CryptoReal
CASE FILE — Aug 19, 2025

BTCTurk Hit for $51.7 Million in Second Major Hot Wallet Breach in 14 Months

Turkish exchange BTCTurk has lost $51.7 million from its hot wallets in an attack that spread across seven blockchains, marking the second major private-key compromise the platform has suffered in just over a year.

Cyvers flagged suspicious outflows on August 14th, but by the time the alert went out, funds were already moving across Ethereum, Avalanche, Arbitrum, Base, Optimism, Mantle, and Polygon. The attackers systematically converted the stolen assets into ETH as they moved.

A familiar failure mode

The mechanism behind this breach mirrors the exchange's prior incident: leaked private keys enabling direct access to hot wallet funds. Cyvers' monitoring picked up funds flowing abnormally across the seven networks in the early morning, with attackers consolidating the stolen assets into two wallets before BTCTurk's team responded.

Roughly an hour after detection, BTCTurk acknowledged the incident publicly, describing it in terms of "technical problems" rather than characterizing it as a security breach. The attack itself was methodical: funds denominated in ETH, AVAX, ARB, BASE, OP, MANTLE, and MATIC were systematically converted into liquid ETH.

BTCTurk suspended crypto deposits and withdrawals within about an hour of detection, but the attackers had already moved and consolidated funds across multiple chains by that point.

Tracing the funds

According to on-chain analysis, EVM-compatible chains bore the brunt of the exploit, with stolen assets split across several collection addresses.

Blockscope identified three primary consolidation addresses used by the exploiters:

Blockscope further tracked the consolidated ETH being routed onward to additional addresses across L2 and EVM networks:

Beosin's subsequent analysis found additional stolen funds at:

Sums referenced in this case file

Beosin also reported that Bitcoin was part of the haul, with 33.247 BTC (roughly $3.9 million) traced to:

As of August 18th, the exploiter wallets collectively held an estimated $51.7 million. Beosin's latest fund-flow tracking indicates the attackers have not yet moved to launder or cash out the funds. More than 90 distinct token types were rapidly swapped into ETH via MetaMask early in the attack, leaving the proceeds consolidated and ready for a future move. Notably, the outflows continued even after BTCTurk froze user accounts, indicating the compromised infrastructure kept leaking assets after the initial detection.

Limited communication

BTCTurk's public response has been minimal. A single Turkish-language statement cited a "technical issue with hot wallets," asserted that cold wallets and customer funds remained secure, and said authorities had been notified. No further updates followed.

Crypto deposits and withdrawals were suspended indefinitely, while fiat deposits, withdrawals, and trading continued operating normally — meaning lira-denominated activity was unaffected.

Founder Kerem Tibuk, who took over as acting CEO following the exchange's prior hack, has not issued any public statement, interview, or update since the breach.

A repeat incident

This is not BTCTurk's first major security failure. In June 2024, the exchange lost $55 million from ten hot wallets after private keys were compromised, with Binance freezing $5.3 million in stolen funds as part of the investigation. At the time, BTCTurk stated that only company funds, not customer funds, had been affected. ZachXBT subsequently linked the June 2024 attackers to a separate $3.5 million theft from the Sportsbet casino platform that occurred hours later.

The 2025 incident follows the same pattern: compromised private keys, roughly $51.7 million drained from hot wallets, and authorities notified while the attackers organize the stolen funds across chains.

The one notable change between the two incidents is leadership: Özgür Güneri stepped down after seven years following the first hack, leaving founder Kerem Tibuk to manage the fallout from the second.

Context: Turkey's crypto exchange history

BTCTurk's repeat breach is not the most severe incident in Turkey's crypto exchange history. That distinction belongs to Faruk Fatih Özer, who founded the Thodex exchange in 2017. By 2021, Özer had risen to public prominence, photographed with senior political figures including Mevlut Çavuşoğlu and Süleyman Soylu, as Thodex grew into one of Turkey's largest exchanges.

On April 20, 2021 — known in crypto circles as "Dogeday" — Thodex launched a promotion distributing millions of Dogecoin tokens, including roughly 4 million DOGE, before freezing withdrawals and going dark. Airport security footage later showed Özer fleeing Istanbul the same day with an estimated $2 billion in customer funds, leaving 391,000 users locked out of their accounts. Following a two-year international manhunt, Turkish courts sentenced Özer to 11,196 years in prison.

Turkey's persistent currency instability continues to push citizens toward crypto exchanges, some of which combine high user demand with weak security practices.

Broader trend

BTCTurk's loss adds to a difficult summer for exchange security. July 2025 alone saw $142 million lost across crypto platforms, a 27% increase from June, led by India's CoinDCX, which lost $44 million to a server breach. GMX lost $42 million (largely recovered), while BigONE and WOO X lost $27 million and $14 million respectively. BTCTurk's $51.7 million loss pushes the summer's cumulative exchange losses toward the $200 million mark.

As of four days after the attack, the stolen funds remain visible on-chain in the attackers' wallets but have not been moved or laundered — observable on any blockchain explorer, yet effectively out of reach for recovery.

BTCTurkCEXPrivate Key Leak
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.