Top

Hot Wallet Exploit Results in $23M Bitrue Loss

Web3 & Enterprise·April 19, 2023, 3:34 AM

Bitrue, a Singapore-based crypto exchange, has fallen prey to a $23 million hack due to a hot wallet exploit. The exchange has been forced to suspend all withdrawals until April 18, to provide an opportunity to conduct a thorough security review.

wallet with 20 USD bills in cash
©Pexels/Karolina Grabowska

 

Hot wallet vulnerability

Hot wallets are used by exchanges to store small amounts of cryptocurrencies for easy access. These wallets are connected to the internet and are therefore more vulnerable to attacks compared to cold wallets, which are stored offline. In the case of Bitrue, hackers were able to exploit the hot wallet and steal cryptocurrencies worth $23 million.

In a series of Twitter posts, the exchange outlined that the exploit occurred at 07:18 (UTC) on Friday. “We were able to address the matter quickly and prevented the further exploit of funds”, it went on to state.

The stolen digital assets include ETH, QNT, GALA, SHIB, HOT and MATIC. Bitrue outlined that the hot wallet funds account for only 5% of overall funds and that the rest of its wallets remain secure and have not been compromised.

Blockchain security firm PeckShield outlined how the funds were swapped and drained. A wallet it has labeled as “Bitrue drainer” swapped 173,000 QNT, 22.55 billion SHIB tokens, 46.4 million GALA and 310,000 MATIC for 8,540 ETH. The ether is now being held within the following address:

0x1819EDe3B8411EbC613F3603813Bf42aE09bA5A5

 

Reimbursing users

In response to the hack, Bitrue has promised to reimburse all affected users. However, the process could take some time.

The incident underscores the importance of taking precautions when storing cryptocurrencies on exchanges. Users should only keep a minimal amount of cryptocurrencies on an exchange and should not store more than they can afford to lose. Ongoing exploits, hacks and frauds exemplify the need for users to only use reputable platforms with a proven track record of security.

 

Doubling down on security

Bitrue has promised to improve its security measures to prevent similar incidents from occurring in the future. The exchange’s response to the hack has been lauded by many in the cryptocurrency community, who have praised the company’s transparency and commitment to reimbursing affected users.

The cryptocurrency community has been vocal in its criticism of exchanges that fail to prioritize security. The Bitrue hack is just the latest in a series of incidents that have highlighted the importance of maintaining security in the world of cryptocurrency.

It’s not the first security breach that the exchange has encountered. In 2019 Bitrue suffered a $4.7 million loss, with quantities of both XRP and Cardano (ADA) having been stolen. On that occasion, the exchange released tracking details relative to the stolen funds. Thanks to collaboration with Huobi, Bittrex and ChangeNOW, the funds and associated accounts were frozen.

According to data from CoinGecko, Bitrue trades an average of $1 billion in digital assets daily, with bitcoin and ether trading pairs accounting for a large proportion of that trading volume. The Bitrue hack has been a wake-up call for the cryptocurrency community and serves as a reminder of the ongoing risks associated with storing cryptocurrencies on exchanges.

More to Read
View All
Policy & Regulation·

Apr 11, 2025

Standard Chartered & OKX partner on collateral mirroring program in Dubai

British multinational banking conglomerate Standard Chartered has partnered with global crypto exchange OKX in Dubai on a collateral mirroring pilot program.Photo by appshunter.io on UnsplashOff-chain collateralIn a press release published on April 10, the companies set out details of the collaboration. The initiative will facilitate institutional clients to utilize digital assets and tokenized money market funds for trading as off-chain collateral. Trading activity requires the ongoing movement of funds and assets between custodians and exchange platforms. The activity is expensive and slow. Back in 2023, OKX had collaborated with crypto custodian Komainu and asset manager CoinShares to enable collateral mirroring to overcome this operational inefficiency. In that instance, CoinShares was enabled to trade on OKX using a collateral mirroring facility provided by OKX with Komainu acting as asset custodian. This latest initiative has also seen OKX work with alternative investment management firm Brevan Howard, global investment management company Franklin Templeton and local regulator in Dubai, the Virtual Assets Regulatory Authority (VARA).  Developed within regulatory frameworkThe collateral mirroring facility has been established on a pilot program basis to start with, having been developed within the regulatory framework established in Dubai by VARA. Standard Chartered will act as the digital asset custodian as part of the arrangement.  The press release points out that Standard Chartered is a Globally Systemically Important Bank (G-SIB), asserting that this will afford clients a higher level of security. By not having to manually move the digital assets, there is an additional security-related process improvement, given the ongoing risks associated with digital assets held on exchanges due to incidents of hacking. Hong Fang, OKX president, provided some insight into why the company has partnered with Standard Chartered, stating:”By leveraging Standard Chartered's position as a top custodian globally, as well as OKX's market leadership in cryptocurrency trading, the partnership sets an industry standard for current and potential institutional clients to deploy trading capital at scale in a trusted environment." OKX CEO Star Xu outlined on X that the service offering is geared towards tokenized money market funds with the aim of improving capital efficiency and counterparty risk protection. Standard Chartered launched its crypto custody services in Dubai last September. The service was established in partnership with Brevan Howard Digital, having been licensed by the Dubai Financial Services Authority (DFSA), the independent regulator for financial service providers located within the Dubai International Financial Centre (DIFC), an economic free zone. In October 2024, OKX selected Standard Chartered as its digital asset custodian for the crypto exchange platform’s institutional clients. First clientsBrevan Howard Digital and Franklin Templeton will participate as the first clients to trial the new service offering. Furthermore, as part of the collaboration, OKX platform users will gain access to tokenized on-chain assets developed and offered by Franklin Templeton. Franklin Templeton’s head of digital assets, Roger Bayston, commented on the firm’s on-chain product offering, stating: “By ensuring assets are minted on-chain, we enable true ownership, allowing them to move and settle at blockchain speed – eliminating the need for traditional infrastructure.”

news
Policy & Regulation·

Oct 20, 2023

US Treasury Sanctions Gaza-Based Crypto Operator

US Treasury Sanctions Gaza-Based Crypto OperatorThe Office of Foreign Assets Control (OFAC) of the United States Department of the Treasury has imposed sanctions on a crypto operator allegedly linked to the Palestinian militant group Hamas.The move by OFAC comes as a result of greater scrutiny of terrorist financing following an attack by Hamas on Israel in early October, in which a number of Israelis lost their lives.Photo by Karolina Grabowska on Pexels“Buy Cash Money and Money Transfer Company”The entity targeted by these sanctions is a Gaza-based virtual currency exchange known as the “Buy Cash Money and Money Transfer Company.” It is operated by Khan Yunis, a resident of Gaza. According to the Treasury Department, both the exchange and Khan Yunis are alleged to have ties to Hamas. Ahmed M.M. Alaqad, the owner of the business, has also been named in the sanctions.The primary objective of these sanctions, as stated by the Treasury Department, is to disrupt the sources of revenue for Hamas. The attack on Israel served as a trigger for these actions. Treasury Secretary Janet Yellen emphasized the determination to prevent Hamas from raising funds for further acts of terror and violence against the people of Israel.This includes imposing sanctions and cooperating with international allies and partners to identify, freeze, and seize any assets related to Hamas in their respective jurisdictions. Yellen stated:“The United States is taking swift and decisive action to target Hamas’s financiers and facilitators following its brutal and unconscionable massacre of Israeli civilians, including children.”Crypto sector riskIt’s not the first time that crypto platforms have been implicated where terrorist financing is concerned. Earlier this year it emerged that Bitfinex Turkiye, the Turkish local exchange business of global crypto platform Bitfinex, was alleged to have been used for the purposes of money laundering by Hamas. Additionally, leading crypto platform Binance has found itself facing similar allegations.In the immediate aftermath of the recent attack, Israeli authorities moved to close down accounts they claimed were linked with Hamas on crypto platforms like Binance and elsewhere. The Israelis have continued where they left off in this respect, with a report emerging earlier this week that over one hundred accounts on Binance have been ordered to be shut down, with a further two hundred accounts facing scrutiny.While crypto may not account for a sizable proportion of terrorist financing means, these events open up a point of attack for those who oppose the further roll-out of decentralized money and systems.Fighting illicit finance through sanctionsNotably, the US Treasury has been employing sanctions as a tool to cut off financial support to entities suspected of being involved in terrorism or other illicit activities. In a similar vein, earlier in October, the Treasury announced sanctions against crypto wallets associated with Chinese chemical manufacturers, concurrently with an indictment from the Department of Justice related to the production of the drug fentanyl.Earlier this year, blockchain analytics firm Elliptic indicated that most Chinese suppliers of fentanyl precursors were accepting payments for the illicit material in cryptocurrency.It’s worth mentioning that this move by OFAC not only targets Hamas but also includes other entities allegedly connected to the Buy Cash Money and Money Transfer Company, including an al-Qaeda affiliate and the Islamic State of Iraq and Syria (ISIS).

news
Policy & Regulation·

Mar 07, 2024

Busan at risk of losing its status as blockchain regulation-free zone

Nearly five years have passed since South Korea’s second-largest city Busan was designated as a blockchain regulation-free zone (blockchain zone) in July 2019. This designation has allowed blockchain companies to run their businesses within the region’s regulatory sandbox, freely exploring the potential of the cutting-edge industry. Busan is the only city in Korea to have won the bid for running more than two regulation-free blockchain projects approved by the SME ministry. However, Busan city may soon lose its status as the blockchain zone, unless it develops and attracts new blockchain-related businesses, local news media KBS News reported. The city has been struggling to attract new blockchain businesses after its 10-month-long preparation to enact a law, which would have enabled startups to enroll in indemnity insurance, resulted in failure.  Photo by Alexander Smagin on UnsplashBlockchain startups on the brink of closing its services Among the blockchain companies operating in the blockchain zone is Busan Blockchain Real-estate Investment Currency (BBRIC), which allows users to invest in real estate with a budget as small as KRW 1,000 ($0.75). Park Hyo-jin, Vice CEO of Sejong Telecom operating BBRIC, expressed his concerns in an interview with KBS News, saying that the termination of the city’s status as the blockchain zone would make it difficult for BBRIC to continue its services. Another blockchain startup in the region’s blockchain zone emphasized the importance of maintaining the city’s status in an interview with the press. Kim Yong-gil, the chief research officer at a blockchain-driven solution firm, said the company he’s working for was able to lay the foundation for its business growth after it was selected as one of the first companies to operate within the blockchain zone in 2019. The company currently aims to expand its distribution business from fisheries to coffee industry.  At the moment, 43 blockchain companies like these are operating their offices at the Busan International Finance Center (BIFC). Among 15 of them have relocated to Busan from the outside region to benefit from the sandbox. Busan’s loss of its status would also result in these companies leaving.  Busan’s desperate bid to retain its status as blockchain zone To retain the blockchain startups, the Busan government must maintain its status as the blockchain zone by getting permission to extend the designation period. Kwon Ki-kwang, Head of the Blockchain Regulation-free Zone team at Busan Technopark – a public foundation that supports SMEs – stated that it is looking for businesses specialized in blockchain technology, including those focused on blockchain-driven voting systems.  

news
Loading