BigONE hack — July 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 16, 2025 |
| Target type | Centralised exchange |
| Loss | $27,000,000Price at time of incident |
| Method | Supply chain or frontend compromiseCompromise of the exchange's backend build and deployment infrastructure. Attackers reached BigONE's production servers and modified the operating logic of its account, accounting and risk-control services so that withdrawals could be authorised through the exchange's own systems. BigONE and SlowMist both stated that no private keys were accessed. Cointelegraph reported that the initial foothold came from a social-engineering compromise of a developer's device. |
| Chains | Bitcoin, Ethereum, Tron, Solana, BNB Chain |
| Outcome | Users reimbursed |
What happened
BigONE, a centralised cryptocurrency exchange, lost about $27 million in the early hours of 16 July 2025 when attackers reached its production infrastructure rather than its keys.
The exchange said it detected abnormal movements involving a portion of platform assets and confirmed these were the result of a third-party attack. According to BigONE and the security firm SlowMist, which the exchange engaged to trace the funds, the intrusion was a supply-chain compromise: the attackers obtained access to BigONE's backend build and deployment environment and altered the operating logic of its account, accounting and risk-management services, which allowed withdrawals to be authorised through the exchange's own systems. Both BigONE and SlowMist stated that private keys remained secure and that the attack path was identified and contained without further loss. Cointelegraph reported that the entry point was a socially engineered compromise of a developer's device.
Reported asset breakdowns differ slightly between outlets: roughly 120 to 121 BTC, 350 ETH, 1,800 SOL, several million dollars of USDT, between about 9.5 and 9.7 billion SHIB, 538,000 DOGE, and smaller amounts of UNI, CELR, LEO and XIN. The holdings spanned Bitcoin, Ethereum, BNB Chain, Tron and Solana, and the stolen assets were swapped and moved cross-chain shortly after the theft.
BigONE suspended deposits and withdrawals, stating that all user assets were safe and that it would bear the losses in full using internal reserves and borrowing to replace tokens it did not hold in sufficient quantity. Trading and deposits resumed first, and the exchange later announced that withdrawals had been fully restored. It also offered a bounty of up to $8 million for information identifying the attackers. No attribution has been published and no recovery has been reported.
Sources
- CoinDeskSecondary · retrieved 2026-08-01
- Cointelegraph (via TradingView)Secondary · retrieved 2026-08-01
- CoinCentralSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "BigONE hack — July 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bigonehttps://itokenly.com/hacks/bigonePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.