Overview
- CoinDCX disclosed that a security incident at analytics provider Mixpanel exposed data tied to some users of the Indian crypto exchange.
- Mixpanel was breached on November 8 and informed CoinDCX on November 25, after which the exchange notified customers on November 28–29.
- The company said the event was not specific to CoinDCX, Mixpanel cannot access its infrastructure or wallets, and no passwords, OTPs, seed phrases or critical KYC were exposed.
- CoinDCX said it is working with Mixpanel to confirm containment and has launched a review of vendor security practices and data minimisation.
- The number of affected customers was not disclosed from a base of more than 20 million registered users, and the exchange urged vigilance against phishing attempts.