HTX and Heco Bridge hack — November 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | November 22, 2023 |
| Target type | Cross-chain bridge |
| Loss | $113,300,000Published estimates range $113,300,000 to $115,400,000Price at time of incident |
| Method | Private key compromiseThe operator key for the Heco Bridge, which links Ethereum to the Heco chain, was compromised, letting the attacker call the bridge's withdrawToken function, which only the operator address can invoke, and drain bridge-held assets on Ethereum. Hot wallets belonging to the affiliated HTX exchange were emptied in the same operation across Ethereum, Tron and Bitcoin. |
| Chains | Ethereum, Tron, Bitcoin |
| Outcome | Unresolved |
What happened
On 22 November 2023 the operator key controlling the Heco Bridge, the cross-chain bridge linking Ethereum to the Heco chain, was compromised, and hot wallets at the HTX exchange, formerly Huobi, were drained in the same operation. Both are associated with Justin Sun. CertiK's analysis found the attacker called the bridge's withdrawToken function, which only the operator address can invoke, and moved about $87 million out of the bridge on Ethereum: 10,145 ETH, 42.11 million USDT, 489 HBTC, 173,200 UNI, 42,399 LINK, 619,000 USDC, 346,994 TUSD and a large SHIB position. HTX's own wallets lost about $13.6 million on Ethereum and about $12.6 million on Tron, plus roughly 74 BTC.
HTX said in a statement that assets worth about $30 million in its hot wallet were affected, that it had temporarily suspended deposit and withdrawal services on both the HTX platform and the Heco Chain gateway, and that it would fully compensate for any losses incurred due to the hot wallet attack. Services were restored over the following days.
Reported totals for the combined event differ modestly. CertiK put it at about $113.3 million. CNBC's figure of about $115 million combined HTX's own $30 million with CryptoQuant's estimate that $85.4 million was taken from Heco, largely in USDT and ether. A CryptoQuant analyst told CNBC the attacker was converting into ether because USDT and USDC can be frozen by their issuers.
The exchange and bridge losses were one operation and are recorded here as a single incident. No funds were returned, no arrests have been reported, and neither HTX nor CertiK attributed the compromise to a named actor.
Law enforcement
No arrests reported.
Sources
- HTXPrimary · retrieved 2026-08-01
- CNBCSecondary · retrieved 2026-08-01
- CertiKSecondary · retrieved 2026-08-01
Official post-mortem: https://www.htx.com/support/104954980569005
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "HTX and Heco Bridge hack — November 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/htx-heco-bridgehttps://itokenly.com/hacks/htx-heco-bridgePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.