Skip to main content
AVOID.NET

Phemex

avoid.net/phemex10/100·100% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·LDBroZ…yNWW

Summary

Phemex is a centralized cryptocurrency derivatives exchange founded in November 2019 by former Morgan Stanley executives and registered in the British Virgin Islands. In January 2025, the exchange suffered one of the largest crypto hacks of that year, with an estimated $69–85 million drained from hot wallets across 16 blockchains, subsequently attributed to North Korea's Lazarus Group through on-chain evidence linking the same wallets to the February 2025 Bybit hack. Phemex has also faced formal regulatory enforcement actions in Ontario, Canada, and operates without authorization in the United Kingdom.

Connected Entities

1 entities
Organizations
Phemex
Relationships
    Have evidence about Phemex?
    0
    Accepted
    2
    Under review
    0
    Rejected / revoked

    Community submissions

    Timeline(10 events)

    November 2019

    Phemex founded by Jack Tao and seven other former Morgan Stanley executives; incorporated in the British Virgin Islands.

    2021

    UK Financial Conduct Authority designates Phemex as an unauthorized firm operating without FCA approval.

    7 January 2023

    Phemex implements IP-based blocks on Ontario users after being contacted by the Ontario Securities Commission.

    18 December 2024

    Ontario Capital Markets Tribunal rules in Phemex Limited (Re), 2024 ONCMT 30 that Phemex operated an unregistered securities trading platform in Ontario; both entities permanently banned from Ontario capital markets.

    23 January 2025

    Phemex hot wallets drained across 16 blockchains; estimated $69–85 million stolen. Withdrawals suspended at 15:13 UTC. PeckShield and Cyvers flag approximately 125 suspicious transactions.

    24 January 2025

    Phemex CEO publishes Proof of Reserves and issues compensation plan. Security firms Halborn, Merkle Science, and Hacken begin on-chain analysis; Lazarus Group suspected.

    February 2025

    Phemex restores full withdrawal services approximately 10 days after the breach.

    19 February 2025

    Global Ledger identifies 2,080+ ETH from Phemex hack routed through Tornado Cash, eXch mixer, THORChain, and Wintermute.

    21 February 2025

    Bybit suffers $1.4 billion hack, subsequently attributed to Lazarus Group.

    22 February 2025

    ZachXBT publicly identifies on-chain commingling of Phemex and Bybit hack proceeds at Ethereum address 0x33d057af74779925c4b2e720a820387cb89f8f65, directly linking both hacks to Lazarus Group.

    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (1 event). 11 of 17 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 5/4/2026, 2:54:26 AM

    last updated: 9/16/2026, 12:39:58 AM

    5 views

    avoid.net — verified advice for a post-truth world