BtcTurk Hack

Reported loss $54.0M
Private Key Compromised (Unknown Method)

What happened

On June 22, 2024, Turkish exchange BtcTurk reported unauthorized access affecting hot wallets. Industry reporting put the loss at roughly $54 million, while BtcTurk said trading and fiat operations continued and that most assets remained in cold storage. The exchange did not publish a definitive root-cause report.

Technical root cause

The confirmed issue is compromise of hot-wallet custody controls. Public sources do not establish whether the entry point was a stolen private key, malware, insider access or another method; the mechanism was not disclosed.

How it happened

  1. An attacker obtained control of one or more BtcTurk hot-wallet paths.
  2. Crypto assets were moved from wallets holding funds needed for withdrawals.
  3. BtcTurk restricted crypto deposits and withdrawals while investigating and coordinating with exchanges and investigators.
  4. Public on-chain reporting associated the incident with a limited set of assets rather than the exchange’s entire reserve.

Protocol details

Classification CeFi / Key Compromise
Protocol Type Exploit/Access control
Protocol links Website

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.