Crypto exchange BigONE has suffered a $27 million loss after a sophisticated third-party supply chain attack compromised its hot wallet infrastructure. Detected on July 16 via real-time monitoring alerts, the breach allowed attackers to modify server logic and bypass risk controls, triggering unauthorized withdrawals across Bitcoin, Ethereum, Tron, Solana and other chains.
Key Takeaways
-
Attack targeted BigONE’s production network via compromised CI/CD or server channels.
-
Attackers modified account and risk control logic to approve unlimited withdrawals.
-
Approximately 120 BTC, 350 ETH, 7.1 million USDT and other tokens were stolen.
-
BigONE activated internal reserves (BTC, ETH, USDT, SOL, XIN) and will borrow liquidity for niche tokens.
-
Deposits and trading have resumed; withdrawals remain paused pending security upgrades.
-
Exchange is working with SlowMist and Cyvers on fund tracing and recovery.
Details Of The Supply Chain Attack
Security firms SlowMist and Cyvers traced the intrusion to malicious binaries deployed to account-operation servers. By tampering with business logic and disabling risk-control checks, the attacker bypassed hot wallet approval processes without accessing private keys.
Key exploit points:
-
Compromised CI/CD or server management channels.
-
Injection of unauthorized withdrawal logic into production servers.
-
Large-scale draining across multiple blockchains.
-
Consolidation of stolen assets into a single external address for laundering.
Stolen Assets
Token
Quantity
Approx. USD Value
Bitcoin (BTC)
120
$14.2 million
Ether (ETH)
350
$1.1 million
USDT
7.1 million
–
SHIB
9.5 billion
–
DOGE
538,000
–
SOL
1,800
–
TRX
23.3 million
$7.0 million
CELR
15.7 million
–
UNI
25,487
–
LEO
16,071
–
XIN
20,730
–
BigONE's Response And Compensation Plan
BigONE has assured users that private keys remain secure and all losses will be fully covered:
-
Internal security reserves (BTC, ETH, USDT, SOL, XIN) were deployed immediately.
-
External borrowing mechanisms are being used to restore liquidity for affected non-mainstream tokens.
-
Deposits and trading resumed within hours; withdrawals will reopen after enhanced security controls.
-
Investigation progress and recovery efforts will be communicated with full transparency.
Industry Context And Security Lessons
This incident marks another major breach in 2025, with crypto losses topping $2.47 billion in hacks and scams during the first half of the year. Experts urge exchanges to:
-
Harden CI/CD pipelines and enforce strict dependency controls.
-
Implement continuous on-chain and off-chain monitoring.
-
Adopt automated incident response to halt unauthorized activity.
-
Segregate build environments from wallet-management systems.
As the attack demonstrates, third-party vulnerabilities can pose systemic risks to centralized exchanges. Ongoing vigilance and robust infrastructure safeguards remain essential for protecting user assets in the rapidly evolving crypto landscape.
Sources
-
BigONE Loses $27M in Hot Wallet Hack, Commits to User Compensation, Cointelegraph.
-
Crypto Exchange BigONE Confirms $27M Hack, Vows Full User Compensation, CoinDesk.
-
BigONE Suffers $27 Million Loss in Supply Chain Attack, AInvest.
-
BigONE Suffers Supply Chain Attack, Losses Exceed $27M, Cryptonews.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.