T
iTokenly

AscendEX hack — December 2021

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedDecember 12, 2021
Target typeCentralised exchange
Loss$77,700,000Price at time of incident
Recovered$10,000,000
MethodInfrastructure compromiseunauthorised passthrough access to hot wallet infrastructure, attributed by AscendEX to a hardware-level vulnerability in third-party infrastructure
ChainsEthereum, Polygon, BNB Chain, Other
OutcomeUsers reimbursed

What happened

AscendEX, a Singapore-based exchange formerly called BitMax, identified unauthorised transfers from one of its hot wallets on 11 December 2021, detected at around 22:00 UTC. The exchange's own incident report says an individual or group "gained unauthorized passthrough access to AscendEX's hot wallet infrastructure" and initiated transfers on the Ethereum, Polygon, Binance Smart Chain, Litecoin and Bitcoin Cash networks; its earlier follow-up announcement also listed xDai addresses. An internal audit identified the breach as "the result of an exploit of hardware-level vulnerability from third-party infrastructure utilized by AscendEX." The vulnerability itself was never described.

AscendEX never published a loss figure. The widely cited estimate comes from PeckShield, which put the total at $77.7 million — roughly $60 million on Ethereum, $9.2 million on Binance Smart Chain and $8.5 million on Polygon — reported by CoinDesk and Cointelegraph on 12 and 13 December 2021. Headlines quoting $80 million round the same estimate. Stolen assets spanned dozens of ERC-20 tokens including USDT, USDC and SHIB. Cold wallet reserves were not affected.

The exchange suspended deposits and withdrawals, moved unaffected assets to cold storage, and encouraged affected token projects to migrate contracts. Five did so — Zignaly, Bemil Coin, Gather, BTC Proxy and Aubit — which AscendEX said recovered over $10 million. Deposits and withdrawals reopened from 03:00 UTC on 16 December 2021 on entirely new hot wallet infrastructure, with new deposit addresses for every account. AscendEX stated it had reimbursed 100% of impacted users. No attacker has been publicly identified.

Law enforcement

AscendEX said it worked with law enforcement and with Ledger and Chainalysis. No arrests, charges or sanctions have been reported.

Sources

  1. AscendEX (Dec. 11 Security Incident Report, archived)Primary · retrieved 2026-08-01
  2. AscendEX (follow-up announcement, archived)Primary · retrieved 2026-08-01
  3. CoinDeskSecondary · retrieved 2026-08-01
  4. CointelegraphSecondary · retrieved 2026-08-01

Official post-mortem: https://web.archive.org/web/20220126215612/https://ascendex.com/en/support/articles/62198

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "AscendEX hack — December 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/ascendex
https://itokenly.com/hacks/ascendex

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.