processor$7.5 millionSecond hit on the same pooled custodial wallets, six months after the first
July 2023CoinsPaidPayment processor$37 millionLazarus Group, social engineering on an employee, pooled hot wallets drained
July 2023AlphapoPayment processor$60 millionLazarus Group, custodial hot wallets across multiple chains

Total across the ledger: about $1.8 billion in two years, all of it taken from wallets the processor or exchange controlled on behalf of its customers. This ledger is maintained. When a custodial processor or exchange incident is confirmed, it is added here with the month and the figure. Last updated August 30, 2026.

Bybit: $1.46 Billion (February 2025)

The largest crypto hack in history. North Korean Lazarus Group hackers compromised Bybit's hot wallet infrastructure, draining $1.46 billion in a single attack. The hack exploited the fundamental weakness of custodial architecture, all customer funds stored in centralized wallets controlled by the platform.

DMM Bitcoin: $308 Million (May 2024)

Japanese exchange DMM Bitcoin lost 4,502.9 BTC ($308 million) when attackers compromised their hot wallet system. Despite security measures including multi-signature wallets, the custodial model meant funds were concentrated and targetable.

CoinsPaid: $44.5 Million (2023-2024)

CoinsPaid, one of the largest crypto payment processors for iGaming, was hacked twice. In July 2023, Lazarus Group stole $37 million through a social engineering attack on an employee. Six months later, in January 2024, hackers returned for another $7.5 million. Multiple gambling platforms using CoinsPaid lost access to deposited funds.

Alphapo: $60 Million (July 2023)

Enterprise crypto payment processor Alphapo lost $60 million in the same month as CoinsPaid, also attributed to Lazarus Group. Hot wallets across multiple blockchains were drained. Several major gambling platforms that processed through Alphapo were directly affected.

The Pattern

Every hack follows the same pattern: a custodial processor pools merchant and customer funds in centralized wallets. Hackers target those wallets, through social engineering, infrastructure compromise, or insider access. When they succeed, everyone who stored funds on the platform loses.

What custodial hacks have in common:

  • Funds were pooled in processor-controlled wallets
  • Hot wallets held significant balances for operational convenience
  • A single compromise drained multiple merchants simultaneously
  • Merchants had no way to protect their own funds

The Non-Custodial Alternative

Non-custodial payment processors eliminate this attack vector entirely. When funds flow directly from customer to merchant wallet on-chain, there is no pool of funds to steal. Even if the processor's infrastructure is fully compromised, merchant funds are safe, because they're in the merchant's own wallet.

PYMSTR is non-custodial. We never hold merchant funds. Payments settle directly to your wallet in 2-15 seconds across 5 chains. The architecture that led to $1.8 billion in losses simply doesn't apply.

//FAQ2 questions
CoinsPaid was hacked twice: $37 million in July 2023 (attributed to the Lazarus Group, via social engineering on an employee) and another $7.5 million in January 2024. Alphapo lost $60 million in July 2023, also attributed to the Lazarus Group. Both are custodial processors that pooled merchant funds in hot wallets. The exchanges Bybit ($1.46 billion, February 2025) and DMM Bitcoin ($308 million, May 2024) share the same root cause: customer funds concentrated in wallets the platform controlled.
A non-custodial gateway has no pooled merchant balance to drain. Money moves from the customer's wallet to the merchant's wallet on the blockchain and the gateway never holds it in between (the industry calls this non-custodial). That is how PYMSTR is built: we never hold your money, so a compromise of the gateway's own infrastructure does not expose merchant funds the way every incident in the ledger above did.
→ Ready to ship?

Add the stablecoin rail to your checkout.

Non-custodial. 1% flat. Stable-in, stable-out. Live in minutes, not months.

Launch app →