Bitrue hack — April 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | April 14, 2023 |
| Target type | Centralised exchange |
| Loss | $23,000,000Price at time of incident |
| Method | Other or undisclosedOne of Bitrue's hot wallets was drained of six ERC-20 assets in a single incident. Bitrue described it only as a brief exploit of that wallet and never disclosed the mechanism; no post-mortem was published and no independent analysis has established the root cause. |
| Chains | Ethereum |
| Outcome | Users reimbursed |
What happened
At 07:18 UTC on 14 April 2023 an attacker withdrew about $23 million of assets from a hot wallet belonging to Bitrue, a centralised cryptocurrency exchange. Bitrue disclosed the incident the same day, describing it as a brief exploit of one of its hot wallets and saying it had acted quickly enough to prevent further losses.
The assets taken were ETH, QNT, GALA, SHIB, HOT and MATIC. Bitrue said the affected wallet held less than 5 percent of its total funds and that its remaining wallets were not compromised. It suspended all withdrawals to run additional security checks and said they would reopen on 18 April 2023. The exchange committed to compensating affected users in full.
Bitrue has never published a technical explanation of how the wallet was compromised. Its public statements describe the outcome rather than the mechanism, and no post-mortem followed. The $23 million figure originates with Bitrue itself and has not been independently disputed; it was reported consistently by CoinDesk, The Block and Cointelegraph on the day, all citing the exchange's own statement.
No suspect has been publicly identified, no arrests have been reported, and the funds have not been recovered. This was not Bitrue's first hot wallet breach; the exchange lost nearly $5 million in Cardano in a 2019 hot wallet hack.
Sources
- BitruePrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Bitrue hack — April 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bitruehttps://itokenly.com/hacks/bitruePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.