OlaXBT hack — September 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 1, 2025 |
| Target type | Token contract |
| Loss | $2,000,000Price at time of incident |
| Method | Other or undisclosedUndisclosed. Roughly 32 million AIO tokens were withdrawn without authorisation from multisig wallets controlled by the project, moved to a single address and sold on-chain. No root cause was ever published: OlaXBT said only that a 'wallet vulnerability' had been resolved and that it had found 'evidence of coordinated unauthorized access', and neither CertiK nor HashDit stated whether signing keys were stolen, a signer device was compromised, or a signer acted deliberately. Classified as undisclosed rather than as key compromise because no source establishes how the signers were defeated. |
| Chains | BNB Chain |
| Outcome | Unresolved |
What happened
On 1 September 2025 roughly 32 million AIO tokens were withdrawn without authorisation from multisig wallets controlled by OlaXBT, a BNB Chain project marketing an AI trading agent built around the Model Context Protocol. The tokens were moved to a single address, and sold on-chain. Two blockchain security firms flagged the movement separately the same day. CertiK reported the withdrawals from the multisigs to that address and the subsequent sales, putting the value at over $2 million. HashDit said the project had been compromised, that AIO had been drained from the multisig wallets and sold on-chain, and that proceeds worth at least $2 million were sent to accounts at KuCoin and Bitget. Both figures are floors rather than reconciled accounting, and no party has published a final total. OlaXBT confirmed the unauthorised withdrawals in a statement the same day and said it was preparing a compensation plan for verified holders who held AIO before the incident. It subsequently announced a swap to a new token contract at a 1:1 ratio, and Gate suspended AIO deposits and withdrawals while it supported the swap. The mechanism behind the multisig withdrawals remains undisclosed. Descriptions of the incident as a social-engineering attack circulate but are not supported by any statement from the project or from CertiK or HashDit. No funds have been reported recovered, no arrests have been announced, and there is no public confirmation that the compensation plan was completed.
Law enforcement
OlaXBT said on 1 September 2025 that it was coordinating with global law enforcement agencies. No agency, case or arrest has been publicly identified.
On-chain references
Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.
Attacker addresses
- 0xec75a0bb45a07f6e23760c7fe8fcb2408a74348c
Sources
- The Crypto Times (reporting CertiK's alert)Secondary · retrieved 2026-08-01
- HashDit (published via Binance Square)Secondary · retrieved 2026-08-01
- OlaXBTPrimary · retrieved 2026-08-01
- GatePrimary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "OlaXBT hack — September 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/olaxbthttps://itokenly.com/hacks/olaxbtPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.