Skip to content
Incident record

Mixin Network Database Compromise, September 2023: What Happened & What to Check

Mixin reported roughly $200m lost after the database of its cloud service provider was attacked, and suspended deposits and withdrawals.

Contained Discovered Disclosed
Share X in @
Schematic of the Mixin Network incident showing the infrastructure compromise stage as the failure point.
Schematic of the Mixin Network incident showing the infrastructure compromise stage as the failure point.

At a glance

AFFECTED ENTITY
Mixin Network
CHAIN(S)
Bitcoin, Ethereum
REPORTED LOSS
approx. US$200 million(Mixin Network, 25 Sep 2023)
OFFICIAL RESPONSE
mixin.one

The provider is inside the perimeter

Mixin’s account places the failure at its cloud database provider rather than in its own protocol code. That distinction matters less than it sounds: from a user’s position, assets were lost, and the dependency that failed was one they had no visibility into.

The question this raises for any service

Architecture diagrams show protocols and contracts. They rarely show the managed database, the CI runner, the DNS provider, the package registry or the CDN — all of which can be the shortest path to the assets. The Ledger Connect Kit compromise and the BadgerDAO front-end injection are the same lesson from different angles.

There is no user-side check that resolves this. The honest mitigation is exposure limits: not holding more on any single service than you could absorb losing.

Timeline

Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.

  1. The database of Mixin's cloud service provider is attacked; assets are lost from the mainnet. Mixin Network
  2. Mixin publicly discloses the incident, reports approximately $200m affected, and suspends deposits and withdrawals. Mixin Network

What to check

Mixin Network's own announcements are the authoritative record of service status and any restoration of withdrawals.

Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.

Sources

  1. Mixin Network, Official incident announcements (25 Sep 2023)

Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.

Last verified by Conisec Staff.