The Exodus Breach: 101,597 Crypto Wallet Emails Stolen in 2025
HEROIC analysts flagged a data breach tied to Exodus, the popular all-in-one cryptocurrency wallet, on May 15, 2025. The incident exposed the personal records of 101,597 users through what appears to be a direct exfiltration from a backend database. The only data type confirmed in this leak is email addresses, but as our team knows well, that single piece of informaton is often all an attacker needs to launch a damaging follow-on campaign against crypto holders.
Why a Crypto Wallet Email Leak Is More Dangerous Than It Looks
At first glance, email addresses seem harmless. But for users of a cryptocurrency platform, the stakes are considerably higher than they would be for a typical consumer app. Attackers who obtain a list of verified Exodus users know exactly who holds digital assets. From there, they can craft highly convincing phishing emails that mimic Exodus's branding, trick users into revealing their seed phrases or login credentails, or push malicious wallet updates designed to drain funds. Because crypto transactions are irreversible, victims rarely recover what is stolen. The specific targeting of a crypto user base makes this leak particularily concerning.
What Was Exposed in the Exodus Breach
- Email addresses for 101,597 registered Exodus wallet users
No passwords were included in this breach. However, the absence of passwords does not reduce the risk significantly when the exposed data directly identifies active cryptocurrency holders.
Why This Matters for Exodus Users
Even a list of email addresses tied to a crypto platform opens the door to a range of serious threats. Credential stuffing attacks are common: bad actors take email addresses and pair them with passwords from other breaches, then try those combinations on Exodus and related services. Account takeover attempts follow quickly. Beyond that, verified crypto user lists are sold and re-sold across dark web markets, meaning the risk does not expire after the initial leak. Identity theft, SIM-swap attacks, and targeted spear-phishing are all real outcomes that Exodus users should prepare for.
How a Database Breach Works
A database breach occurs when an unauthorized party gains access to a company's stored data, either through a vulnerability in the application layer, misconfigured cloud storage, exposed credentials, or a direct intrusion into a server. Once inside, attackers can copy user tables containing names, emails, and other personal details without disrupting normal site operations. Companies often do not detect these exfiltrations for days or weeks, giving attackers ample time to distribute or sell the stolen data. In Exodus's case, the extracted records surfaced on an underground forum, which is how HEROIC analysts identified and verified the breach.
Check If Your Email Was Exposed in the Exodus Breach
If you have ever created an account with Exodus, your email address may be among the 101,597 records compromised in this breach. HEROIC offers a free breach scanner backed by a database of over 400 billion exposed records. You can run a check in seconds to find out whether your information has appeared in this incident or any other known breach. Knowing your exposure is the first step toward protecting your accounts and your digital assets.
Breach Breakdown
101,597 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds