Security Upgrade or Breach? BitoPro Responds to Alleged $11.5M Hack

2025-06-27 08:17:29
Beginner
Quick Reads
ZachXBT observed unusual fund movements in BitoPro's on-chain hot wallet, where the funds were exchanged through a centralized exchange and then directed towards anonymous trading tools like Tornado Cash, or cross-chain through Thorchain into the Bitcoin mainnet and subsequently stored in Wasabi, suspected of engaging in money laundering activities.

On-chain security investigation resurfaces, BitoPro hot wallet operations raise external concerns.

Blockchain investigator ZachXBT recently revealed a suspected major security incident in the community, pointing out that the Taiwanese cryptocurrency exchange BitoPro may face capital outflows on May 8, 2025, involving an amount as high as $11.5 million. He observed abnormal fund movements in BitoPro’s hot wallets across Ethereum, Tron, Solana, and Polygon chains, and these funds were exchanged via decentralized exchanges before being directed to anonymous trading tools such as Tornado Cash, or transferred across chains into the Bitcoin mainnet via Thorchain and stored in Wasabi, suggesting potential money laundering activities.

The platform token BITO has dropped sharply, and the user community is worried about asset security.

Following the exposure of the news, the BitoPro platform token $BITO fell by more than 8% in a single day. The user community has raised questions about the authenticity of the event and the platform’s response, especially since ZachXBT pointed out that BitoPro only referred to it as “system maintenance” at the time and did not promptly disclose the specific situation of the suspected hacking through official channels, which further deepened market concerns.


(Image source: BitoPro)

The cybersecurity company has intervened in the investigation, and the platform has activated its response mechanism.

In response to external doubts, BitoPro has issued an official statement acknowledging that it suffered a hacker attack during the upgrade of its hot wallet and the transfer of assets. The platform stated that it immediately activated emergency response measures at the time of the incident, swiftly transferring the remaining assets to a new hot wallet, while also blocking suspicious activities and commissioning a third-party cybersecurity company to assist in a comprehensive investigation and tracking of the hacker’s whereabouts. BitoPro emphasized that its overall asset reserves are sufficient, and most digital assets are stored in offline cold wallets, which were not affected by this incident.

Suspected to be related to an international hacker organization

According to a joint analysis by its internal cybersecurity team and third-party organizations, the attack method bears a high similarity to several previous global cybersecurity incidents, and is suspected to be the work of the notorious North Korean hacker group Lazarus Group, which has been involved in multiple illegal SWIFT transfers from multinational financial institutions, as well as large-scale asset theft incidents on cryptocurrency platforms, demonstrating a high level of technical skill and operational stealth.

Social engineering infiltrates cloud permissions, targeting operational nodes to launch attacks.

The hacker used social engineering as an entry point to target an engineer responsible for maintaining cloud infrastructure, successfully implanting a trojan and bypassing multiple protective mechanisms, including endpoint detection, antivirus, and cloud security alert systems. They then lurked for an extended period to observe the engineer’s operational behavior. During this process, the attacker hijacked the engineer’s AWS Session Token, successfully bypassing Multi-Factor Authentication (MFA), and pushed malicious scripts to the cloud environment via a C2 control endpoint, ultimately directing the attack towards the hot wallet host.

Lock the timing for scheduling platform assets, multi-chain assets are stolen and transferred.

During the attack, the platform was undergoing a wallet upgrade and fund allocation. The hacker took the opportunity to trigger a pre-deployed script, simulating the daily legitimate operation process, and quickly transferred assets illegally from chains such as Ethereum, Tron, Solana, and Polygon, totaling approximately $11.5 million. The assets were converted and obfuscated through decentralized tools like Tornado Cash and Thorchain, and then cross-chain to the Bitcoin network, ultimately flowing into mixing services like Wasabi Wallet, further concealing the source of the funds.

The event has entered a judicial investigation, the wallet has been rebuilt and has become public and transparent.

The incident has now been fully handed over to the judicial authorities for criminal investigation and tracing. The platform has also initiated a comprehensive security check, rebuilding the wallet infrastructure. Users can now view the latest hot wallet deployment status of BitTrust through the Arkham platform. The platform promises to continuously enhance security levels in the future and strengthen monitoring of operational permissions and prevention of abnormal behaviors to prevent similar incidents from occurring again.

The latest deployment status of Bit托’s hot wallets:https://intel.arkm.com/explorer/entity/bitopro

If you want to learn more about Web3 content, click to register:https://www.gate.com/

Summary

In the cryptocurrency market, asset security is always the most fundamental commitment of trading platforms. The BitoPro incident reminds all practitioners and users that layered management of hot and cold wallets and transparency of information will be crucial for the security of digital assets in the future. This incident will undoubtedly prompt a comprehensive review of the security protection of exchanges within the community once again.

Author: Allen
Disclaimer
* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.

Share

Crypto Calendar
Tokenların Kilidini Aç
Wormhole, 3 Nisan'da 1.280.000.000 W token açacak ve bu, mevcut dolaşımdaki arzın yaklaşık %28,39'unu oluşturacak.
W
-7.32%
2026-04-02
Tokenların Kilidini Aç
Pyth Network, 19 May'da 2.130.000.000 PYTH tokenini serbest bırakacak ve bu, mevcut dolaşım arzının yaklaşık %36,96'sını oluşturacak.
PYTH
2.25%
2026-05-18
Tokenların Kilidini Aç
Pump.fun, 12 Temmuz'da 82,500,000,000 PUMP token'ı kilidini açacak ve bu, mevcut dolaşımdaki arzın yaklaşık %23,31'ini oluşturacak.
PUMP
-3.37%
2026-07-11
Token Kilidi Açma
Succinct, 5 Ağustos'ta mevcut dolaşımdaki arzın yaklaşık %104,17'sini oluşturan 208,330,000 PROVE token'ını serbest bırakacak.
PROVE
2026-08-04
sign up guide logosign up guide logo
sign up guide content imgsign up guide content img
Sign Up

Related Articles

What is Fartcoin? All You Need to Know About FARTCOIN
Intermediate

What is Fartcoin? All You Need to Know About FARTCOIN

Fartcoin (FARTCOIN) is a representative meme coin within the Solana ecosystem based on an AI-driven narrative. Its core concept originated from an experiment aimed at exploring the "boundaries between AI Agents and humor." More than just a digital asset with social attributes, the project deeply couples absurd humor culture with on-chain financial logic by integrating autonomous AI interaction models.
2026-03-04 05:38:51
Gold Price Forecast for the Next Five Years: 2026–2030 Trend Outlook and Investment Implications, Could It Reach $6,000?
Beginner

Gold Price Forecast for the Next Five Years: 2026–2030 Trend Outlook and Investment Implications, Could It Reach $6,000?

Analyze current gold price trends alongside authoritative five-year forecasts, integrating an evaluation of market risks and opportunities. This gives investors insight into the potential trajectory of gold prices and the main drivers expected to shape the market over the next five years.
2026-01-26 03:33:33
2026 Silver Price Forecast: Bull Market Continuation or High-Level Pullback? In-Depth Analysis of Silver Candlestick Chart
Beginner

2026 Silver Price Forecast: Bull Market Continuation or High-Level Pullback? In-Depth Analysis of Silver Candlestick Chart

2026 Silver Price Forecast: Latest Outlook This article integrates current market trends, silver candlestick chart analysis, and momentum factors to assess the potential key support and resistance levels, upside targets, and pullback risks for silver prices. The goal is to help investors make informed, rational decisions.
2026-01-28 08:36:39
Crypto Future Profit Calculator: How to Calculate Your Potential Gains
Beginner

Crypto Future Profit Calculator: How to Calculate Your Potential Gains

Crypto Future Profit Calculator helps traders estimate potential earnings from futures contracts by considering entry price, leverage, fees, and market movement.
2025-02-09 17:28:28
Crypto Futures Calculator: Easily Estimate Your Profits & Risks
Beginner

Crypto Futures Calculator: Easily Estimate Your Profits & Risks

Use a crypto futures calculator to estimate profits, risks, and liquidation prices. Optimize your trading strategy with accurate calculations.
2025-02-11 02:25:44
What is Oasis Network (ROSE)?
Beginner

What is Oasis Network (ROSE)?

The Oasis Network is driving the development of Web3 and AI through smart privacy technology. With its privacy protection, high scalability, and cross-chain interoperability, the Oasis Network is providing new possibilities for the future development of decentralized applications.
2025-05-20 09:41:15