Bitmart
On December 4, 2021, the exchange BitMart lost roughly $196 million after attackers gained control of the private keys to two of its hot wallets — one on Ethereum, one on BNB Smart Chain — and drained them to addresses outside BitMart's control. How the keys were obtained was never disclosed publicly. In the first hours, BitMart's own Telegram admins dismissed reports of a breach as "fake news"; the exchange confirmed the hack only after blockchain analytics firm PeckShield had already tracked the outflows on-chain (Rekt, Crypto Briefing).
How the attack worked
Public sources describe the breach only at a high level: compromise of the signing keys for two internet-connected ("hot") wallets, with no disclosed vector — it was never confirmed whether it was employee phishing, an infrastructure leak, a compromised deployment pipeline, or something else. Structurally this is simpler than a smart-contract exploit: the attacker doesn't need to find a bug in protocol code, only a single opportunity to obtain a key that can sign transfers.
- The Ethereum and BSC wallets were drained in close succession — about $100 million and $96 million respectively.
- Most of the stolen assets were illiquid altcoins and meme tokens; the attacker routed them through the DEX aggregator
1inchto convert them into ETH and BNB, avoiding centralized venues that could freeze the funds. - A portion of the proceeds was then run through Tornado Cash, a mixer that breaks the on-chain link between the receiving address and whatever the funds do next.
Our database labels the technique "Private Key Compromised (Unknown Method)," which matches exactly what sources established: the key compromise itself is confirmed, but neither BitMart nor outside analysts ever named the method the attacker used to obtain it.
What happened next
BitMart froze deposits and withdrawals while it investigated, and announced a phased restoration of service by December 7. Neither the attacker nor the stolen funds were ever traced further — the 1inch-then-Tornado-Cash route made the on-chain trail unusable for recovery, and no public source reports either a fund recovery or an arrest. That's why our table lists $0M "returned": nothing was seized from or given back by the thief.
Instead of recovering the stolen assets, BitMart pledged to cover the loss from its own balance sheet. CEO Sheldon Xia said the exchange would "use our own funding to cover the incident and compensate affected users" (Decrypt). That's a fundamentally different mechanism from restitution of the stolen coins — it's self-insurance funded by the exchange's own treasury.
BitMart kept operating for nearly five more years after the incident. In July 2026 the company announced it would wind down entirely, with trading ending August 26, 2026 and full closure set for January 2027. It cited "operating conditions, market environment, and future strategic direction," with no reference to the 2021 breach anywhere in the announcement (Cointelegraph).
Takeaways
- Self-funded compensation is a promise, not a guarantee. Unlike some smart-contract exploits, where negotiation or a white-hat freeze can claw back part of the loss, a CEX hot-wallet theft leaves users entirely dependent on the exchange's solvency and goodwill — not on recovery of the specific assets that were stolen.
- There's no external signal a user can check in advance. Unlike a published smart-contract audit, an exchange's internal key-custody setup is invisible from the outside; the only mitigation available is not leaving more on an exchange than is needed for active trading.
- An exchange's first public reaction is itself informative. Denying a breach as "fake news" in the hours after analysts have already tracked outflows on-chain is a pattern worth recognizing — a slow or defensive first response often signals the absence of a real incident-response process.
- Routing through a DEX aggregator and a mixer is the default laundering path, not a sophisticated one. Its ordinariness doesn't make it less effective: years later, no arrest or on-chain recovery tied to this specific theft has been publicly confirmed.
On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.