{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-crypto-exchange-woo-x-loses-14-million-after-staff-member-phished"},"incident":{"slug":"2025-crypto-exchange-woo-x-loses-14-million-after-staff-member-phished","title":"Crypto exchange WOO X loses $14 million after staff member phished","date":"2025-07-24","date_precision":"day","year":2025,"victim_org":"WOO X","sector":"Cryptocurrency","country":"Taiwan","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Cryptocurrency Theft","Service Disruption"],"loss_usd":14000000,"loss_kind":"direct_loss","loss_note":"Approximately $14 million in customer assets drained; WOO X said it would cover affected user balances from its own reserves.","records_affected":null,"threat_actor":null,"summary":"Crypto trading platform WOO X suspended withdrawals on 24 July 2025 after an attacker drained roughly $14 million. The company's post-mortem said the attacker compromised a team member through a phishing attack, then used that access to reach the platform's development environment and issue fraudulent withdrawal requests. WOO X halted trading, said fewer than a hundred accounts were affected, and pledged to reimburse users.","how_it_worked":"A single employee was targeted with a phishing lure that led to compromise of their machine and working credentials. From that foothold the attacker reached WOO X's development environment, which retained the ability to influence production withdrawal handling, and submitted malicious withdrawal requests that the platform processed as legitimate. The trust signal abused was the internal provenance of the requests: they came from an authenticated staff context inside the company's own tooling, so they did not look like an external attack. No exchange smart contract was exploited; the entire chain rested on one person being deceived into an action on their own device.","lessons":"Separating development environments from anything that can move production funds, and requiring multi-party approval for withdrawals above a threshold, would have contained the compromised endpoint.","confidence":"Confirmed","sources":[{"title":"July 24th - Security incident post-mortem","url":"https://woox.io/blog/july-24th-security-incident-post-mortem","publisher":"WOO X"},{"title":"Crypto Exchange WOO X Loses $14M After Team Member Falls for Phishing Attack","url":"https://cryptonews.com/news/crypto-exchange-woo-x-loses-14m-after-team-member-falls-for-phishing-attack/","publisher":"Cryptonews"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-crypto-exchange-woo-x-loses-14-million-after-staff-member-phished"}}