Security Upgrade or Breach? BitoPro Responds to Alleged $11.5M Hack

6/27/2025, 8:17:29 AM
Beginner
Quick Reads
ZachXBT observed unusual fund movements in BitoPro's on-chain hot wallet, where the funds were exchanged through a centralized exchange and then directed towards anonymous trading tools like Tornado Cash, or cross-chain through Thorchain into the Bitcoin mainnet and subsequently stored in Wasabi, suspected of engaging in money laundering activities.

On-chain security investigation resurfaces, BitoPro hot wallet operations raise external concerns.

Blockchain investigator ZachXBT recently revealed a suspected major security incident in the community, pointing out that the Taiwanese cryptocurrency exchange BitoPro may face capital outflows on May 8, 2025, involving an amount as high as $11.5 million. He observed abnormal fund movements in BitoPro’s hot wallets across Ethereum, Tron, Solana, and Polygon chains, and these funds were exchanged via decentralized exchanges before being directed to anonymous trading tools such as Tornado Cash, or transferred across chains into the Bitcoin mainnet via Thorchain and stored in Wasabi, suggesting potential money laundering activities.

The platform token BITO has dropped sharply, and the user community is worried about asset security.

Following the exposure of the news, the BitoPro platform token $BITO fell by more than 8% in a single day. The user community has raised questions about the authenticity of the event and the platform’s response, especially since ZachXBT pointed out that BitoPro only referred to it as “system maintenance” at the time and did not promptly disclose the specific situation of the suspected hacking through official channels, which further deepened market concerns.


(Image source: BitoPro)

The cybersecurity company has intervened in the investigation, and the platform has activated its response mechanism.

In response to external doubts, BitoPro has issued an official statement acknowledging that it suffered a hacker attack during the upgrade of its hot wallet and the transfer of assets. The platform stated that it immediately activated emergency response measures at the time of the incident, swiftly transferring the remaining assets to a new hot wallet, while also blocking suspicious activities and commissioning a third-party cybersecurity company to assist in a comprehensive investigation and tracking of the hacker’s whereabouts. BitoPro emphasized that its overall asset reserves are sufficient, and most digital assets are stored in offline cold wallets, which were not affected by this incident.

Suspected to be related to an international hacker organization

According to a joint analysis by its internal cybersecurity team and third-party organizations, the attack method bears a high similarity to several previous global cybersecurity incidents, and is suspected to be the work of the notorious North Korean hacker group Lazarus Group, which has been involved in multiple illegal SWIFT transfers from multinational financial institutions, as well as large-scale asset theft incidents on cryptocurrency platforms, demonstrating a high level of technical skill and operational stealth.

Social engineering infiltrates cloud permissions, targeting operational nodes to launch attacks.

The hacker used social engineering as an entry point to target an engineer responsible for maintaining cloud infrastructure, successfully implanting a trojan and bypassing multiple protective mechanisms, including endpoint detection, antivirus, and cloud security alert systems. They then lurked for an extended period to observe the engineer’s operational behavior. During this process, the attacker hijacked the engineer’s AWS Session Token, successfully bypassing Multi-Factor Authentication (MFA), and pushed malicious scripts to the cloud environment via a C2 control endpoint, ultimately directing the attack towards the hot wallet host.

Lock the timing for scheduling platform assets, multi-chain assets are stolen and transferred.

During the attack, the platform was undergoing a wallet upgrade and fund allocation. The hacker took the opportunity to trigger a pre-deployed script, simulating the daily legitimate operation process, and quickly transferred assets illegally from chains such as Ethereum, Tron, Solana, and Polygon, totaling approximately $11.5 million. The assets were converted and obfuscated through decentralized tools like Tornado Cash and Thorchain, and then cross-chain to the Bitcoin network, ultimately flowing into mixing services like Wasabi Wallet, further concealing the source of the funds.

The event has entered a judicial investigation, the wallet has been rebuilt and has become public and transparent.

The incident has now been fully handed over to the judicial authorities for criminal investigation and tracing. The platform has also initiated a comprehensive security check, rebuilding the wallet infrastructure. Users can now view the latest hot wallet deployment status of BitTrust through the Arkham platform. The platform promises to continuously enhance security levels in the future and strengthen monitoring of operational permissions and prevention of abnormal behaviors to prevent similar incidents from occurring again.

The latest deployment status of Bit托’s hot wallets:https://intel.arkm.com/explorer/entity/bitopro

If you want to learn more about Web3 content, click to register:https://www.gate.com/

Summary

In the cryptocurrency market, asset security is always the most fundamental commitment of trading platforms. The BitoPro incident reminds all practitioners and users that layered management of hot and cold wallets and transparency of information will be crucial for the security of digital assets in the future. This incident will undoubtedly prompt a comprehensive review of the security protection of exchanges within the community once again.

Author: Allen
* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.

Share

Crypto Calendar

Project Updates
Etherex will launch the token REX on August 6.
REX
22.27%
2025-08-06
NFT AI Product Launch
Nuls will launch an NFT AI product in the third quarter.
NULS
2.77%
2025-08-06
dValueChain v.1.0 Launch
Bio Protocol is set to roll out dValueChain v.1.0 in the first quarter. It aims to establish a decentralized health data network, ensuring secure, transparent, and tamper-proof medical records within the DeSci ecosystem.
BIO
-2.47%
2025-08-06
AI-Generated Video Subtitles
Verasity will add an AI-generated video subtitles function in the fourth quarter.
VRA
-1.44%
2025-08-06
VeraPlayer Multi-Language Support
Verasity will add multi-language support to VeraPlayer in the fourth quarter.
VRA
-1.44%
2025-08-06

Related Articles

Pi Coin Transaction Guide: How to Transfer to Gate.io
Beginner

Pi Coin Transaction Guide: How to Transfer to Gate.io

Pi Network is a decentralized cryptocurrency network for the general public, using the Stellar Consensus Protocol (SCP) consensus mechanism, which allows users to easily mine Pi tokens from their mobile devices and use them for payments and transactions. With the official opening of the mainnet on February 20, 2025, investors can deposit and trade $PI on exchanges such as Gate.io. This article details how to securely transfer Pi Coins to Gate.io, including obtaining a deposit address, completing the transfer using the Pi Network mainnet wallet, and the exchange's arrival confirmation process. In addition, we have analysed $PI investment risks, including market volatility, compliance and potential fraud risks, to remind investors to take risk management before trading.
2/25/2025, 8:21:43 AM
What is N2: An AI-Driven Layer 2 Solution
Beginner

What is N2: An AI-Driven Layer 2 Solution

This article introduces N2 (Niggachain AI Layer 2), the world's first AI-driven Layer 2 blockchain solution. N2 combines AI technology and quantum computing resistance to address the limitations of traditional blockchains in scalability, transaction speed, and cost. Its core technologies include '0-second block time', AI-driven network optimization, and quantum-resistant security protection, aiming to improve transaction efficiency and ensure system stability.
12/23/2024, 7:21:00 AM
Grok AI, GrokCoin & Grok: the Hype and Reality
Beginner

Grok AI, GrokCoin & Grok: the Hype and Reality

Discover Grok AI, GrokCoin, and Grok Crypto—from Elon Musk's AI chatbot to the viral meme coin inspired by it. Learn about GrokCoin’s rise, its connection to Grok AI, and the risks of investing in meme coins.
3/7/2025, 10:33:07 AM
How to Sell Pi Coin: A Beginner's Guide
Beginner

How to Sell Pi Coin: A Beginner's Guide

This article provides detailed information about Pi Coin, how to complete KYC verification, and choose the right exchange to sell Pi Coin. We also provide specific steps for selling Pi Coin and remind of important matters to pay attention to when selling, helping novice users complete Pi Coin transactions smoothly.
2/26/2025, 9:20:50 AM
Crypto Trends in 2025
Beginner

Crypto Trends in 2025

As 2025 arrives, the cryptocurrency market stands at a new crossroads of development. This article delves into five key trends shaping the current crypto landscape, covering significant regulatory changes, the transformational impact of Bitcoin spot ETFs, the deep integration of AI and blockchain, Ethereum’s technical upgrades, and the rise of emerging markets. Through analysis of these trends, the goal is to provide investors, professionals, and enthusiasts with clear insights into the future direction of the crypto market, helping them better seize opportunities and face challenges. Real-world examples are included to help readers understand the dynamics of how the market is developing under each trend.
4/10/2025, 9:55:53 AM
What is Official Elon Coin (ELON)?
Beginner

What is Official Elon Coin (ELON)?

Official ELON Coin is an innovative project launched on the Solana blockchain, connecting the future of cryptocurrency and fan concepts through the $ELON token. After its launch, the project quickly gained strong community support and market confidence, with a maximum market value of $26 million. Through its unique token distribution mechanism and long-term development plan, the project ensures market stability and sustainability.
1/20/2025, 5:08:32 AM
Start Now
Sign up and get a
$100
Voucher!