BitoPro BitoGroup Hack

REPORTED LOSS $11.5M
High Access Control

What happened

On May 8, 2025, Taiwanese crypto exchange BitoPro was likely exploited for approximately $11.5 million following unauthorized access to one of its hot wallets during a wallet system upgrade. The stolen funds were quickly laundered through decentralized exchanges and privacy tools such as Tornado Cash, Thorchain, and Wasabi Wallet. Initially, BitoPro did not publicly disclose the breach, citing "system maintenance" as the reason for service disruption.

After blockchain sleuth ZachXBT exposed the exploit, BitoPro confirmed the incident.

The attacker compromised BitoPro’s hot wallet infrastructure during a scheduled upgrade and asset transfer operation. The breach allowed the attacker to withdraw assets across multiple chains, including Ethereum, Solana, Polygon, and Tron. The attacker then converted these assets to more anonymous forms, leveraging decentralized exchanges and mixing protocols to obfuscate their trail.

BitoPro later admitted that the hot wallet involved was outdated and targeted during maintenance. Despite the breach, the exchange claimed to have sufficient reserves and assured users that withdrawals, deposits, and trading remained unaffected. The exchange’s transparency came only after outside scrutiny, highlighting gaps in disclosure and incident response.

Case & protocol details

Classification CeFi
Protocol Type Exploit/Access control
Official Website bito.bitopro.com/
Protocol Twitter/X @bitoex_official?lang=en

Evidence & learning

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.