What happened
Taiwanese exchange BitoPro lost about $11.5 million from an old hot wallet on May 8, 2025, during a wallet system upgrade and asset transfer operation, and disclosed the incident on June 3. BitoPro said the attackers first conducted social engineering against an employee who managed cloud operations, then deployed malware on that person's device. The exchange attributed the attack to the Lazarus Group based on methodology matching prior exchange and SWIFT intrusions.
How the deception worked
BitoPro described the entry point only as social engineering against a cloud operations employee and did not disclose the specific channel or pretext used; the vector is recorded here as targeted phishing on that basis and the channel remains unconfirmed. Malware planted on the employee's device let the attackers hijack AWS session tokens, which sidestepped multi-factor authentication entirely because a live session had already satisfied it. Holding valid session tokens, they took control of BitoPro's cloud infrastructure and used their command server to inject scripts into the hot wallet system while a scheduled wallet upgrade and asset transfer was in progress. The malicious withdrawals were timed and shaped to mimic the legitimate migration traffic around them.
AI involvement · No AI reported
No AI involvement was reported.
The control that would have caught it· our reading, not a claim from the sources
Binding cloud session tokens to device posture and network origin, so a stolen token is unusable elsewhere, plus freezing automated wallet operations during manual migrations, would have denied both halves of this attack.
Sources (2)
- BitoPro exchange links Lazarus hackers to $11 million crypto heistBleepingComputer·bleepingcomputer.comOpen ↗
- Taiwanese crypto exchange BitoPro confirms estimated $11.5 million hackFortune·fortune.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.