T
iTokenly

OlaXBT hack — September 2025

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedSeptember 1, 2025
Target typeToken contract
Loss$2,000,000Price at time of incident
MethodOther or undisclosedUndisclosed. Roughly 32 million AIO tokens were withdrawn without authorisation from multisig wallets controlled by the project, moved to a single address and sold on-chain. No root cause was ever published: OlaXBT said only that a 'wallet vulnerability' had been resolved and that it had found 'evidence of coordinated unauthorized access', and neither CertiK nor HashDit stated whether signing keys were stolen, a signer device was compromised, or a signer acted deliberately. Classified as undisclosed rather than as key compromise because no source establishes how the signers were defeated.
ChainsBNB Chain
OutcomeUnresolved

What happened

On 1 September 2025 roughly 32 million AIO tokens were withdrawn without authorisation from multisig wallets controlled by OlaXBT, a BNB Chain project marketing an AI trading agent built around the Model Context Protocol. The tokens were moved to a single address, and sold on-chain. Two blockchain security firms flagged the movement separately the same day. CertiK reported the withdrawals from the multisigs to that address and the subsequent sales, putting the value at over $2 million. HashDit said the project had been compromised, that AIO had been drained from the multisig wallets and sold on-chain, and that proceeds worth at least $2 million were sent to accounts at KuCoin and Bitget. Both figures are floors rather than reconciled accounting, and no party has published a final total. OlaXBT confirmed the unauthorised withdrawals in a statement the same day and said it was preparing a compensation plan for verified holders who held AIO before the incident. It subsequently announced a swap to a new token contract at a 1:1 ratio, and Gate suspended AIO deposits and withdrawals while it supported the swap. The mechanism behind the multisig withdrawals remains undisclosed. Descriptions of the incident as a social-engineering attack circulate but are not supported by any statement from the project or from CertiK or HashDit. No funds have been reported recovered, no arrests have been announced, and there is no public confirmation that the compensation plan was completed.

Law enforcement

OlaXBT said on 1 September 2025 that it was coordinating with global law enforcement agencies. No agency, case or arrest has been publicly identified.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Attacker addresses

  • 0xec75a0bb45a07f6e23760c7fe8fcb2408a74348c

Sources

  1. The Crypto Times (reporting CertiK's alert)Secondary · retrieved 2026-08-01
  2. HashDit (published via Binance Square)Secondary · retrieved 2026-08-01
  3. OlaXBTPrimary · retrieved 2026-08-01
  4. GatePrimary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "OlaXBT hack — September 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/olaxbt
https://itokenly.com/hacks/olaxbt

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.