T
iTokenly

Kronos Research hack — November 2023

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedNovember 19, 2023
Target typeOther
Loss$26,000,000Published estimates range $25,000,000 to $26,000,000Price at time of incident
MethodInfrastructure compromiseCompromise of Kronos Research's exchange API keys, which are trading credentials held at centralised venues rather than on-chain wallet keys. CertiK's analysis found the attacker used them to withdraw roughly 22.9 million USDT from Binance over about three hours, beginning with a 72 USDT test transaction at 16:47 UTC on 18 November 2023, and also reached roughly $2 million in WOO tokens, $107,000 in WBNB and $82,000 in BNB on BNB Chain. Proceeds were consolidated into ether and split across six Ethereum wallets. Kronos never disclosed how the keys were obtained.
ChainsEthereum, BNB Chain
OutcomeUnresolved

What happened

Kronos Research is a Taipei-based quantitative trading and market-making firm. On 18 November 2023 an attacker who had obtained some of the firm's exchange API keys used them to move funds out of its trading accounts. Kronos disclosed the breach on X the following day, saying unauthorised access to its API keys had occurred and that it had suspended trading while it investigated.

CertiK's analysis put the loss at 13,008 ETH, approximately $26 million, consolidated on Ethereum and split across six wallets. It traced the activity to withdrawals totalling 22,899,712 USDT from Binance over about three hours, starting with a 72 USDT test transaction at 16:47 UTC that CertiK read as the attacker confirming control, and found the attacker also reached about $2 million in WOO tokens plus roughly $107,000 in WBNB and $82,000 in BNB on BNB Chain. The independent investigator ZachXBT, who mapped the outflows separately, estimated over $25 million. Kronos itself put the figure at approximately $26 million, the number recorded here.

The credentials involved were API keys issued by trading venues, not blockchain private keys, so the attacker never needed control of a wallet: the withdrawals were authorised by the exchanges as though Kronos had requested them. Kronos has not published a technical account of how the keys were taken.

The firm said the potential loss was "not a significant portion of our equity", that all losses would be covered internally and that no partners would be affected. It paused trading, audited its systems and later resumed spot and perpetual trading and withdrawals. No funds have been publicly reported as recovered, no arrests have been announced, and no named source has attributed the theft to a specific actor.

Sources

  1. CertiKSecondary · retrieved 2026-08-01
  2. The Record (Recorded Future News)Secondary · retrieved 2026-08-01
  3. The BlockSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Kronos Research hack — November 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/kronos-research
https://itokenly.com/hacks/kronos-research

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.