The provider is inside the perimeter
Mixin’s account places the failure at its cloud database provider rather than in its own protocol code. That distinction matters less than it sounds: from a user’s position, assets were lost, and the dependency that failed was one they had no visibility into.
The question this raises for any service
Architecture diagrams show protocols and contracts. They rarely show the managed database, the CI runner, the DNS provider, the package registry or the CDN — all of which can be the shortest path to the assets. The Ledger Connect Kit compromise and the BadgerDAO front-end injection are the same lesson from different angles.
There is no user-side check that resolves this. The honest mitigation is exposure limits: not holding more on any single service than you could absorb losing.
Timeline
Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.
- The database of Mixin's cloud service provider is attacked; assets are lost from the mainnet. Mixin Network
- Mixin publicly discloses the incident, reports approximately $200m affected, and suspends deposits and withdrawals. Mixin Network
What to check
Mixin Network's own announcements are the authoritative record of service status and any restoration of withdrawals.
Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.
Sources
- Mixin Network, Official incident announcements (25 Sep 2023)
Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.
Last verified by Conisec Staff.