Key Highlights
- A threat actor claims to possess a database containing more than 6.5 million HTX user records, according to a Sept. 9 alert from Dark Web Intelligence.
- The disclosed database structure reportedly contains fields for emails, phone information, passwords, Google authentication and KYC-related data.
- Neither the authenticity of the dataset nor the 6.5 million-record figure has been independently verified, and the visible field names do not prove sensitive credentials were actually exposed.
Crypto exchange HTX is facing an unverified data-breach claim after a threat actor allegedly offered a database containing records linked to more than 6.5 million users.
Cybersecurity monitoring account Dark Web Intelligence reported the claim on Sept. 9. The post appeared at approximately 16:46 UTC and included a small portion of the alleged database presented by the threat actor as proof.
HTX, formerly known as Huobi, has not been shown confirming the authenticity or scope of the claimed dataset. The Crypto Times reached out to them and is awaiting a reply. The Crypto Times also could not independently verify that the material originated from HTX or that the database contains the claimed number of records.
Claimed HTX Database Includes Sensitive Field Names
According to Dark Web Intelligence, the visible portion of the database contains fields associated with email addresses, phone information, account identifiers and user-status information.
More sensitive labels, including “password,” “money_password,” “google_auth” and KYC-related fields, also appear within the database structure.
However, the presence of those labels does not establish that usable passwords, Google Authenticator secrets or KYC documents were actually contained in the exposed records. A database schema can contain a field even when the underlying information is encrypted, hashed, empty or otherwise unusable.
The sample reportedly also contains records carrying 2026 timestamps. While that may indicate relatively recent entries are present in the material being advertised, it does not by itself establish when the data was obtained or whether it came directly from HTX.
6.5 Million User Figure Remains Unverified
The threat actor reportedly claims the dataset contains records belonging to more than 6.5 million HTX users, but no independent analysis confirming that number has been made public.
The small sample shown with the claim is also insufficient to establish whether the wider database is complete, authentic or assembled from previously available information.
Dark-web breach listings require particular caution because threat actors can exaggerate record counts, combine older datasets or advertise data whose origin has not been demonstrated.
At the time of writing, verification from HTX or an independent cybersecurity investigation would be required before the incident could be treated as a confirmed breach. HTX maintains a dedicated section for account-security notices on its website.
HTX Has Faced Previous Security Incidents
The latest allegation comes shortly after HTX experienced a DDoS attack on Aug. 31, which Justin Sun said affected services but did not compromise user funds.
Earlier in August, HTX also changed its hot-wallet withdrawal architecture by distributing funds across multiple addresses and periodically rotating withdrawal wallets. HTX detailed the security changes following increased wallet scrutiny.
The exchange, then operating under the Huobi name, previously dealt with a separate data-security incident involving 4,960 users, which was reported in 2023. That incident involved exposed user contact and account-related information.
There is currently no evidence linking those earlier incidents to the newly advertised database.
For now, the alleged 6.5 million-user dataset should remain treated as an unverified breach claim. Confirmation of the database’s origin, the number of affected accounts and whether password, authentication or KYC information was genuinely exposed will depend on further technical verification or a response from HTX.
Also Read: Crypto Hacks Cross $322M in September’s First Week as Liquid Network Alone Loses $320M
