CSIDB logo
Incident

BIT Mining Limited

Incident posture

Attack window
Dec 2022
Location
China
Status
Historical
CIA posture
Available to members
Updated
2025-10-15 00:00

Linked entities

Victim
BIT Mining Limited
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

BIT Mining Limited's subsidiary BTC.com experienced a cyberattack resulting in the theft of digital assets, including approximately $700,000 belonging to clients and $2.3 million owned by the company. Law enforcement authorities in Shenzhen were notified, and partial recovery of the assets was achieved through internal coordination. An investigation was subsequently launched, with evidence collection and inter-agency coordination initiated to pursue recovery efforts. The company deployed enhanced security measures to block future attacks, and while BTC.com's digital asset services were impacted, its client fund operations remained unaffected, with business continuing normally.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On December 3, 2022, BIT Mining Limited’s subsidiary BTC.com experienced a cyberattack resulting in the theft of digital assets. The incident involved approximately $700,000 in client-owned assets and $2.3 million in company-owned assets. BIT Mining, a NYSE-listed cryptocurrency mining and mining pool operator, disclosed the breach on December 26, 2022, confirming the attack targeted BTC.com’s digital asset services. The company promptly reported the incident to law enforcement authorities in Shenzhen, China. Internal coordination and local collaboration enabled the partial recovery of some compromised digital assets, though specific technical details of the attack vector or perpetrator were not disclosed. The theft exclusively impacted digital asset holdings, with no disruption to BTC.com’s client fund services or broader mining pool operations.

Following the breach discovery, BIT Mining implemented enhanced cybersecurity measures designed to block and intercept malicious actors, though exact technical specifics were not elaborated. By December 23, 2022, Shenzhen authorities had formally initiated an investigation, evidence collection, and inter-agency coordination to trace the stolen assets. BIT Mining committed significant resources to recovery efforts but did not specify methodologies or timelines. BTC.com resumed normal business operations post-attack, maintaining functionality across all non-digital asset services, including its blockchain browser and multi-currency mining pool supporting BTC, ETH, and LTC. The incident underscored operational risks in digital asset management but did not affect the company’s mining hardware manufacturing through subsidiary Bee Computing or its data center activities. No additional breaches or system compromises were reported following the initial December 3 attack.

Sources

Sources available to members: 1 source.

CSIDB