CoinDCX Engineer Arrested Following July’s $43.4M Exploit: Report
A significant cryptocurrency theft impacting CoinDCX, a prominent Indian exchange, has led to the arrest of a software engineer. Bengaluru police apprehended 30-year-old Rahul Agarwal, alleging his involvement in the unauthorized transfer of 3.79 billion rupees (approximately $43.4 million) in crypto assets on July 19th. The theft involved the use of Agarwal’s company-issued laptop credentials to access CoinDCX’s internal systems and facilitate the transfer of funds to six distinct wallets.
While Agarwal denies direct participation in the heist, his account reveals intriguing details. He admitted to undertaking freelance work for unidentified overseas clients, a fact that has become a key focus of the investigation. Furthermore, a 1.5 million rupee deposit into his account and a WhatsApp call originating from a German number shortly preceded the theft, raising suspicion about potential external collaborators.
Authorities are exploring several avenues of investigation. The possibility of malware compromise during Agarwal’s freelance work is being examined, alongside the potential for credential misuse. The scale and coordination of the breach suggest a sophisticated operation, leading investigators to explore connections to international hacking groups. The involvement of North Korean hackers is a specific line of inquiry, mirroring patterns observed in previous crypto-related heists. This hypothesis is further supported by a separate report detailing North Korean hacking groups targeting top cryptocurrency firms using malware concealed within job applications.
CoinDCX’s parent company, Neblio Technologies, conducted an internal investigation, reassuring customers that their assets remain untouched. The exchange has publicly stated it will absorb the losses from its own treasury. However, the incident underscores serious concerns regarding internal security vulnerabilities within the cryptocurrency industry and highlights the potential for significant financial losses due to sophisticated cyberattacks. The stolen funds remain unrecovered, and the investigation is ongoing. The case serves as a stark reminder of the risks associated with both internal security breaches and the growing threat of state-sponsored cybercrime in the cryptocurrency sector.

