T
iTokenly

WOO X hack — July 2025

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJuly 24, 2025
Target typeCentralised exchange
Loss$14,000,000Price at time of incident
MethodSocial engineeringWOO X's post-mortem describes a three-stage intrusion. On 28 June 2025 an outsider posing as a collaborator on an open-source development forum asked a WOO developer for help debugging a tool. On 8 July the developer downloaded the file on a mobile device and transferred it to a company MacBook via AirDrop; a malware scan came back negative, but the program installed a hidden backdoor that resembled a common backend process. The attacker deployed a backdoor in a production microservice pod for persistent access, escalated privileges within the Kubernetes environment and reached a database. On 24 July the attacker issued unauthorised withdrawal requests against nine customer accounts over roughly two hours. WOO X publicly characterised the breach as not having compromised its core infrastructure, though its own post-mortem describes persistence in the production environment and it subsequently migrated its entire production infrastructure.
ChainsBitcoin, Ethereum, BNB Chain, Arbitrum
OutcomeUsers reimbursed

What happened

WOO X, the centralised exchange operated by WOO, lost $14 million from nine customer accounts on 24 July 2025. The first unauthorised withdrawal went out at 13:50 UTC+8 and the exchange contained the incident by roughly 15:40, a window of about two hours.

The entry point was a developer rather than a wallet, and the intrusion began almost a month before the theft. According to WOO X's post-mortem, an outsider posing as a collaborator on an open-source forum approached a WOO developer on 28 June asking for help debugging a development tool. On 8 July the developer downloaded the file on a phone and moved it to a company MacBook by AirDrop. Malware scanning came back negative, but the program installed a hidden backdoor disguised as an ordinary backend process. The attacker deployed a backdoor in a production microservice pod for persistent access, escalated privileges inside the Kubernetes environment and reached a database. WOO X publicly said its core infrastructure was not compromised and that losses were confined to nine high-value accounts; its own post-mortem, which describes persistence in the production environment and a subsequent migration of the entire production infrastructure, sits awkwardly with that characterisation.

Funds moved across Bitcoin, Ethereum, BNB Chain and Arbitrum. The security firm Cyvers Alerts flagged more than $12 million of suspicious transactions while the incident was still in progress, including about $1 million in Tether leaving a WOO X hot wallet, with later conversions into BTCB and BNB. WOO X suspended withdrawals platform-wide, published six attacker addresses and engaged outside security firms.

All nine affected users were made whole from WOO's treasury. Published remediation included rebuilding production cloud infrastructure, isolating the development environment under a zero-trust model, shortening cloud session lifetimes from 24 to 8 hours and adding container-level threat detection. No actor has been publicly named.

Sources

  1. WOO XPrimary · retrieved 2026-08-01
  2. HalbornSecondary · retrieved 2026-08-01
  3. DeFi PlanetSecondary · retrieved 2026-08-01

Official post-mortem: https://woox.io/blog/july-24th-security-incident-post-mortem

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "WOO X hack — July 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/woo-x
https://itokenly.com/hacks/woo-x

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.