Skip to main content
Sign in

Summary

CoinsPaid (operating legal entity Dream Finance OÜ, headquartered in Tallinn, Estonia) is a business-to-business crypto payment processing platform founded in 2014 by Max Krupyshev and Pavel Kashuba. The company suffered two confirmed external cyberattacks — a $37.3 million theft in July 2023 and a $7.5 million breach in January 2024 — both attributed to third-party attackers with the first definitively linked to North Korea's Lazarus Group by blockchain analysts and the FBI; client funds were reported unaffected in both incidents. The company is currently navigating significant regulatory uncertainty under the EU's MiCA framework after losing its legacy Estonian FIU licence and suspending operations through its Lithuanian entity, while its CASP application in Estonia remains pending as of mid-2026.

Have evidence about CoinsPaid?

Timeline(13 events)

2014-01-01

CoinsPaid founded in Tallinn, Estonia by Max Krupyshev and Pavel Kashuba.

Crunchbase / company profile sources

2023-01-01

Lazarus Group begins a six-month social engineering campaign targeting CoinsPaid employees, including fake recruiter approaches and technical test lures.

DL News / CoinTelegraph

2023-07-07

Large-scale brute-force and DDoS attack using approximately 150,000 IP addresses hits CoinsPaid infrastructure, attributed to Lazarus Group preparatory activity.

DL News

2023-07-22

CoinsPaid hot wallets breached; approximately $37.3 million in cryptocurrency stolen. Simultaneously, Lazarus Group steals approximately $60 million from Alphapo. Operations suspended for approximately four days.

BleepingComputer / CoinTelegraph / FBI

2023-07-25

CoinsPaid files report with Estonian law enforcement regarding the hack. Company attributes attack to Lazarus Group.

CoinTelegraph

2023-07-26

CoinsPaid resumes processing operations after rebuilding infrastructure in isolated environment.

CoinsPaid official / CoinsPaid Media

2023-09-25

CoinsPaid renews its crypto licence from Estonia's Financial Intelligence Unit (FIU) under the new licensing regime.

CoinsPaid official announcement

2024-01-06

Second hack: Cyvers detects unauthorized withdrawals of approximately $7.5 million from CoinsPaid wallets. Root cause identified as inadequate wallet access control. Cyvers attributes the incident to Lazarus Group.

BeInCrypto / CoinMarketCap Academy / Web3 Is Going Great

2024-01-01

CoinsPaid receives ISO/IEC 27001 information security certification from Bureau Veritas.

Crypto.news / CoinsPaid security announcements

2025-12-31

Lithuania's MiCA transitional grandfathering period ends. Dream Finance UAB suspends all crypto-asset services in Lithuania rather than obtaining CASP authorisation.

FinTelegram

2026-05-01

CryptoProcessing by CoinsPaid achieves CCSS Level 3 certification following a Hacken audit that commenced in Q4 2025.

Crypto.news / The Next Web

2026-06-30

New entity Coinspaid Solutions OÜ registered in Estonia, one day before the old FIU licence regime ended.

FinTelegram

2026-07-01

MiCA enforcement phase begins in Estonia. CoinsPaid's legacy FIU licence is no longer valid for serving EU clients. Dream Finance OÜ's MiCA CASP application remains pending with no final decision.

FinTelegram / regulatory monitoring
Provenance & Audit Trail

Decision Log

  • #3review revise+13⛓ pending8/18/2026, 8:31:19 PM
    hash: GisDWKWrWbFovdFh1PbwZbpUaAko8W1E9FA2N3bDcJ6g
  • #2review⛓ pending8/18/2026, 8:31:19 PM
    hash: EV5DGvS8VurwfbJWE7ZtGn5dV9Ra96UqxqX9jDmerHJV
  • #1publish⛓ anchored · slot 4208044615/19/2026, 4:20:51 PM
    hash: HTJY7WBU6ZWLdPLfjpPGXcu8cwW3vnwU4SJrzVXpghM7

This investigation is cryptographically anchored to the Solana blockchain (1 event). 15 of 20 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/4/2026, 2:54:10 AM

last updated: 8/19/2026, 8:42:16 AM

avoid.net — verified advice for a post-truth world