{"investigation":{"slug":"coinstats","entity_name":"CoinStats","trust_score":35,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"CoinStats is an Armenian-founded cryptocurrency portfolio tracking application with approximately 1.5 million users, founded in 2017 by Narek Gevorgyan. On June 22, 2024, the platform suffered a significant security breach in which 1,590 internally-hosted wallets were compromised and approximately $2.2 million in cryptocurrency was stolen, with attribution pointing to North Korea's Lazarus Group. The platform has since rebuilt its infrastructure and restored operations, but no confirmed compensation program for affected users has been publicly documented.","sections":[{"content":"CoinStats (coinstats.app) is a cryptocurrency portfolio tracker and wallet management application headquartered in Yerevan, Armenia. The platform was founded in 2017 by Narek Gevorgyan, who created it to track his own holdings. As of 2024, the platform reported over 1.5 million total users and supported tracking across 300+ exchanges, 120+ blockchains, and 20,000+ coins. The company raised $4.4 million in funding from investors including Hack VC and Imperii Partners. CoinStats offers both read-only portfolio tracking via linked external wallets and a custodial wallet service — the latter being the component compromised in the June 2024 breach.","heading":"Overview","sources":[{"url":"https://legelata.am/armenian-startup-coinstats-raised-3-2-million/","name":"legelata.am","type":"other","credibility":3},{"url":"https://tracxn.com/d/companies/coinstats/__neWRsQPS1LXU_Vdg5HVQS00dVtH9kGnfI-KWacM6xKU","name":"tracxn.com","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/cryptocurrency/coinstats-says-north-korean-hackers-breached-1-590-crypto-wallets/","name":"bleepingcomputer.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 22, 2024, at approximately 18:00 UTC, CoinStats detected abnormal activity related to transfers from its internally hosted CoinStats Wallet product. The platform was taken offline shortly thereafter. Attackers gained unauthorized access to the company's AWS infrastructure and HashiCorp Vault, which secured CoinStats Wallet 2FA keys (PINs) and API credentials for a third-party wallet-as-a-service provider. This allowed the attackers to obtain private keys for 1,590 CoinStats wallets, representing approximately 1.3% of all hosted wallets on the platform. Approximately $2.2 million in cryptocurrency was stolen in total. CEO Narek Gevorgyan stated that 'strong evidence' pointed to the attack having been carried out through an employee who was 'socially engineered into downloading malicious software' onto a work computer, compromising AWS credentials. During or immediately following the breach, attackers also pushed a fraudulent push notification to iOS users congratulating them on winning 14.2 ETH and directing them to a drainer website disguised as a CoinStats AirScout wallet reward. External wallets linked to CoinStats for read-only portfolio tracking were not affected, as these connections use read-only API access.","heading":"June 2024 Security Breach","sources":[{"url":"https://coinstats.app/blog/security-incident-report/","name":"coinstats.app","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/coinstats-hack-social-engineering-attack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/cryptocurrency/coinstats-says-north-korean-hackers-breached-1-590-crypto-wallets/","name":"bleepingcomputer.com","type":"other","credibility":3},{"url":"https://www.securityweek.com/hackers-steal-over-2-million-in-cryptocurrency-from-coinstats-wallets/","name":"securityweek.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/coinstats-suspends-app-after-security-breach-compromises-1590-wallets/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://beincrypto.com/coinstats-security-breach-crypto-wallets-hacked/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The largest single loss linked to the breach involved a wallet associated with the DeFi developer known as Blurr.eth, which held 3,657 Maker (MKR) tokens valued at approximately $8.7 million at the time of theft. The attacker liquidated the MKR tokens on-chain, causing a temporary 7% price drop in MKR — from approximately $2,462 to $2,280. This individual loss was significantly larger than the $2.2 million aggregate figure CoinStats reported, suggesting either that Blurr.eth's wallet may not have been counted in CoinStats' official tally, or that portions of the loss occurred through mechanisms outside the company's direct accounting. Some users reported fund losses from wallets not included on CoinStats' official list of 1,590 affected addresses, which raised questions about whether the total breach scope was fully disclosed.","heading":"Notable Victims and Collateral Market Impact","sources":[{"url":"https://www.bitget.com/news/detail/12560604061545","name":"bitget.com","type":"other","credibility":3},{"url":"https://www.financemagnates.com/trending/coinstats-hack-the-2-million-crypto-heist-that-left-traders-reeling/","name":"financemagnates.com","type":"other","credibility":3},{"url":"https://www.binance.com/en/square/post/2024-06-23-coinstats-app-attacked-hackers-steal-and-sell-mkr-tokens-9840683146137","name":"binance.com","type":"other","credibility":3}],"severity":"medium"},{"content":"CoinStats publicly attributed the June 2024 attack to the Lazarus Group, a North Korea-state-affiliated hacking collective, or 'a related organization with a nation-state level of sophistication and resources.' This attribution was stated in the company's July 12, 2024 security incident report and supported by evidence gathered in collaboration with law enforcement, the FBI, and external security researchers including ZachXBT and Tay (Head of Security at MetaMask). CEO Gevorgyan cited a CISA document on the Lazarus Group as part of the evidentiary basis. This attribution has not been independently confirmed by a US government agency in a public enforcement action specific to this incident. The Lazarus Group has been linked to over $3 billion in cryptocurrency theft since 2017, including the $600 million Ronin Network hack in 2022 and the alleged $305 million DMM Bitcoin hack in 2024.","heading":"Lazarus Group Attribution","sources":[{"url":"https://coinstats.app/blog/security-incident-report/","name":"coinstats.app","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/cryptocurrency/coinstats-says-north-korean-hackers-breached-1-590-crypto-wallets/","name":"bleepingcomputer.com","type":"other","credibility":3},{"url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/coinstats-breach-state-sponsored-hackers-to-blame-for-stealing-funds-from-approx-1-600-user-accounts","name":"bitdefender.com","type":"other","credibility":3},{"url":"https://www.securityweek.com/hackers-steal-over-2-million-in-cryptocurrency-from-coinstats-wallets/","name":"securityweek.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the breach, on-chain analysts observed wallets associated with the CoinStats exploiter transferring approximately 211 ETH (nearly $1 million at the time) to Tornado Cash, a sanctioned cryptocurrency mixer. This movement was tracked and reported by CoinTelegraph and on-chain security researchers. The use of Tornado Cash is consistent with Lazarus Group laundering methodologies documented in prior hacks. The transfer to a sanctioned mixer significantly reduces the probability of fund recovery.","heading":"On-Chain Fund Movement and Tornado Cash","sources":[{"url":"https://cointelegraph.com/news/coinstats-hack-1m-eth-transferred-tornado-cash","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://secret3.com/news/hackers-launder-1m-in-ether-through-tornado-cash-after-coinstats-exploit/","name":"secret3.com","type":"other","credibility":3}],"severity":"medium"},{"content":"CoinStats shut down the application immediately upon detecting the breach on June 22, 2024. By June 24, limited functionality was restored. CoinStats subsequently undertook a complete rebuild of its production environment, migrating to new AWS accounts and ensuring no components of the old infrastructure were reused. The company implemented mandatory password resets and enforced 2FA requirements across the platform. Full functionality was restored by July 3, 2024. The July 12, 2024 security incident report detailed these steps and was co-authored with security experts. CoinStats also reported the incident to local law enforcement and the FBI.","heading":"Platform Response and Infrastructure Rebuild","sources":[{"url":"https://coinstats.app/blog/security-incident-report/","name":"coinstats.app","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/cryptocurrency/coinstats-says-north-korean-hackers-breached-1-590-crypto-wallets/","name":"bleepingcomputer.com","type":"other","credibility":3}],"severity":"medium"},{"content":"CoinStats created a form requiring affected users to submit their information by August 15, 2024 to be eligible for 'any future support from the CoinStats team.' CEO Gevorgyan stated that 'CoinStats will definitely support the victims of the hack' and pledged a detailed plan of action post-mortem. However, no public record of an executed compensation program or confirmed reimbursements to victims has been identified in available reporting as of mid-2026. The company's official security incident report from July 2024 does not commit to specific reimbursement figures or timelines. Users were warned by CoinStats that scammers were promoting fake refund schemes in the aftermath of the breach.","heading":"Victim Compensation","sources":[{"url":"https://coinstats.app/blog/security-incident-report/","name":"coinstats.app","type":"other","credibility":3},{"url":"https://www.financemagnates.com/trending/coinstats-hack-the-2-million-crypto-heist-that-left-traders-reeling/","name":"financemagnates.com","type":"other","credibility":3},{"url":"http://help.coinstats.app/en/articles/6453281-protect-yourself-from-potential-scams","name":"help.coinstats.app","type":"other","credibility":3}],"severity":"medium"},{"content":"Separately from the June 2024 breach, CoinStats has documented an ongoing pattern of scammers impersonating the platform. Fraudsters create CoinStats accounts and contact users via phone, text, email, or social media, falsely claiming the user has cryptocurrency funds waiting for them in a CoinStats account. CoinStats has issued warnings about these schemes through its official help center. This impersonation activity is distinct from the June 2024 state-sponsored hack and does not reflect on the company's operations directly, but represents an elevated risk surface for users of the platform.","heading":"Impersonation Scams Targeting CoinStats Users","sources":[{"url":"http://help.coinstats.app/en/articles/6453281-protect-yourself-from-potential-scams","name":"help.coinstats.app","type":"other","credibility":3}],"severity":"medium"},{"content":"As of 2026, CoinStats continues to operate as a cryptocurrency portfolio tracker with active weekly app updates. The platform reports over 1 million active users and supports 120+ blockchains, 300+ wallets and exchanges, and 1,000+ DeFi protocols. No new major security incidents have been reported since the June 2024 breach. The platform added an AI Assistant feature as of April 2026. No regulatory actions from the SEC, CFTC, DOJ, or equivalent agencies against CoinStats or its executives have been identified in public records.","heading":"Current Operational Status","sources":[{"url":"https://cryptoslate.com/products/coinstats/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://play.google.com/store/apps/details?id=com.coinstats.crypto.portfolio","name":"play.google.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2017","event":"CoinStats founded in Yerevan, Armenia by Narek Gevorgyan as a personal crypto portfolio tracking tool.","source":"","date_original":"2017-01-01"},{"date":"2021","event":"CoinStats reports 1.2 million monthly active users and sixfold revenue growth; raises $3.2 million in early funding.","source":"","date_original":"2021-01-01"},{"date":"2024-06-22","event":"Security breach detected at approximately 18:00 UTC. Attackers gain access to AWS infrastructure and HashiCorp Vault via a socially engineered employee. 1,590 internal wallets compromised. Malicious push notification sent to iOS users directing them to a drainer site. Platform taken offline.","source":""},{"date":"2024-06-22","event":"Blurr.eth's wallet drained of 3,657 MKR tokens (~$8.7M). Hacker liquidates MKR on-chain, causing a 7% MKR price drop.","source":""},{"date":"2024-06-22","event":"CoinStats publicly discloses breach via X (Twitter) and urges users with internally-created wallets to transfer funds immediately.","source":""},{"date":"2024-06-24","event":"CoinStats partially restores platform operations with enhanced security measures.","source":""},{"date":"2024-06-25","event":"On-chain analysts observe approximately 211 ETH (~$1M) transferred from attacker wallets to Tornado Cash mixer.","source":""},{"date":"2024-07-03","event":"CoinStats announces full platform restoration; all functionalities operational.","source":""},{"date":"2024-07-12","event":"CoinStats publishes formal security incident report attributing attack to Lazarus Group or a related nation-state actor. Reports $2.2M in total losses across 1,590 wallets. Announces victim registration form with August 15 deadline for compensation eligibility consideration.","source":""},{"date":"2024-08-15","event":"Deadline for affected users to submit information to CoinStats for potential future compensation consideration.","source":""}],"sources_used":[{"url":"https://legelata.am/armenian-startup-coinstats-raised-3-2-million/","name":"legelata.am","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://tracxn.com/d/companies/coinstats/__neWRsQPS1LXU_Vdg5HVQS00dVtH9kGnfI-KWacM6xKU","name":"tracxn.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.bleepingcomputer.com/news/cryptocurrency/coinstats-says-north-korean-hackers-breached-1-590-crypto-wallets/","name":"bleepingcomputer.com","type":"other","archive_url":"http://web.archive.org/web/20260301105916/https://www.bleepingcomputer.com/news/cryptocurrency/coinstats-says-north-korean-hackers-breached-1-590-crypto-wallets/","credibility":3,"archive_timestamp":"2026-03-01T10:59:16+00:00"},{"url":"https://coinstats.app/blog/security-incident-report/","name":"coinstats.app","type":"other","archive_url":"https://web.archive.org/web/20260829234158/https://coinstats.app/blog/security-incident-report/","credibility":3,"archive_timestamp":"2026-08-29T23:41:58+00:00"},{"url":"https://cointelegraph.com/news/coinstats-hack-social-engineering-attack","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260208192257/https://cointelegraph.com/news/coinstats-hack-social-engineering-attack","credibility":3,"archive_timestamp":"2026-02-08T19:22:57+00:00"},{"url":"https://www.securityweek.com/hackers-steal-over-2-million-in-cryptocurrency-from-coinstats-wallets/","name":"securityweek.com","type":"other","archive_url":"http://web.archive.org/web/20260830010401/https://www.securityweek.com/hackers-steal-over-2-million-in-cryptocurrency-from-coinstats-wallets/","credibility":3,"archive_timestamp":"2026-08-30T01:04:01+00:00"},{"url":"https://cryptoslate.com/coinstats-suspends-app-after-security-breach-compromises-1590-wallets/","name":"cryptoslate.com","type":"other","archive_url":"https://web.archive.org/web/20260829235845/https://cryptoslate.com/coinstats-suspends-app-after-security-breach-compromises-1590-wallets/","credibility":3,"archive_timestamp":"2026-08-29T23:58:45+00:00"},{"url":"https://beincrypto.com/coinstats-security-breach-crypto-wallets-hacked/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.bitget.com/news/detail/12560604061545","name":"bitget.com","type":"other","archive_url":"https://web.archive.org/web/20260829144217/https://www.bitget.com/news/detail/12560604061545","credibility":3,"archive_timestamp":"2026-08-29T14:42:17+00:00"},{"url":"https://www.financemagnates.com/trending/coinstats-hack-the-2-million-crypto-heist-that-left-traders-reeling/","name":"financemagnates.com","type":"other","archive_url":"https://web.archive.org/web/20260829151651/https://www.financemagnates.com/trending/coinstats-hack-the-2-million-crypto-heist-that-left-traders-reeling/","credibility":3,"archive_timestamp":"2026-08-29T15:16:51+00:00"},{"url":"https://www.binance.com/en/square/post/2024-06-23-coinstats-app-attacked-hackers-steal-and-sell-mkr-tokens-9840683146137","name":"binance.com","type":"other","archive_url":"https://web.archive.org/web/20260830044534/https://www.binance.com/en/square/post/2024-06-23-coinstats-app-attacked-hackers-steal-and-sell-mkr-tokens-9840683146137","credibility":3,"archive_timestamp":"2026-08-30T04:45:34+00:00"},{"url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/coinstats-breach-state-sponsored-hackers-to-blame-for-stealing-funds-from-approx-1-600-user-accounts","name":"bitdefender.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/news/coinstats-hack-1m-eth-transferred-tornado-cash","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260214140913/https://cointelegraph.com/news/coinstats-hack-1m-eth-transferred-tornado-cash","credibility":3,"archive_timestamp":"2026-02-14T14:09:13+00:00"},{"url":"https://secret3.com/news/hackers-launder-1m-in-ether-through-tornado-cash-after-coinstats-exploit/","name":"secret3.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"http://help.coinstats.app/en/articles/6453281-protect-yourself-from-potential-scams","name":"help.coinstats.app","type":"other","archive_url":"http://web.archive.org/web/20251014064012/https://help.coinstats.app/en/articles/6453281-protect-yourself-from-potential-scams","credibility":3,"archive_timestamp":"2025-10-14T06:40:12+00:00"},{"url":"https://cryptoslate.com/products/coinstats/","name":"cryptoslate.com","type":"other","archive_url":"https://web.archive.org/web/20260829132032/https://cryptoslate.com/products/coinstats/","credibility":3,"archive_timestamp":"2026-08-29T13:20:32+00:00"},{"url":"https://play.google.com/store/apps/details?id=com.coinstats.crypto.portfolio","name":"play.google.com","type":"other","archive_url":"http://web.archive.org/web/20260805105330/https://play.google.com/store/apps/details?id=com.coinstats.crypto.portfolio","credibility":3,"archive_timestamp":"2026-08-05T10:53:30+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:31.32903+00:00","updated_at":"2026-08-30T05:14:07.472127+00:00"}}