BigONE Exchange Hit by $27 Million Supply Chain Cyberattack
The cryptocurrency exchange BigONE recently fell victim to a major security breach, losing $27 million due to a sophisticated supply chain attack that targeted its hot wallet. The incident, which occurred on July 16, 2025, has raised concerns about the vulnerability of crypto platforms to increasingly advanced cyber threats.
How the Attack Unfolded
Unlike traditional cryptocurrency exchange hacks, the attackers behind the BigONE breach exploited the exchange’s production network infrastructure. By compromising the production network, they were able to manipulate the servers responsible for account management and security protocols. This allowed them to override security checks and authorize unauthorized withdrawals without needing access to the exchange’s private keys.
According to security experts, the attackers deployed malicious binaries to the account-operation servers through compromised CI/CD channels, enabling them to reprogram the exchange’s internal systems and facilitate the unauthorized withdrawals.
Assets Stolen in the Attack
The hackers swiftly converted the stolen assets into various cryptocurrencies, including 120 Bitcoin, 23.3 million TRON tokens, 1,272 Ethereum, and 2,625 Solana tokens. The stolen funds also included smaller tokens such as Dogecoin, Shiba Inu, and CELR. To evade detection, the hackers fragmented the stolen funds through bridges and decentralized exchanges.
BigONE’s Response and User Protection
Following the breach, BigONE took immediate action to contain the damage by temporarily suspending deposits and withdrawals. The exchange assured users that all losses would be covered using internal security reserves, including Bitcoin, Ethereum, USDT, Solana, and Mixin tokens. While trading and deposit services resumed swiftly, withdrawals remained suspended pending additional security enhancements.
Allegations and Controversy
The security incident took a controversial turn when allegations surfaced accusing BigONE of processing funds from various scams, including romance and investment frauds. Despite refuting these claims, the exchange faced scrutiny over its alleged involvement in facilitating illicit activities.
The Wider Crypto Security Landscape
The BigONE cyberattack is part of a concerning trend in the cryptocurrency space, with a significant increase in security breaches targeting exchanges. The incident underscores the industry’s ongoing struggle to combat sophisticated cyber threats and protect user funds.
About BigONE Exchange
Established in 2017 and based in Seychelles, BigONE is a prominent cryptocurrency exchange supporting a wide range of assets and trading pairs. Despite its global presence, the exchange has maintained a lower profile compared to industry giants like Binance and Coinbase. The security breach highlights the challenges faced by crypto platforms in balancing accessibility with robust security measures.