T
iTokenly

Bitrue hack — April 2023

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedApril 14, 2023
Target typeCentralised exchange
Loss$23,000,000Price at time of incident
MethodOther or undisclosedOne of Bitrue's hot wallets was drained of six ERC-20 assets in a single incident. Bitrue described it only as a brief exploit of that wallet and never disclosed the mechanism; no post-mortem was published and no independent analysis has established the root cause.
ChainsEthereum
OutcomeUsers reimbursed

What happened

At 07:18 UTC on 14 April 2023 an attacker withdrew about $23 million of assets from a hot wallet belonging to Bitrue, a centralised cryptocurrency exchange. Bitrue disclosed the incident the same day, describing it as a brief exploit of one of its hot wallets and saying it had acted quickly enough to prevent further losses.

The assets taken were ETH, QNT, GALA, SHIB, HOT and MATIC. Bitrue said the affected wallet held less than 5 percent of its total funds and that its remaining wallets were not compromised. It suspended all withdrawals to run additional security checks and said they would reopen on 18 April 2023. The exchange committed to compensating affected users in full.

Bitrue has never published a technical explanation of how the wallet was compromised. Its public statements describe the outcome rather than the mechanism, and no post-mortem followed. The $23 million figure originates with Bitrue itself and has not been independently disputed; it was reported consistently by CoinDesk, The Block and Cointelegraph on the day, all citing the exchange's own statement.

No suspect has been publicly identified, no arrests have been reported, and the funds have not been recovered. This was not Bitrue's first hot wallet breach; the exchange lost nearly $5 million in Cardano in a 2019 hot wallet hack.

Sources

  1. BitruePrimary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. The BlockSecondary · retrieved 2026-08-01
  4. CointelegraphSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Bitrue hack — April 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bitrue
https://itokenly.com/hacks/bitrue

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.