BitoPro BitoGroup Hack
What happened
On May 8, 2025, Taiwanese crypto exchange BitoPro was likely exploited for approximately $11.5 million following unauthorized access to one of its hot wallets during a wallet system upgrade. The stolen funds were quickly laundered through decentralized exchanges and privacy tools such as Tornado Cash, Thorchain, and Wasabi Wallet. Initially, BitoPro did not publicly disclose the breach, citing "system maintenance" as the reason for service disruption.
After blockchain sleuth ZachXBT exposed the exploit, BitoPro confirmed the incident.
The attacker compromised BitoPro’s hot wallet infrastructure during a scheduled upgrade and asset transfer operation. The breach allowed the attacker to withdraw assets across multiple chains, including Ethereum, Solana, Polygon, and Tron. The attacker then converted these assets to more anonymous forms, leveraging decentralized exchanges and mixing protocols to obfuscate their trail.
BitoPro later admitted that the hot wallet involved was outdated and targeted during maintenance. Despite the breach, the exchange claimed to have sufficient reserves and assured users that withdrawals, deposits, and trading remained unaffected. The exchange’s transparency came only after outside scrutiny, highlighting gaps in disclosure and incident response.
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report coindesk.com
- report Report binance.com
- report Report fortune.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.