{"investigation":{"slug":"fixedfloat","entity_name":"FixedFloat","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"FixedFloat (ff.io) is a non-custodial, no-KYC cryptocurrency swap exchange launched in 2018 that suffered two confirmed security breaches in 2024 totaling approximately $28.9 million in stolen assets. Both attacks were attributed to the same threat actor exploiting vulnerabilities in FixedFloat's third-party hosting provider, Time4VPS, and stolen funds were routed through the eXch mixer — a service subsequently shut down by German authorities for laundering proceeds from major crypto thefts. The platform resumed operations after a two-month suspension but has faced ongoing scrutiny for its anonymity-first model, opaque team structure, and inadequate incident disclosure.","sections":[{"content":"FixedFloat is a non-custodial cryptocurrency swap exchange operating at ff.io. The platform launched in 2018 and markets itself as a privacy-preserving service allowing users to swap over 1,000 cryptocurrencies without mandatory registration or Know Your Customer (KYC) verification. The team behind FixedFloat has not publicly disclosed the identities of its founders or key personnel. The platform claims to have processed millions of transactions across 190+ countries. Despite its no-KYC positioning, FixedFloat does implement limited AML screening: orders may be suspended and funds frozen if transactions are flagged as suspicious, and the platform reserves the right to share user IP addresses and data with authorities on request. The platform blocks access from certain jurisdictions, including the United States, which its terms of service characterize as falling outside the platform's risk appetite. The operational entity and country of incorporation have not been publicly disclosed.","heading":"Background","sources":[{"url":"https://u.today/fixedfloat-introduces-multi-blockchain-noncustodial-exchange-with-no-kyc-review","name":"","type":"other","credibility":3},{"url":"https://ff.io/faq","name":"","type":"other","credibility":3},{"url":"https://kycnot.me/service/fixedfloat","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"FixedFloat was breached twice in 2024 by what the company alleges was the same threat actor.\n\nFirst breach (February 16, 2024): Attackers drained 409.304 BTC (approximately $21 million at the time) and 1,728.48 ETH (approximately $4.85 million), totaling roughly $26.1 million. The theft occurred across nine transactions — five on Bitcoin and four on Ethereum — and was completed in under 45 minutes. FixedFloat initially characterized the incident as 'minor technical problems' before eventually confirming an 'external attack caused by vulnerabilities in our security structure.' The platform entered maintenance mode for approximately two months. The exact attack vector was not publicly disclosed at the time of the incident.\n\nSecond breach (April 1, 2024): Approximately $2.8 million in digital assets was stolen from FixedFloat's Ethereum hot wallet, including ETH, USDT, WETH, DAI, and USDC. Web3 security firm Cyvers identified suspicious transactions and alerted the community via social media on April 2, 2024. Tether proactively froze attacker-linked USDT addresses in response. FixedFloat again entered maintenance mode and issued no immediate public statement.\n\nOfficial root cause: In a subsequent official statement, FixedFloat attributed both breaches to vulnerabilities in Time4VPS, a Lithuanian hosting provider (operated by UAB 'Interneto vizija'). For the February breach, the attacker obtained the IP address of a FixedFloat technical server hosted at Time4VPS. By March 31, the attacker achieved unauthorized access across all of FixedFloat's Time4VPS-hosted servers. On April 1, the attacker changed FixedFloat's hosting account email to an invalid address, locking the company out of recovery systems. FixedFloat stated that Time4VPS technical staff were off duty when the breach was first reported, that no action was taken for several days, and that more than three months after the incident FixedFloat had still not received an incident report from the provider. FixedFloat alleged the breach may have involved an insider at Time4VPS.","heading":"The Hacks","sources":[{"url":"https://decrypt.co/218077/fixedfloat-hack-26-million-bitcoin-ethereum","name":"","type":"other","credibility":3},{"url":"https://unchainedcrypto.com/crypto-exchange-fixedfloat-hacked-for-26-million-in-bitcoin-ether/","name":"","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2024/04/02/fixedfloat-hit-by-2-8-million-crypto-hack-again/","name":"","type":"other","credibility":3},{"url":"https://cryptoslate.com/fixedfloat-reportedly-suffers-2-8-million-theft-tether-blocks-400000-from-attackers/","name":"","type":"other","credibility":3},{"url":"https://ff.io/en/blog/news/reasons-for-hacking","name":"","type":"other","credibility":3},{"url":"https://www.bankinfosecurity.com/cryptohack-roundup-26m-fixedfloat-hack-a-24424","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-fixedfloat-hack-february-2024","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Blockchain analytics firms tracked the movement of stolen assets from both breaches in detail.\n\nFebruary 2024 breach — Ethereum: The attacker's externally owned account (EOA) was identified by PeckShield and labeled as the 'FixedFloat drainer' at address 0x85c4fF99bF0eCb24e02921b0D4b5d336523Fa085. The victim address was 0x4E5B2e1dc63F6b91cb6Cd759936495434C7e972F. The 1,728.48 ETH was drained across four transactions over approximately 34 minutes and routed to eXch, a centralized token swapping service used to obscure the trail. Secondary fund movements were also observed to HitBTC and CoinSpot.\n\nFebruary 2024 breach — Bitcoin: The primary attacker address was bc1q2skp47p9f5mr4n4m27k66v0l68gh3xdd7ad4e5. The victim address was bc1qns9f7yfx3ry9lj6yz7c9er0vwa0ye2eklpzqfw. The 409.304 BTC was split across two movement patterns: a main sequential wallet chain moving 370.85 BTC through a series of addresses, and a dispersion pattern fragmenting 97.64 BTC across 72 distinct addresses, each receiving approximately 0.5 BTC, which were then further split into 576 total addresses to complicate tracing. As of February 20, 2024, 202 BTC remained in the originating attacker address.\n\nApril 2024 breach: Attackers routed stolen assets through eXch again, swapping liquid stablecoins such as USDT and USDC before Tether could freeze them, while DAI was deposited directly to eXch without conversion. Tether subsequently froze approximately $400,000 in attacker-linked USDT addresses.\n\nDestination — eXch: eXch, the primary laundering destination for the Ethereum-denominated stolen funds, was shut down by German authorities (Frankfurt am Main Public Prosecutor's Office, ZIT, and the BKA) on April 30, 2024. Investigators seized approximately 34 million euros ($38.5 million) in crypto assets and identified eXch's role in laundering funds from the FixedFloat hacks, the Bybit hack, the Genesis creditor theft, and other major incidents. Blockchain investigator ZachXBT documented eXch's laundering role across multiple incidents.","heading":"On-Chain Evidence","sources":[{"url":"https://medium.com/coinmonks/fixed-float-exploit-tracing-the-26-million-lost-to-the-hack-25fda467b577","name":"","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/the-rise-and-fall-of-exch-the-dark-service-used-by-north-korea-to-launder-200-million-stolen-from-bybit","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/germany-seizes-38-million-crypto-bybit-hack-linked-exch","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2024/04/02/bitcoin-lightning-exchange-fixedfloat-sees-suspicious-transfers-of-3m-to-ethereum-tron","name":"","type":"other","credibility":3},{"url":"https://medium.com/sentinel-protocol/the-fixedfloat-april-hack-comprehensive-analysis-and-insights-9bac2e2ca61d","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"FixedFloat does not publicly disclose the identities of its founders, executives, or core team members. The operational legal entity and country of incorporation have not been confirmed in any public filing or disclosure. The platform has been operating since 2018 and describes its founders only as 'blockchain specialists with extensive experience in developing rich web applications.' This level of anonymity is atypical even among no-KYC exchanges and creates meaningful accountability gaps: there are no named individuals responsible for security decisions, no disclosed regulatory registrations, and no clear legal recourse mechanism for users who suffer losses. Following the two 2024 breaches, communications from the platform were issued without attribution to named personnel. In its official post-breach statement, FixedFloat disclosed that it had outsourced significant infrastructure to a third-party hosting provider (Time4VPS) without implementing network-level white-listing or adequate access controls, suggesting resource or capacity constraints in its operations. The platform's decision to provide post-breach information 'only privately to journalists' rather than through public disclosure further limits independent accountability assessment.","heading":"Team & Anonymity","sources":[{"url":"https://u.today/fixedfloat-introduces-multi-blockchain-noncustodial-exchange-with-no-kyc-review","name":"","type":"other","credibility":3},{"url":"https://ff.io/en/blog/news/reasons-for-hacking","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-fixedfloat-hack-february-2024","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"FixedFloat presents an elevated risk profile across several dimensions.\n\nSecurity track record: The platform suffered two confirmed hacks within six weeks in 2024 totaling approximately $28.9 million in losses. Both breaches were attributed to inadequate third-party infrastructure controls. The platform had not implemented basic network access controls (IP white-listing) on hosted servers prior to the attacks. Full technical root cause disclosure was withheld from the public.\n\nOperational anonymity: The absence of any publicly named team, disclosed legal entity, or regulatory registration means there is no clear accountability structure if the platform is again breached, ceases operations, or freezes user funds.\n\nNo-KYC model and illicit finance exposure: FixedFloat's no-KYC model, while legal in some jurisdictions, makes it a preferred channel for users seeking to obscure transaction origins. The stolen funds from both hacks were laundered through eXch, a service subsequently designated by German law enforcement as a money laundering infrastructure. FixedFloat itself has in the past cooperated in freezing stolen funds from third-party hacks (e.g., 112 ETH from the Curve attack), but its own breach funds were not recovered.\n\nUser complaints: Community review platforms document recurring reports of funds frozen under AML review without clear timelines, inadequate support communication, and in some cases allegations of unresolved freezes lasting months.\n\nRegulatory exposure: The platform explicitly blocks US users. It operates without disclosed regulatory licensing in any jurisdiction. The broader regulatory trend toward mandatory KYC for crypto exchanges in the EU, UK, and other jurisdictions creates ongoing operational risk for the platform.\n\nResilience: FixedFloat resumed operations approximately two months after the February 2024 breach, claiming infrastructure migration away from Time4VPS and enhanced security measures. However, no independent security audit has been publicly disclosed to validate these claims.","heading":"Risk Assessment","sources":[{"url":"https://beincrypto.com/fixed-float-two-hacks-survival-story/","name":"","type":"other","credibility":3},{"url":"https://coinpedia.org/press-release/fixedfloat-exchange-statement-on-security-breaches-and-future-enhancements/","name":"","type":"other","credibility":3},{"url":"https://www.trustpilot.com/review/ff.io","name":"","type":"other","credibility":3},{"url":"https://kycnot.me/service/fixedfloat","name":"","type":"other","credibility":3},{"url":"https://ff.io/en/blog/news/reasons-for-hacking","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2018","event":"FixedFloat launches as a non-custodial, no-KYC cryptocurrency swap exchange.","source":"","date_original":"2018-01-01"},{"date":"2024-02-16","event":"First breach: 409.304 BTC and 1,728.48 ETH (approximately $26.1 million) drained in under 45 minutes across nine transactions. Platform enters maintenance mode.","source":""},{"date":"2024-02-18","event":"FixedFloat publicly confirms the hack, attributing it to 'vulnerabilities and security gaps in its infrastructure.' Stolen Ethereum funds traced to eXch mixer by PeckShield.","source":""},{"date":"2024-03-31","event":"Alleged same attacker gains unauthorized access to all FixedFloat servers still hosted at Time4VPS.","source":""},{"date":"2024-04","event":"Second breach: approximately $2.8 million drained from FixedFloat's Ethereum hot wallet. Attacker locks FixedFloat out of Time4VPS account by changing recovery email.","source":"","date_original":"2024-04-01"},{"date":"2024-04-02","event":"Cyvers alerts community to suspicious FixedFloat transactions. CoinDesk and CryptoSlate report the second hack. Tether freezes approximately $400,000 in attacker-linked USDT.","source":""},{"date":"2024-04-30","event":"German authorities (BKA/ZIT) shut down eXch — the primary laundering destination for FixedFloat's stolen Ethereum — seizing approximately $38.5 million in crypto assets.","source":""},{"date":"2024-06","event":"FixedFloat resumes operations after approximately two-month suspension, claims infrastructure migrated away from Time4VPS and security improvements implemented. Attributes both hacks to Time4VPS vulnerabilities in official statement.","source":"","date_original":"2024-06-01"}],"sources_used":[{"url":"https://u.today/fixedfloat-introduces-multi-blockchain-noncustodial-exchange-with-no-kyc-review","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://ff.io/faq","name":"","type":"other","archive_url":"http://web.archive.org/web/20260726201322/https://ff.io/faq","credibility":3,"archive_timestamp":"2026-07-26T20:13:22+00:00"},{"url":"https://kycnot.me/service/fixedfloat","name":"","type":"other","archive_url":"http://web.archive.org/web/20260507193952/https://kycnot.me/service/fixedfloat","credibility":3,"archive_timestamp":"2026-05-07T19:39:52+00:00"},{"url":"https://decrypt.co/218077/fixedfloat-hack-26-million-bitcoin-ethereum","name":"","type":"other","archive_url":"http://web.archive.org/web/20260712071021/https://decrypt.co/218077/fixedfloat-hack-26-million-bitcoin-ethereum","credibility":3,"archive_timestamp":"2026-07-12T07:10:21+00:00"},{"url":"https://unchainedcrypto.com/crypto-exchange-fixedfloat-hacked-for-26-million-in-bitcoin-ether/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.cryptotimes.io/2024/04/02/fixedfloat-hit-by-2-8-million-crypto-hack-again/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829151122/https://www.cryptotimes.io/2024/04/02/fixedfloat-hit-by-2-8-million-crypto-hack-again/","credibility":3,"archive_timestamp":"2026-08-29T15:11:22+00:00"},{"url":"https://cryptoslate.com/fixedfloat-reportedly-suffers-2-8-million-theft-tether-blocks-400000-from-attackers/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260725202438/https://cryptoslate.com/fixedfloat-reportedly-suffers-2-8-million-theft-tether-blocks-400000-from-attackers/","credibility":3,"archive_timestamp":"2026-07-25T20:24:38+00:00"},{"url":"https://ff.io/en/blog/news/reasons-for-hacking","name":"","type":"other","archive_url":"http://web.archive.org/web/20260721055122/https://ff.io/en/blog/news/reasons-for-hacking","credibility":3,"archive_timestamp":"2026-07-21T05:51:22+00:00"},{"url":"https://www.bankinfosecurity.com/cryptohack-roundup-26m-fixedfloat-hack-a-24424","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830044501/https://www.bankinfosecurity.com/cryptohack-roundup-26m-fixedfloat-hack-a-24424","credibility":3,"archive_timestamp":"2026-08-30T04:45:01+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-fixedfloat-hack-february-2024","name":"","type":"other","archive_url":"http://web.archive.org/web/20260315170648/https://www.halborn.com/blog/post/explained-the-fixedfloat-hack-february-2024","credibility":3,"archive_timestamp":"2026-03-15T17:06:48+00:00"},{"url":"https://medium.com/coinmonks/fixed-float-exploit-tracing-the-26-million-lost-to-the-hack-25fda467b577","name":"","type":"other","archive_url":"http://web.archive.org/web/20260217085716/https://medium.com/coinmonks/fixed-float-exploit-tracing-the-26-million-lost-to-the-hack-25fda467b577","credibility":3,"archive_timestamp":"2026-02-17T08:57:16+00:00"},{"url":"https://www.elliptic.co/blog/the-rise-and-fall-of-exch-the-dark-service-used-by-north-korea-to-launder-200-million-stolen-from-bybit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260712071138/https://www.elliptic.co/blog/the-rise-and-fall-of-exch-the-dark-service-used-by-north-korea-to-launder-200-million-stolen-from-bybit","credibility":3,"archive_timestamp":"2026-07-12T07:11:38+00:00"},{"url":"https://cointelegraph.com/news/germany-seizes-38-million-crypto-bybit-hack-linked-exch","name":"","type":"other","archive_url":"http://web.archive.org/web/20251125112310/https://cointelegraph.com/news/germany-seizes-38-million-crypto-bybit-hack-linked-exch","credibility":3,"archive_timestamp":"2025-11-25T11:23:10+00:00"},{"url":"https://www.coindesk.com/markets/2024/04/02/bitcoin-lightning-exchange-fixedfloat-sees-suspicious-transfers-of-3m-to-ethereum-tron","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://medium.com/sentinel-protocol/the-fixedfloat-april-hack-comprehensive-analysis-and-insights-9bac2e2ca61d","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://beincrypto.com/fixed-float-two-hacks-survival-story/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260120220948/https://beincrypto.com/fixed-float-two-hacks-survival-story/","credibility":3,"archive_timestamp":"2026-01-20T22:09:48+00:00"},{"url":"https://coinpedia.org/press-release/fixedfloat-exchange-statement-on-security-breaches-and-future-enhancements/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.trustpilot.com/review/ff.io","name":"","type":"other","archive_url":"http://web.archive.org/web/20260227163358/https://www.trustpilot.com/review/ff.io","credibility":3,"archive_timestamp":"2026-02-27T16:33:58+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-5","created_at":"2026-05-04T02:54:35.346034+00:00","updated_at":"2026-08-30T05:14:08.501489+00:00"}}