T
iTokenly

HTX and Heco Bridge hack — November 2023

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedNovember 22, 2023
Target typeCross-chain bridge
Loss$113,300,000Published estimates range $113,300,000 to $115,400,000Price at time of incident
MethodPrivate key compromiseThe operator key for the Heco Bridge, which links Ethereum to the Heco chain, was compromised, letting the attacker call the bridge's withdrawToken function, which only the operator address can invoke, and drain bridge-held assets on Ethereum. Hot wallets belonging to the affiliated HTX exchange were emptied in the same operation across Ethereum, Tron and Bitcoin.
ChainsEthereum, Tron, Bitcoin
OutcomeUnresolved

What happened

On 22 November 2023 the operator key controlling the Heco Bridge, the cross-chain bridge linking Ethereum to the Heco chain, was compromised, and hot wallets at the HTX exchange, formerly Huobi, were drained in the same operation. Both are associated with Justin Sun. CertiK's analysis found the attacker called the bridge's withdrawToken function, which only the operator address can invoke, and moved about $87 million out of the bridge on Ethereum: 10,145 ETH, 42.11 million USDT, 489 HBTC, 173,200 UNI, 42,399 LINK, 619,000 USDC, 346,994 TUSD and a large SHIB position. HTX's own wallets lost about $13.6 million on Ethereum and about $12.6 million on Tron, plus roughly 74 BTC.

HTX said in a statement that assets worth about $30 million in its hot wallet were affected, that it had temporarily suspended deposit and withdrawal services on both the HTX platform and the Heco Chain gateway, and that it would fully compensate for any losses incurred due to the hot wallet attack. Services were restored over the following days.

Reported totals for the combined event differ modestly. CertiK put it at about $113.3 million. CNBC's figure of about $115 million combined HTX's own $30 million with CryptoQuant's estimate that $85.4 million was taken from Heco, largely in USDT and ether. A CryptoQuant analyst told CNBC the attacker was converting into ether because USDT and USDC can be frozen by their issuers.

The exchange and bridge losses were one operation and are recorded here as a single incident. No funds were returned, no arrests have been reported, and neither HTX nor CertiK attributed the compromise to a named actor.

Law enforcement

No arrests reported.

Sources

  1. HTXPrimary · retrieved 2026-08-01
  2. CNBCSecondary · retrieved 2026-08-01
  3. CertiKSecondary · retrieved 2026-08-01

Official post-mortem: https://www.htx.com/support/104954980569005

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "HTX and Heco Bridge hack — November 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/htx-heco-bridge
https://itokenly.com/hacks/htx-heco-bridge

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.