BitoPro Hack
What happened
On May 8, 2025, attackers made unauthorized withdrawals of about $11 million to $11.5 million from an old BitoPro hot wallet on Ethereum, Tron, Solana and Polygon while the Taiwanese exchange was upgrading its hot wallet system. No smart contract was involved. According to BitoPro's investigation, the attackers used social engineering to plant malware on a cloud operations employee's device, used hijacked AWS session tokens to get past multi-factor authentication, and ran injected scripts on the hot wallet host.
BitoPro first described the downtime to users as maintenance and confirmed the hack on June 2, after ZachXBT reported it. The exchange said it refilled the hot wallets from its reserves, and it attributed the attack to North Korea's Lazarus Group. The stolen funds were swapped on DEXs and laundered through Tornado Cash, THORChain and Wasabi Wallet.
How it happened
- Attackers used social engineering against a BitoPro employee responsible for cloud operations and infected their device with malware.
- From that device they hijacked AWS session tokens, which let them bypass multi-factor authentication on BitoPro's cloud environment.
- Through command-and-control servers they injected scripts into the host running the old hot wallet.
- During a scheduled hot wallet system upgrade on May 8, 2025, they used that access to withdraw funds from the old hot wallet on four chains.
- The proceeds were swapped on decentralized exchanges and moved through Tornado Cash, THORChain and Wasabi Wallet.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.