Bitrue Hack

Reported loss $23.0M
Hot-wallet compromise; initial access unknown

What happened

Bitrue reported that, at 07:18 UTC on April 14, 2023, attackers exploited one of its hot wallets and withdrew approximately $23 million in ETH, QNT, GALA, SHIB, HOT and MATIC. Bitrue said the affected wallet held less than 5% of its overall funds, that other wallets were not compromised, and that it suspended withdrawals for a security review. The exchange said identified affected users would be compensated in full.

Technical root cause

The public incident notice supports a hot-wallet compromise/exploit and unauthorized withdrawals, but does not disclose the credential, key-management, software, or access-control failure that enabled it. A more specific root-cause claim is therefore unresolved.

How it happened

  1. Attackers gained the ability to withdraw assets from one Bitrue hot wallet, an internet-accessible wallet used by the centralized exchange.
  2. Approximately $23 million in ETH, QNT, GALA, SHIB, HOT and MATIC was withdrawn.
  3. Bitrue said it addressed the incident quickly, prevented further exploitation, and determined that the affected wallet contained less than 5% of its funds.
  4. Bitrue suspended withdrawals while conducting additional security checks and announced that identified affected users would be compensated in full.

Protocol details

Classification CeFi / Access Control
Protocol Type CEX
Protocol links Website @BitrueOfficial

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.