Crypto Exchange BigONE Hit with $27M Loss in Hot Wallet Hack

By: crypto insight|2025/08/28 03:40:01
分享
copy

Imagine your digital wallet suddenly springing a leak, draining funds faster than a faulty ATM— that’s the nightmare scenario that unfolded for crypto exchange BigONE, where a sneaky third-party attack siphoned off around $27 million from its hot wallet setup. This incident underscores how even established platforms can face vulnerabilities, much like a fortress with a hidden back door.

BigONE, a prominent crypto exchange, has officially acknowledged a major security breach stemming from a third-party assault on its hot wallet systems, leading to losses estimated at about $27 million. The trouble came to light on July 16 when unusual asset transfers set off the platform’s real-time monitoring alarms. After digging deeper, the team pinpointed the issue to an external attack aimed squarely at their hot wallet. Fortunately, all private keys stayed safe, and they’ve since pinpointed and sealed off the vulnerability to stop any more damage. Teaming up with blockchain security experts at SlowMist, BigONE is now tracking the hacker’s wallet addresses and following the trail of the pilfered funds. The stolen assets include 120 Bitcoin (BTC), 350 Ether (ETH), millions in USDt (USDT) on multiple chains, plus hefty sums of CELR, SNT, SHIB, and other tokens. BigONE is working hand-in-hand with SlowMist to claw back whatever they can.

BigONE Commits to Fully Reimbursing Users After Breach

In a move that rebuilds trust like a safety net catching a falling acrobat, BigONE has vowed to absorb every bit of the loss, ensuring no user feels the pinch. They’ve dipped into their own security reserves—packed with BTC, ETH, USDt, Solana (SOL), and Mixin (XIN)—to refill affected accounts right away. For the mix of mainstream and niche tokens hit hard, the exchange is lining up external loans to boost liquidity and get the platform’s wallets back on track swiftly.

Insights from blockchain security firm Cyvers reveal the attacker infiltrated the exchange’s production network, probably via weak spots in CI/CD pipelines or server controls, tweaking core operations and bypassing vital safety checks. It kicked off with rogue software planted on key servers, followed by an unauthorized pull of 350 ETH worth $1.1 million. The thief then ramped up, hitting Bitcoin, Solana, and Tron networks, funneling everything into one outside address for cleaning. To dodge these threats, experts like Yehor Rudytsia from Hacken emphasize beefing up CI/CD defenses, vetting dependencies rigorously, and running non-stop monitoring both on and off the chain. He stresses that automated incident responses are essential, acting like an emergency brake to limit damage and safeguard funds— a lesson backed by real-world cases where quick action has saved millions.

Tracing the Stolen Crypto: Funds Funneled into WETH

The pilfered assets got swapped into WETH/ETH and shuffled through new middlemen, hinting at plans for mixing services or DEX trades, as per Cyvers’ analysis. They spotlighted flaws like over-reliance on a single hot wallet point, skimpy code checks, missing pre-transfer verifications, and poor separation between build and wallet servers— vulnerabilities that hackers exploit like cracks in a dam.

This BigONE breach follows hot on the heels of the Arcadia Finance DeFi hack on the Base blockchain, where $3.5 million vanished just a day prior. Zooming out, crypto losses from hacks, scams, and exploits have surged in 2025. As of August 2025, total damages have topped $3.1 billion, a stark 29% jump from the $2.4 billion recorded in 2024, according to data from firms like Chainalysis and Certik, driven by increasingly sophisticated attacks amid booming market activity.

Recent buzz on Twitter highlights growing concerns over exchange security, with users debating hot wallet risks versus cold storage benefits— posts from influencers like @CryptoWhale amassing thousands of retweets on the need for multi-signature setups. Google searches spike for queries like “how to secure crypto wallets” and “best exchanges after hacks,” reflecting widespread anxiety. Latest updates include BigONE’s August 2025 announcement of enhanced audits, and a Twitter thread from SlowMist detailing frozen portions of the stolen funds on certain chains, potentially aiding recovery.

In this volatile landscape, platforms that prioritize ironclad security stand out, much like a fortified vault in a sea of safes. Take WEEX exchange, for instance— it’s earning praise for its robust multi-layer defenses, including advanced AI-driven monitoring and segregated cold storage that keeps the bulk of assets offline and safe from hot wallet threats. By aligning with top-tier security standards and offering seamless, user-friendly trading without compromising on protection, WEEX builds credibility as a reliable choice for traders seeking peace of mind, backed by zero major breaches in its history and partnerships with leading auditors.

Echoes of Past Hacks and Lessons Learned

Drawing parallels, this incident echoes the $40 million GMX exploit where the hacker surprisingly returned the funds, showing that not all breaches end in total loss— a rare positive twist that highlights the value of negotiation and tracking tech. Yet, the BigONE case drives home the crypto crime wave fueled by FOMO and loose regulations, creating a supercycle of vulnerabilities. It’s like comparing a neighborhood watch to a high-tech alarm system; while basic monitoring helps, comprehensive strategies prevent disasters.

The event also ties into broader discussions on legal protections, where hacks reveal gaps in recourse— think of it as discovering your insurance policy has fine print excluding digital theft. Strengthening these areas could mirror how traditional finance evolved with FDIC safeguards, potentially stabilizing crypto’s wild ride.

FAQ

What caused the BigONE crypto exchange hack?
The breach stemmed from a third-party attack exploiting vulnerabilities in the hot wallet infrastructure, likely through compromised CI/CD pipelines, allowing unauthorized asset drains without compromising private keys.

How is BigONE handlingECON (B0)
BigONE has pledged to cover all losses using internal reserves and external borrowing, aiming to fully reimburse users and restore platform liquidity swiftly.

What steps can users take to protect their crypto assets after such incidents?**
Enable two-factor authentication, use hardware wallets for long-term storage, diversify across secure exchanges, and stay informed on platform security updates to minimize risks in this volatile space.

猜你喜歡

Trust Wallet 遭黑客攻擊最大損失達350萬美元

Key Takeaways 最大受害者損失了約350萬美元,該錢包已休眠一年。 第二大損失達140萬美元,該錢包已休眠兩年以上。 黑客共竊取超過600萬美元加密資產,其中超過400萬美元已轉移至CEX。 自托管錢包面臨基礎設施漏洞的潛在風險。 WEEX Crypto News, 26 December 2025 近期,Trust Wallet 發生了一起嚴重的黑客事件,此次事件引發了業界廣泛關注。在這起事件中,Trust Wallet的一個錢包損失了價值高達350萬美元的加密資產,該錢包在此次攻擊前已經休眠了一年多。此外,另一個損失較大的錢包也損失了約140萬美元,在攻擊發生前已經休眠超過兩年。 Trust Wallet…

12月26日市場關鍵情報,你錯過了多少?

1. 鏈上資金:本日有 7.8 百萬美元流入 Hyperliquid;5.5 百萬美元流出 Solana 2. 最大漲跌幅:$ISLM、$FTN 3. 熱門新聞:Trust Wallet 將確保所有受影響的用戶都能獲得退款,用戶需盡快完成程序升級

加密聖誕劫:損失超600萬美元,Trust Wallet 擴展錢包遭駭分析

Trust Wallet 瀏覽器擴充功能 2.68 版被發現存在惡意後門,導致用戶資金被盜,總損失超過 600 萬美元。

聯儲局2026年第一季度展望:比特幣和加密市場的潛在影響

關鍵要點 聯儲局暫停利率降息可能對加密貨幣市場施壓,但“隱形量化寬鬆”或許能緩解下行風險。 流動性比降息更加重要,將在2026年第一季度塑造比特幣和以太坊的走向。 若持續通脹壓力,BTC或跌至70,000美元,ETH可能降至2,400美元。 “隱形量化寬鬆”策略可能在沒有激進降息的情況下穩定加密價格。 比特幣價格可能上升到92,000至98,000美元,以太坊或能推升至3,600美元。 WEEX Crypto News, 2025-12-26 10:06:42 隨著美國聯邦儲備系統在2025年內三度降息,主要是在最後一季,失業率上升及通脹顯露明顯緩和跡象。然而,加密貨幣市場反應却出人意料,並未因寬鬆政策而上揚,相反,比特幣、以太坊及主要替代幣銷售疲軟,總市值較10月的歷史高位縮減超過1.45萬億美元。本篇將深入分析央行政策至2026年三月的可能走勢,及其對整體加密市場的潛在影響。 聯儲局暫停降息可能導致比特幣、以太坊進一步下跌 儘管聯儲局連續三次下調0.25%的利率,多數官員包括紐約聯邦儲備銀行總裁約翰·威廉姆斯強調通脹和數據依賴風險,未提供進一步寬鬆的明確信號。威廉姆斯於12月19日表示:「我個人不急於立即在貨幣政策上採取進一步行動,因為我認為我們已作出的降息非常有效。」他補充說:「我希望看到通脹降至2%而不對勞動市場造成不必要的損害,這是一個平衡的行為。」 在這個背景下,11月的消費者物價指數(CPI)達到2.63%或提高2026年第一季度進一步降息的可能性。然而,美國政府的歷史性停擺干擾了勞工統計局的數據收集。一些經濟學家如羅賓·布魯克斯擔心這可能扭曲了11月的年通脹讀數。這種不確定性解釋了為何加密市場在過去幾個月未因降息消息而反彈。 BTSE交易所的首席運營官Jeff Mei指出,如果聯儲局在2026年第一季度保持利率不變,比特幣價格可能跌至70,000美元,以太坊價格則可能低至2,400美元。 聯儲局的“隱形量化寬鬆”可能穩定加密價格…

特朗普的「世界自由金融」代幣在2025年下降超過40%

世界自由金融(WLFI)於2024年由特朗普家族推出,最初預期很高,但2025年年底錄得超過40%的價值下跌。 該項目因特朗普政府的潛在利益衝突問題受到廣泛關注,且涉及疑似違規的交易對象。 WLFI在高市值加密貨幣的牛市中取得巨大成就,但於年底卻呈現出顯著損失。 減少資產價值並未阻止WLFI的資產擴展計劃,屬於現實資產的新倡議將於2026年1月推出。 WEEX Crypto News, 2025-12-26 10:10:42 世界自由金融2025年的衰退 隨著2025年即將結束,特朗普家族的加密貨幣項目「世界自由金融」(World Liberty Financial,簡稱WLFI)正面對其代幣價值下跌超過40%的局面。這一項目於2024年9月,由當時仍在2024選舉競選的美國總統唐納德·特朗普宣布啟動,並由其兩位兒子小唐納德·特朗普和埃瑞克·特朗普領導。這一舉動標誌著美國加密貨幣政策的重要轉變。 WLFI的首次代幣銷售是在2024年10月完成的,當時出售了大約200億枚WLFI代幣,每枚價格0.015美元,總共籌集了約3億美元。隨後的一輪代幣銷售從2025年1月持續到3月,以每枚0.05美元的價格出售了50億枚代幣,籌得約2.5億美元。 2025年3月,特朗普家族還推出了自己的穩定幣USD1。到了6月,特朗普家族與由幣安擁有的去中心化金融協議PancakeSwap達成協議,推動該資產的發展。 2025年加密市場的牛市浪潮 在2025年夏秋兩季期間,加密貨幣市場經歷了一次牛市,世自由金融的代幣價值飆升至數十億美元。然而,自從該代幣開始公開交易以來,其價值下降了超過40%。在這段時間內,WLFI進行了多項大型加密貨幣買入,包括價值2150萬美元的包裹比特幣(WBTC)、以太坊(ETH)和移動幣(MOVE)。 自2025年9月首次公開追踪特朗普家族的投資組合以來,該組合的最高價值達到超過170億美元。然而,截至2025年12月11日,其資產價值僅略低於80億美元,顯示出47%的減少。…

區塊鏈為量子威脅做準備,而比特幣討論未來時間線

關鍵要點: 以太坊聯合創始人Vitalik Buterin強調,量子計算帶來的風險,即使概率低,但應及早規劃準備。 比特幣社區對於量子計算威脅的看法分歧,有人認為當前的做法過於高調,有人則主張迫切需要準備。 Aptos已提出可選升級方案和Solana亦在進行量子耐性測試,藉此展現其對未來威脅的應對能力。 比特幣價值依賴長期信任,對量子威脅的討論如何進行,對市場信心有重大影響。 WEEX Crypto News, 2025-12-26 10:10:43 量子計算機技術雖尚無法破解比特幣,但多數主要區塊鏈已開始為可能的未來風險做準備。在最近的一週內,Aptos提出了量子安全的簽名支持計畫,而Solana則測試其量子耐性交易功能。與此同時,比特幣社區的一部分成員重新呼籲加速對量子安全升級的研究工作。 無需驚慌的區塊鏈準備行動 以太坊已經十分明確地將量子計算風險看作工程問題,而非遙遠的假設。以太坊聯合創始人Vitalik Buterin指出,即便是一個可能性不高的結果,也需要早期的準備,尤其是在失敗代價高昂的情況下,系統的遷移可能需要數年時間。根據但以理預測模型顯示,能夠破解目前公鑰加密技術的量子電腦在2030年之前出現的概率大約為20%,而中位數預測更接近2040年。即便沒有目前可用的機器可以破解比特幣或以太坊,卻仍然強調待到事情明朗再行動是非常危險的。 這種觀點開始在其他主要區塊鏈中產生共鳴,尤其是那些可以在不重新開啟根本性討論的情況下進行試驗的系統。Aptos已經提出了一個通過用戶選擇參與來添加量子簽名支持的計畫,此方案依賴於基於哈希的簽名機制,更定位於未來的保障而非對當前威脅的反應。用戶可自行選擇採用該新方案,避免強制性進行全網遷移。 除了Aptos,Solana選擇通過測試而不是部署來迎接量子挑戰。與量子安全公司Project Eleven合作,該網路近期運行了一個專用測試網來使用量子耐性簽名,這是為了評估此類方案是否能夠在不影響性能或兼容性的情況下進行整合。…

熱門幣種

最新加密貨幣要聞

閱讀更多