Crypto exchange BigONE has confirmed it was hit by a suspected supply chain attack early on July 16, leading to losses exceeding $27 million. The incident was first flagged by blockchain security firm SlowMist, which reported that the attacker compromised BigONE’s production environment by altering server logic related to account and risk control.
The attacker was able to withdraw funds without permission, but BigONE confirmed that private keys were not compromised.
In a blog post, BigONE said the attack specifically hit their hot wallet. They noticed unusual fund activity, looked into it, and managed to find and block the source of the breach. They assured users there’s no further threat of ongoing losses and that private keys have not been exposed.
According to the exchange, the stolen funds include 120 BTC, 350 ETH, over 8.5 million USDT across TRC20, ERC20, BSC, and Solana networks, along with other tokens such as 20,730 XIN, over 4.3 million SNT, 15.7 million CELR, 16,071 LEO, 25,487 UNI, nearly 9.7 billion SHIB, 1,800 SOL, and 538,000 DOGE. BigONE said these figures will be updated as their investigation progresses.
Despite the scale of the loss, BigONE has promised users won’t be impacted materially. The exchange has activated its internal security reserves: BTC, ETH, USDT, SOL, and XIN, to replenish user funds while sourcing external liquidity for other affected tokens through borrowing mechanisms.
The hacker’s wallet addresses have been identified across multiple blockchains.
- Ethereum & BSC: 0x9Bf7a4dDcA405929dba1FBB136F764F5892A8a7a
- Solana: HSr1FNv266zCnVtUdZhfYrhgWx1a4LNEpMPDymQzPg4R
- Bitcoin: bc1qwxm53zya6cuflxhcxy84t4c4wrmgrwqzd07jxm
- Tron: TKKGH8bwmEEvyp3QkzDCbK61EwCHXdo17c
BigONE is now working with SlowMist to monitor these addresses and track the hacker’s movements. While deposit and trading services are expected to resume within a few hours, withdrawals will stay suspended until additional security layers are in place. The exchange has committed to transparent updates as the situation develops.
Also Read: Hackers Drain $2.5M from Arcadia Finance on Base Network
