Aditya Birla Capital Digital Gold Hack | ₹1.95 Crore Stolen in API Breach, Services Restored
Aditya Birla Capital Digital faced a major cyber breach on June 9, 2026, with ₹1.95 crore worth of digital gold stolen from 435 accounts. Learn how the breach occurred, how ABCD responded, and what it means for fintech API security.
Quick answer: On 9 June 2025, Aditya Birla Capital Digital found unauthorised gold sales that took about ₹1.95 crore from 435 users. The company suspended gold selling, restored the affected holdings the next day and later brought services back. The case shows fintech teams must secure their APIs, monitor unusual transactions and test their controls.
Key takeaways
- APIs that execute sales need authorisation checks for every action.
- Rate limits and anomaly alerts can spot odd selling patterns.
- The company reported restoring holdings, so users should still check their statements.
Table of Contents
- What Happened? A Snapshot of the Breach
- How the Attackers Pulled It Off
- Immediate Response Measures
- Why Digital Gold Platforms Are Attractive Targets
- Lessons for Fintech and GoldTech Players
- Impact on Customers and Brand Trust
- What Comes Next?
- Key Takeaways
On 9 June 2025, Aditya Birla Capital Digital (ABCD) revealed a serious cyber incident in which attackers siphoned off ₹1.95 crore worth of digital gold from 435 customer accounts. Although all stolen holdings have since been fully restored, the breach highlights growing risks in India’s booming digital gold market and exposes vulnerabilities in fintech API security.
What Happened? A Snapshot of the Breach
| Timeline | Event | Impact / Action |
|---|---|---|
| 9 June 2025 | Unauthorized gold sales detected | Hackers liquidate ₹1.95 crore from 435 ABCD users |
| Same day | Customer complaints surge | ABCD suspends gold‑selling feature to contain damage |
| 10 June | Holdings restored | Assets credited back; selling remains disabled |
| 12 June | Technical gaps patched | OTP bypass via API fixed; multi‑factor hardening applied |
| 15 June | Gold services resume | “Live and secure,” according to ABCD |
| 18 June | FIR filed in Mumbai | Central Region Cyber Police open investigation |
| Ongoing | Coordination with CERT‑In, Razorpay, insurer | Forensics, liability review, and hunt for culprits |
How the Attackers Pulled It Off
Initial Vector: Investigators believe threat actors exploited weak authentication logic in ABCD’s backend API, specifically, the endpoint that validates one‑time passwords (OTP) during a gold‑sell transaction.
OTP Bypass Workflow
-
Token Replay or Manipulation – By intercepting traffic, attackers forged a valid session token.
-
Server‑Side Validation Flaw – ABCD’s server accepted the forged token without confirming the OTP challenge.
-
Automated Sell Requests – Scripts rapidly sold holdings from hundreds of wallets linked to Razorpay.
-
Fund Diversion – Proceeds transferred to mule accounts before anti‑fraud controls triggered alarms.
Key Weaknesses Identified:
-
Insufficient rate limiting on the sell‑API.
-
Lack of device binding and IP reputation checks.
-
Overly permissive API keys granting write access without scope restriction.
Immediate Response Measures
Asset Restoration
ABCD and its government‑licensed bullion partner re‑credited gold grams within hours, ensuring no net loss to customers.
Service Suspension & Hardening
-
Temporarily disabled the “Sell Gold” button.
-
Patched OTP validation with a server‑side cryptographic nonce.
-
Enabled mandatory device fingerprinting for high‑value sells.
-
Added transaction velocity limits (₹2 lakh/day per account).
Law‑Enforcement & Regulatory Steps
-
Filed an FIR under the Information Technology Act, 2000 and relevant IPC sections.
-
Informed CERT‑In and insurance underwriters; opened threat‑intel sharing with Razorpay.
Why Digital Gold Platforms Are Attractive Targets
| Factor | Risk for Attackers to Exploit |
|---|---|
| Instant Liquidity | Gold can be sold 24 × 7 and settled within minutes. |
| API‑Driven Architecture | Fintech APIs often prioritize speed over deep security. |
| High Retail Adoption | Millions of small wallets mean broad attack surface. |
| Regulation Catch‑Up | Digital bullion rules still maturing compared to banking. |
Lessons for Fintech and GoldTech Players
Strengthen API Security
-
Adopt OAuth 2.0 with short‑lived, signed tokens.
-
Enforce HMAC request signing to prevent tampering.
Harden User Authentication
-
Shift from basic OTP to Step‑Up MFA (device biometrics + OTP).
-
Implement context‑aware risk scoring (geo‑velocity, time‑of‑day anomalies).
Build Real‑Time Fraud Analytics
-
Use machine‑learning models to flag unusual sell patterns.
-
Correlate Razorpay disbursements with on‑chain ledger entries.
Tighten Incident‑Response Playbooks
-
Conduct red‑team API penetration tests every quarter.
-
Maintain cyber insurance that explicitly covers digital assets.
Impact on Customers and Brand Trust
Despite swift remediation, the incident underscores a key challenge: consumer confidence. Digital gold remains popular for micro‑savings in India, but repeated breaches can spur user churn toward better‑secured rivals. Transparent breach disclosures, like ABCD’s real‑time updates, are vital for reputation management.
What Comes Next?
-
Forensic Deep Dive – ABCD’s SOC is reconstructing exact exploit chains.
-
Legal Pursuit – Mumbai cyber police and CERT‑In tracking money‑mule accounts.
-
Industry Wake‑Up Call – Other gold platforms likely to review OTP and API logic.
-
Regulatory Guidance – SEBI and RBI may issue fresh directives on digital commodity storage and transactional controls.
Conclusion
The ABCD breach proves that API‑level flaws, not just malware or phishing, pose critical risks to fintech ecosystems. As digital gold adoption soars, security‑by‑design and rapid incident response will separate trustworthy platforms from the rest.
Whether you’re a fintech architect, compliance officer, or everyday investor, remember: tokenized assets require token‑proof security at every API call.
Related reading
- Indian Businesses May Lose ₹20,000 Crore to Cyber Crimes in 2026 | CloudSEK Report – A Growing Threat to the Digital Economy
- What happened in the Allianz Life Insurance data breach and how many customers were affected?
- Cybersecurity Careers in India | Top AI Skills, Jobs, Salary Trends & Certification Paths
Reference
For the authoritative details, see OWASP.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0