BigONE Hack
What happened
BigONE detected abnormal asset transfers on July 16, 2025 and estimated the loss at approximately $27 million. The exchange said the affected assets came from a hot wallet, that private keys remained secure, and that it would cover the losses.
Compromised production and risk-control infrastructure altered withdrawal logic and enabled unauthorized hot-wallet transfers while the exchange reported that private keys remained secure. That makes this a supply-chain or server-integrity failure, not evidence of a leaked signing key.
Case & protocol details
How it happened
- BigONE detected abnormal transfers and suspended deposits, withdrawals and trading.
- The exchange said the affected assets came from a hot wallet and that private keys remained secure.
- SlowMist attributed the path to a supply-chain compromise of production infrastructure.
- Modified account and risk-control logic enabled unauthorized withdrawals, which is not evidence that the signing key itself was leaked.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.