BitoPro hack — May 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | June 2, 2025 |
| Target type | Centralised exchange |
| Loss | $11,500,000Price at time of incident |
| Method | Social engineeringAttackers used social engineering to plant malware on the device of a BitoPro employee who managed the exchange's cloud operations. BitoPro said the malware evaded its antivirus, endpoint protection and cloud security detection systems, and that the attackers hijacked AWS session tokens to bypass multi-factor authentication. The access was used during a scheduled hot wallet system upgrade and asset transfer operation to move funds out of hot wallets on four chains. |
| Chains | Ethereum, Tron, Solana, Polygon |
| Attributed to | Lazarus GroupSuspected |
| Outcome | Users reimbursed |
What happened
BitoPro, a Taiwanese cryptocurrency exchange, lost roughly $11.5 million from hot wallets on Ethereum, Tron, Solana and Polygon. Published dates differ by a day: the outflow transactions are dated 8 May on-chain, while accounts based on the exchange's own description place the incident at about 01:00 on 9 May 2025 Taipei time.
BitoPro said attackers used social engineering to plant malware on the device of an employee who managed its cloud operations. The malware evaded the company's antivirus, endpoint protection and cloud security detection, and the attackers hijacked AWS session tokens to bypass multi-factor authentication, then linked the AWS environment to a command-and-control server that issued instructions to the hot wallet systems while simulating legitimate wallet operations. The access was exploited during a scheduled hot wallet system upgrade and asset transfer operation. BitoPro said no internal personnel were involved and that the matter had been handed to criminal investigation units.
BitoPro did not publish a loss figure. The $11.5 million estimate comes from on-chain analyst ZachXBT, who flagged the outflows publicly on 2 June 2025 — 25 days after the incident and before the exchange had said anything — and traced funds into Tornado Cash and across Thorchain into Bitcoin and then Wasabi. Some reporting rounds the total to $11 million. BitoPro said it replenished the affected wallets from its own reserves and that no user funds were affected. An external cybersecurity firm commissioned by BitoPro concluded the methods bore hallmarks consistent with past Lazarus Group operations; no government body has attributed the theft.
Law enforcement
BitoPro said the case was handed to criminal investigation units in Taiwan for ongoing investigation and forensic analysis. No charges have been reported.
Sources
- BitoProPrimary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- BitdefenderSecondary · retrieved 2026-08-01
- SecurityOnlineSecondary · retrieved 2026-08-01
Official post-mortem: https://www.bitopro.com/ns/en-US/announcements/1226
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "BitoPro hack — May 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bitoprohttps://itokenly.com/hacks/bitoproPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.