Smart Business Tips
Sign In
  • Home
  • Business
    • Business Coaching
    • Business Growth
    • Business Tools & Apps
  • Entrepreneurship
    • Entrepreneurs
    • Crypto
    • Innovation
    • Investing
    • Leadership
    • Productivity
  • Contact US
    • Blog
  • Branding
    • Content Marketing
    • Digital Marketing
    • E-commerce
    • Marketing Strategies
    • Personal Finance
  • Sales
    • Small Business Tips
    • Social Media
    • Startups
    • Tech Trends
    • Investing
  • Shop
Notification
Trump says he’s found a buyer for TikTok
Tech Trends

Trump says he’s found a buyer for TikTok

The Secret to Staying Energized and Productive All Day Long
Productivity

The Secret to Staying Energized and Productive All Day Long

How to Build a Rental Portfolio (Fast) That Gives You Financial Freedom
Investing

How to Build a Rental Portfolio (Fast) That Gives You Financial Freedom

7 Real Ways To Get Paid To Eat at Restaurants
Personal Finance

7 Real Ways To Get Paid To Eat at Restaurants

Font ResizerAa
Smart Business TipsSmart Business Tips
  • Home
  • Business
  • Entrepreneurship
  • Contact US
  • Branding
  • Sales
  • Shop
Search
  • Home
  • Business
    • Business Coaching
    • Business Growth
    • Business Tools & Apps
  • Entrepreneurship
    • Entrepreneurs
    • Crypto
    • Innovation
    • Investing
    • Leadership
    • Productivity
  • Contact US
    • Blog
  • Branding
    • Content Marketing
    • Digital Marketing
    • E-commerce
    • Marketing Strategies
    • Personal Finance
  • Sales
    • Small Business Tips
    • Social Media
    • Startups
    • Tech Trends
    • Investing
  • Shop
Sign In Sign In
Follow US
Made by ThemeRuby using the Foxiz theme. Powered by WordPress
Smart Business Tips > Blog > Crypto > How the BigONE hack happened
Crypto

How the BigONE hack happened

Admin45
Last updated: August 4, 2025 2:30 pm
By
Admin45
8 Min Read
How the BigONE hack happened
SHARE


Contents
What was the BigONE $27 million hack?How the BigONE crypto exchange hot wallet exploit happenedTracing the BigONE July 2025 crypto hack fundsWhy understanding supply chain attack vulnerabilities is more important than ever

What was the BigONE $27 million hack?

The Seychelles-based cryptocurrency exchange BigONE confirmed that on July 16, 2025, it suffered a crypto supply chain attack that allowed cybercriminals to drain $27 million from the exchange’s hot wallets.

With a sophisticated attack, the hackers compromised the exchange’s production network and gained access to the funds without ever accessing private keys.

Interestingly, BigONE has reported that no private keys were leaked during the exploit. Instead, internal systems were manipulated to grant unauthorized fund withdrawals across various assets. As confirmed by onchain data, the attackers took:

  • 121 Bitcoin (BTC).
  • 350 Ether (ETH).
  • 9.69 billion Shiba Inu (SHIB).
  • 538,000 Dogecoin (DOGE).
  • Digital assets like Tether USDt (USDT) and more.

These unauthorized fund withdrawals were officially confirmed by BigONE, saying: “In the early hours of July 16, BigONE detected abnormal movements involving a portion of platform assets. Upon investigation, it was confirmed as the result of a third-party attack targeting our hot wallet.”

BigONE also continued to assure users that the threat was contained and that all customer private keys were secure. It concluded that the attack vulnerability had been identified and closed, removing the risk of further losses.

This joined the list of high-profile crypto exchange hacks in 2025. BigONE was quick to restore its services, including deposits and trading, while working with blockchain security experts SlowMist to begin tracing stolen funds.

Did you know? Crypto attacks now target multiple vectors, often combining social engineering, malicious contract deployment, UI spoofing and deepfake deception. These have become standard practices for top cybercriminals, representing a significant evolution from simple phishing scams. 

How the BigONE crypto exchange hot wallet exploit happened

The BigONE exchange hack was different from many of the attacks seen in recent months. Instead of using compromised private keys or smart contract vulnerabilities, this attack vector targeted weaknesses in the exchange’s back-end infrastructure. 

It added another threat that centralized exchanges (CEX) need to be aware of, with the potential to circumvent many of the industry-standard security practices. Plus, it left a difficult-to-trace digital footprint.

According to HackenProof, a bug bounty platform that connects companies with cybersecurity experts, the exploit started with social engineering tactics. Criminals targeted a key BigONE developer to compromise the developer’s device. This enabled them to gain unauthorized access and permissions to the exchange.

The hackers then orchestrated a sophisticated supply chain attack. With unauthorized access, malicious code was deployed, which enabled the temporary alteration of accounting and risk management service logic within the exchange. This allowed hackers to transfer $27 million worth of crypto from hot wallets.

Once the internal logic had been bypassed, fund extraction occurred with precision. Attackers moved assets rapidly, millions vanished almost instantly, followed by cleanup transactions totaling 102,000 USDC (USDC) and 79,000 USDT, revealing extensive pre-planning and deep understanding of internal systems.

HackenProof noted that the system has been reinforced and that private keys and user data remained secure. BigONE is covering all user losses from its insurance reserve fund.

In an attempt to recover funds, a bounty program has been issued to encourage the identification of the attackers and trace stolen funds. Any useful intelligence and successful recoveries could lead to rewards of up to $8 million in reward bounties.

Did you know? The crypto insurance market has grown from $1.3 billion in 2023 to $4.2 billion in 2025. It shows the escalation in the industry, with exchange premiums rising 35% year-over-year for Q1 of 2025. 

Tracing the BigONE July 2025 crypto hack funds

Blockchain security firm SlowMist has joined the investigation. The firm is renowned for providing security audits, consultancy and attack investigations. SlowMist’s X account confirmed the process hackers used to steal funds before listing the addresses used in the heist on Ethereum and BNB Chain networks.

Tracing the BigONE July 2025 crypto hack funds

Following the heist, the attackers began laundering stolen assets through other cryptocurrencies. Analysis from Lookonchain, a blockchain observatory company, showed that funds had been laundered through other blockchains including Tron, Solana, Ethereum and Bitcoin.

Beyond this BigONE hack investigation update, figuring the final destination of the funds has been tricky for the crypto community. Investigators are working through blockchain transaction proofs, exchange intelligence, technical analysis and chain-of-custody proofs to provide additional forensic blockchain intelligence.

Ironically, famous pseudonymous blockchain investigator Zach XBT responded not by being helpful but commenting on X: “Do not feel bad for the team as this CEX processed a good bit of volume from pig butchering romance and investment scams,” intimating that the hack may have been karma for BigONE’s involvement in processing funds from investment scams.

Did you know? Criminals are getting increasingly creative in washing the proceeds of crypto heists. This includes methods like leveraged trading on decentralized exchanges (DEX) to open large bets and hedge them with clean capital.

Why understanding supply chain attack vulnerabilities is more important than ever

This incident is another dent in the trust that crypto users place in centralized exchanges. In the past, threats of exchange hacks and the preference for self-custody were often cited as best practices.

Now attacks are becoming more sophisticated and making headlines every week. BigONE joins a scary list in 2025. As you can see on Web3IsGoingGreat.com, which keeps track of scams and frauds in the industry, the list is growing quickly:

The BigONE attack shows an important difference between cryptographic security and protecting private keys, compared with infrastructure security and system integrity. Many of these exchange organizations rely heavily on continuous integration (CI) systems to rapidly update software. This automation is essential for efficient operation, but clearly can become compromised.

One single point of failure, like a vital developer, can lead to malicious code injection to bypass security safeguards. Effectively, systems can be reprogrammed to allow for fund extraction, going undetected by monitoring systems that look for external threats instead of internal server compromises.

Fortunately, top exchanges do use tiered systems to protect funds. This includes segregation in different funding areas and insurance reserve funds so that when losses do occur, customers can be reimbursed.

You can’t help but think that blockchain security firms are having a bumper year in 2025, with $2.5 billion already stolen in the first half. That already exceeds total annual losses in 2024.



Source link

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
Share This Article
Facebook Email Copy Link
Leave a Comment Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow
Ad image

You Might Also Like

Strategy Unveils .2B BTC-Backed Security
Crypto

Strategy Unveils $4.2B BTC-Backed Security

By
Admin45
August 2, 2025
InternetX to Tokenize 22 Million Domains With Doma Protocol
Crypto

InternetX to Tokenize 22 Million Domains With Doma Protocol

By
Admin45
July 29, 2025
Technical Charts Suggest a ‘Phenomenal ’Altseason is Coming: Analysts
Crypto

Technical Charts Suggest a ‘Phenomenal ’Altseason is Coming: Analysts

By
Admin45
July 17, 2025
US-Regierung verkündet Crypto Week! Was das für den Kryptomarkt bedeutet
Crypto

US-Regierung verkündet Crypto Week! Was das für den Kryptomarkt bedeutet

By
Admin45
July 12, 2025
Gemini CEO Accuses JPMorgan Of Onboarding Process Sabotage Over Criticism – Details Gemini CEO Accuses JP Morgan Of Onboarding Process Sabotage Over Criticism – Details
Crypto

Gemini CEO Accuses JPMorgan Of Onboarding Process Sabotage Over Criticism – Details Gemini CEO Accuses JP Morgan Of Onboarding Process Sabotage Over Criticism – Details

By
Admin45
July 27, 2025
Analyst Says Sell XRP Now Before 72% Price Crash To alt=
Crypto

Analyst Says Sell XRP Now Before 72% Price Crash To $0.6

By
Admin45
July 4, 2025

SmartBusinessTips

  • Business Tools & Apps
  • Marketing Strategies
  • Social Media
  • Tech Trends
  • Branding
  • Business
  • Crypto
  • Sales
  • About Us
  • Privacy Policy
  • Member Login
  • Contact Us
  • Business Coaching
  • Business Growth
  • Content Marketing
  • Branding

@Smartbusinesstips Copyright-2025-2027 Content.

Don't not sell my personal information
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

Not a member? Sign Up