What happened
Crypto trading platform WOO X suspended withdrawals on 24 July 2025 after an attacker drained roughly $14 million. The company's post-mortem said the attacker compromised a team member through a phishing attack, then used that access to reach the platform's development environment and issue fraudulent withdrawal requests. WOO X halted trading, said fewer than a hundred accounts were affected, and pledged to reimburse users.
How the deception worked
A single employee was targeted with a phishing lure that led to compromise of their machine and working credentials. From that foothold the attacker reached WOO X's development environment, which retained the ability to influence production withdrawal handling, and submitted malicious withdrawal requests that the platform processed as legitimate. The trust signal abused was the internal provenance of the requests: they came from an authenticated staff context inside the company's own tooling, so they did not look like an external attack. No exchange smart contract was exploited; the entire chain rested on one person being deceived into an action on their own device.
The control that would have caught it· our reading, not a claim from the sources
Separating development environments from anything that can move production funds, and requiring multi-party approval for withdrawals above a threshold, would have contained the compromised endpoint.
Sources (2)
- July 24th - Security incident post-mortemWOO X·woox.ioOpen ↗
- Crypto Exchange WOO X Loses $14M After Team Member Falls for Phishing AttackCryptonews·cryptonews.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.