{"id":14748,"date":"2021-12-05T05:46:42","date_gmt":"2021-12-05T04:46:42","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=14748"},"modified":"2021-12-05T13:35:21","modified_gmt":"2021-12-05T12:35:21","slug":"crypto-exchange-bitmart-hacked-with-losses-of-200m","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/crypto-exchange-bitmart-hacked-with-losses-of-200m\/","title":{"rendered":"Crypto Exchange Bitmart hacked with losses of $200M"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">Bitmart has lost close to $200 million in multiple cryptocurrencies, making this the most damaging centralized exchange breach to date. The hackers made off with a collection of over 20 tokens <\/h5>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/12\/Crypto-Exchange-Bitmart-hacked-with-losses-of-200M.png\" alt=\"Crypto Exchange Bitmart hacked with losses of $200M\" class=\"wp-image-14749\" width=\"1000\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/12\/Crypto-Exchange-Bitmart-hacked-with-losses-of-200M.png 400w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/12\/Crypto-Exchange-Bitmart-hacked-with-losses-of-200M-300x150.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/12\/Crypto-Exchange-Bitmart-hacked-with-losses-of-200M-360x180.png 360w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/><figcaption>Crypto Exchange Bitmart hacked with losses of $200M<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Huge loss for Bitmart following hack<\/h2>\n\n\n\n<p>Bitmart has lost $196 million in multiple cryptocurrencies, making this the most damaging centralized exchange breach to date.<\/p>\n\n\n\n<p>The purported attack was initially brought to light Saturday night by security analysis firm Peckshield in a tweet. One of Bitmart's addresses is currently showing regular outflows of whole token balances, some worth tens of millions of dollars, to an address known as the &#8220;Bitmart Hacker&#8221; by Etherscan.<\/p>\n\n\n\n<p>In a follow-up tweet, Peckshield assessed the damage at $100 million in various cryptocurrencies on the Ethereum network and $96 million on the Binance Smart Chain.<\/p>\n\n\n\n<p>The team's further investigation discovered a concurrent $96 million compromise of the crypto exchange's BSC reserves:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Total estimated loss: ~200M (~100M on&nbsp;<a href=\"https:\/\/twitter.com\/ethereum?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@ethereum<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>&nbsp;and ~96M on&nbsp;<a href=\"https:\/\/twitter.com\/BinanceChain?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@BinanceChain<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>&nbsp;). (Previously we only counted the loss on&nbsp;<a href=\"https:\/\/twitter.com\/ethereum?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@ethereum<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>). And here is the list of affected assets\/amounts on&nbsp;<a href=\"https:\/\/twitter.com\/BinanceChain?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@BinanceChain<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>&nbsp;<a href=\"https:\/\/t.co\/cXXApDFtd7\" target=\"_blank\">pic.twitter.com\/cXXApDFtd7<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>\u2014 PeckShield Inc. (@peckshield)&nbsp;<a href=\"https:\/\/twitter.com\/peckshield\/status\/1467310381073047552?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">December 5, 2021<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p><\/blockquote>\n\n\n\n<p>The hackers made off with a collection of over 20 tokens, including BNB, Safemoon, BSC-USD, and BPay. The attack also exposed a large number of meme currencies, including BabyDoge, Floki, and Moonshot.<\/p>\n\n\n\n<p>According to Peckshield, the hack was a simple case of transfer-out, swap, and wash: <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2021-12\/5f32419d-7ccf-46d2-9502-26a6e5cc15e8.jpg\" alt=\"Crypto Exchange Bitmart hacked with losses of $200M\" \/><figcaption>Crypto Exchange Bitmart hacked with losses of $200M. <em>Transfer of stolen Bitmart tokens. Source:&nbsp;<\/em><a href=\"https:\/\/twitter.com\/peckshield\/status\/1467318513971118083\" target=\"_blank\" rel=\"noreferrer noopener\">PeckShield<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/figcaption><\/figure>\n\n\n\n<p>The hacker systematically used decentralized exchange aggregator 1inch to swap stolen assets for cryptocurrency ether (<a href=\"https:\/\/coinscreed.com\/staging\/tornado-cash-sets-to-launch-on-ethereums-layer-two-network-arbitrum.html\" data-type=\"post\" data-id=\"14306\">ETH<\/a>), then deposited the ETH into privacy mixer Tornado Cash using a secondary address, making the hacked funds harder to track.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">&#8216;Outflows were normal withdrawals'- staffs<\/h2>\n\n\n\n<p>The Crypto Exchange staff first stated that the outflows were &#8220;normal withdrawals&#8221; on an official Telegram channel, dismissing reports of the hack as &#8220;false news.&#8221;<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Interesting from&nbsp;<a href=\"https:\/\/twitter.com\/BitMartExchange?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@BitMartExchange<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>&nbsp;&#8230;\ud83d\ude33\ud83d\ude33\ud83d\ude33 \ud83d\ude4f\ud83d\ude4f\ud83d\ude4f&nbsp;<a href=\"https:\/\/t.co\/dFrzSww0fs\" target=\"_blank\">https:\/\/t.co\/dFrzSww0fs<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>&nbsp;<a href=\"https:\/\/t.co\/GuDB7bt2eC\" target=\"_blank\">pic.twitter.com\/GuDB7bt2eC<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>\u2014 PeckShield Inc. (@peckshield)&nbsp;<a href=\"https:\/\/twitter.com\/peckshield\/status\/1467316799977193476?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">December 5, 2021<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p><\/blockquote>\n\n\n\n<p>Bitmart CEO Sheldon Xia later admitted that the outflows were really the consequence of a &#8220;security breach&#8221; hours later.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>1\/3 We have identified a large-scale security breach related to one of our ETH hot wallets and one of our BSC hot wallets. At this moment we are still concluding the possible methods used. The hackers were able to withdraw assets of the value of approximately USD 150 millions.\u2014 Sheldon Xia (@sheldonbitmart)&nbsp;<a href=\"https:\/\/twitter.com\/sheldonbitmart\/status\/1467316252855226368?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">December 5, 2021<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">A continuous threat to the crypto ecosystem <\/h2>\n\n\n\n<p>In what appears to be a continuous threat to the crypto ecosystem, cryptocurrency lending provider Celsius announced a $50 million <a href=\"https:\/\/cointelegraph.com\/news\/badgerdao-reportedly-suffers-security-breach-and-loses-10m\" target=\"_blank\" rel=\"noopener\">loss<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> as a result of the BadgerDAO decentralized finance (DeFi) protocol's vulnerability.<\/p>\n\n\n\n<p>The initial complaints about a security vulnerability involving BadgerDAO appeared on December 2, with the protocol publicly declaring on Wednesday that it had received multiple exporters of illicit withdrawals using cash.<\/p>\n\n\n\n<p>To minimize any more losses, the Badger team proceeded to investigate the issue and paused all smart contracts on the protocol, similar to Bitmart. With a total loss of $196 million, this is one of the most costly centralized exchange attacks ever.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Bitmart has lost close to $200 million in multiple cryptocurrencies, making this the most damaging centralized exchange breach to date. The hackers made off with a collection of over 20 tokens Huge loss for Bitmart following hack Bitmart has lost $196 million in multiple cryptocurrencies, making this the most damaging centralized exchange breach to date. [&hellip;]<\/p>\n","protected":false},"author":29,"featured_media":14749,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[5816,5392,5817],"class_list":["post-14748","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-bitmart-2","tag-cryptocurrency-2","tag-hack-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/12\/Crypto-Exchange-Bitmart-hacked-with-losses-of-200M.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/14748","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=14748"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/14748\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/14749"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=14748"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=14748"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=14748"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}