Cyber Incident Victim: Bitrue
Date:
Mar 2023
Location:
Singapore
Summary
A Singapore-based cryptocurrency trading platform experienced a theft of approximately $23 million from a single internet-connected hot wallet, with stolen funds involving multiple cryptocurrencies including Ethereum, Polygon, and Shiba Inu. The compromised wallet represented under 5% of the platform's total assets, while other wallets remained secure. Withdrawals were temporarily suspended for security reviews, and affected users were promised full reimbursement. Blockchain analysts confirmed the attacker converted some funds to Ethereum. This marks the second breach for the platform, following a prior incident involving $5 million in losses. The attack occurred shortly after another decentralized finance platform reported an $11 million theft.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 14, 2023, Singapore-based cryptocurrency trading platform Bitrue disclosed that approximately $23 million in digital assets was stolen from one of its hot wallets through a cyberattack. The attacker withdrew funds in multiple cryptocurrencies, including Ethereum (ETH), Polygon (MATIC), Shiba Inu (SHIB), Quant (QNT), GALA, and Holo (HOT). A hot wallet—connected to the internet for operational liquidity—represented the attack vector, though Bitrue emphasized this compromised wallet held less than 5% of the platform’s total funds. The company immediately suspended all withdrawals following the incident to conduct additional security reviews, intending to restore withdrawal functionality by April 18. Blockchain analytics firm PeckShield tracked the stolen assets, noting the attacker converted a portion into Ethereum. Bitrue pledged full reimbursement to affected users, mirroring its response to a prior 2019 breach that resulted in $5 million in losses from exploited vulnerabilities.

The incident highlighted Bitrue’s continued reliance on hot wallets despite inherent security risks, though the firm confirmed non-compromise of its offline cold wallets storing the majority of assets. While no additional technical details of the attack method were released, Bitrue initiated a comprehensive security assessment to identify weaknesses. The theft ranked among several high-profile cryptocurrency exchange breaches in early 2023, occurring shortly after decentralized finance platform Yearn Finance reported an $11 million cyberheist. Bitrue’s prioritization of customer reimbursement and service resumption aligned with its established incident response approach, emphasizing fund recovery without operational disruption beyond the temporary withdrawal pause. Financial losses were confined exclusively to the company’s holdings, with no direct impact reported on individual user accounts outside the compensation guarantee.
