How a Compromised Build Pipeline Drained $27M From BigONE's Hot Wallets
Exchange operators tend to focus their defenses on wallet security and cold storage, but the incident that hit BigONE on July 15th shows how a compromised internal pipeline can bypass those safeguards entirely. No private keys were stolen, no flash loans were used, and no smart contract was exploited. Instead, someone altered BigONE's own account and risk-control logic from within its production network, turning ordinary withdrawal functions into a channel for unauthorized transfers — and roughly $27 million disappeared as a result.
Credit: CertiK, Blockchain Insights, BigONE, SlowMist, Lookonchain, ZachXBT

01Timeline of discovery
CertiK first flagged unusual activity late on the night of July 15th, noticing repeated large outflows from BigONE's hot wallet address as roughly $4 million in ETH and assorted tokens piled up in an attacker-controlled account. A few hours afterward, Blockchain Insights confirmed the full scope: funds had been drained simultaneously across five separate chains — Bitcoin, Ethereum, TRON, BSC, and Solana — totaling around $27 million.
Notably, earlier that same day BigONE had posted a routine-sounding "system maintenance" notice, hours before the scale of the breach became public. By late evening, the exchange could no longer avoid transparency, confirming a "security incident: unauthorized access to our hot wallet."
02What was taken and where it went
According to BigONE's own incident disclosure, the assets drained from its hot wallet infrastructure included: 120 BTC, 350 ETH, 8.54 million USDT spread across chains, 20,730 XIN, 9.7 billion SHIB, 538,000 DOGE, 1 WBTC, 15.7 million CELR, 25,487 UNI, and 16,071 LEO.
SlowMist tracked the outbound funds to the following addresses:
Bitcoin: bc1qwxm53zya6cuflxhcxy84t4c4wrmgrwqzd07jxm
Ethereum: 0x9Bf7a4dDcA405929dba1FBB136F764F5892A8a7a
BSC: 0x9Bf7a4dDcA405929dba1FBB136F764F5892A8a7a
TRON: TKKGH8bwmEEvyp3QkzDCbK61EwCHXdo17c
Solana: HSr1FNv266zCnVtUdZhfYrhgWx1a4LNEpMPDymQzPg4R
Lookonchain's analysis showed the attackers moving quickly to convert the haul: 120 BTC (worth roughly $14.15 million), 23.316 million TRX (about $7.01 million), 1,272 ETH (around $4 million), and 2,625 SOL (approximately $428,000).
One detail suggests premeditation: the infrastructure used to carry out the transfer appears to have been staged in advance of the actual strike, implying either extended reconnaissance of BigONE's production environment or prior access to it.
03The mechanism: a supply chain compromise, not a key leak
Unlike typical exchange breaches involving leaked private keys or exploited contracts, this attack targeted BigONE's internal software supply chain. SlowMist's analysis identifies the vector as a supply chain attack against BigONE's production network, which let the intruder alter the operational logic running on the account and risk-control servers. In effect, rather than breaking into the system, the attacker manipulated it into treating unauthorized withdrawals as routine, legitimate ones.
Crucially, SlowMist also confirmed that no private keys were exposed at any point — this was purely an infrastructure-level compromise, with risk controls and withdrawal-approval logic rewritten to wave transactions through. BigONE has since stated that the attack path has been identified and closed off, preventing further losses.
04Communications and compensation
BigONE's public messaging moved through several stages. It began with a maintenance notice giving no indication of a breach, followed hours later by an acknowledgment of "unauthorized access to our hot wallet." Once outside security researchers weighed in, the framing shifted again to describe a "third-party attack targeting our hot wallet."
The exchange has pledged full compensation for affected users, drawing on internal reserves of BTC, ETH, USDT, SOL, and XIN, and supplementing with external borrowing to restore liquidity for the remaining tokens.
05A separate compliance problem surfaces
Investigator ZachXBT then raised a separate issue: BigONE, he alleged, had processed substantial volumes tied to pig-butchering and romance scams, pointing to a deposit address that had reportedly handled $60 million in fraud proceeds.

Suspect Address: 16jAfbpfRzFvagiP5hzBPrYF9YhUhQuq9h
In response, BigONE said it had "successfully froze[n] a portion of the assets involved" and was cooperating with multiple law enforcement agencies.
ZachXBT followed up with additional detail, describing a seven-month period during which the same pig-butchering operation allegedly used a single BigONE deposit address without interruption. He wrote that the group had "used the same account for 7 months uninterrupted," and that it had since moved to a new BigONE deposit address which, per his tracking, had received $4.5 million from scam activity within the preceding week.
Fresh Suspect Address: 1MWq9iNRe3MfYCq3j7439JDyooczqGBnR5
Taken together, the allegations describe romance scams, investment fraud, and pig-butchering schemes running through BigONE's platform for months, seemingly without triggering compliance intervention. Even after the $27 million hack, the same fraud network reportedly just switched to a new address and resumed operations.
06Takeaways
The episode illustrates two distinct failure modes converging at once: a novel infrastructure-level attack that bypassed conventional wallet and smart-contract defenses by corrupting the exchange's own risk-control logic, and a longer-running compliance gap that allowed scam proceeds to move through the platform largely unchecked. Whatever compensation BigONE extends to victims of the hack, the separate questions raised about its handling of suspicious deposit activity remain unresolved.
Get new scam files the moment we publish them — usually 2–3 emails a week.