Poloniex
On November 10, 2023, the Tron-affiliated exchange Poloniex lost roughly $126 million from its hot wallets on Ethereum and Tron. The exchange initially described the outage as routine "maintenance" before owner Justin Sun confirmed a breach hours later. Blockchain trackers spent the following days revising the loss estimate upward from an initial ~$100 million as more outgoing transactions were identified (CoinLive, CoinGape).
How the attack worked
This was not a smart-contract exploit — there was no vulnerable code to patch. The attacker obtained the private key (or equivalent signing authority) to one or more of Poloniex's hot wallets and simply signed valid transactions moving funds out, exactly as the legitimate owner would. Poloniex has never disclosed how the key was obtained: phishing, an infrastructure breach, or an insider are all possibilities that fit the public evidence, which is why the case is classified as private-key compromise by an unknown method rather than a specific named vector (Web3 Is Going Just Great).
Once inside, the attacker moved assets — BTC, ETH, TRX, SHIB, stablecoins and others — across roughly 357 transactions, routing tokens through intermediary addresses and swapping on decentralized exchanges to convert them into TRX and other liquid assets, then spread the proceeds across hundreds of wallets to complicate tracing (CoinGape). Blockchain analysts, including Halborn, noted that the fund-splitting and DEX-laundering pattern resembled known Lazarus Group tradecraft, though this attribution rests on behavioral similarity rather than a confirmed claim.
What happened next
Sun publicly acknowledged the incident within hours and offered the attacker a 5% "white-hat" bounty — about $10 million — to return the funds by November 25, warning that law enforcement would get involved otherwise. No public evidence indicates the attacker returned any funds by that deadline. Poloniex froze withdrawals, ran a security review with CertiK tracing the outflows across roughly 681 wallets, and resumed deposits and withdrawals around mid-November (CoinLive). Sun committed to reimbursing affected users in full from company reserves rather than from recovered stolen funds — a distinction that matters: the $126 million itself was never clawed back, it was absorbed by the exchange (DeFi Teller). Poloniex continued operating after the incident.
What this means
- The exploit sat entirely in exchange operations, not in any smart contract users interacted with — no amount of due diligence on a token or protocol would have flagged this risk in advance.
- Hot-wallet key compromises are invisible to depositors until the exchange discloses them; the only mitigant available to users is capping the balance held on any single exchange, not trying to assess key-management practices from outside.
- A same-day "we're doing maintenance" statement followed by a slow, incremental upward revision of the damage estimate (~$100M to $126M) is a recurring pattern across CEX hacks — initial official statements tend to understate scope.
- Reimbursement funded from company treasury rather than recovered assets means an exchange's solvency after a hack depends on its own balance sheet — a detail rarely visible to users when they choose where to custody funds.
Sources
- Explained: The Poloniex Hack (November 2023) — Halborn ↗
- Poloniex hacked for more than $120 million — Web3 Is Going (Just) Great ↗
- Poloniex Hack: Total Funds Stolen Reaches Over $126 Million — CoinGape ↗
- Poloniex Hack November 2023: Identified Hacker & $10M Reward — DeFi Teller ↗
- Poloniex Crypto Exchange Reinstates Withdrawals Following $100M Hack — CoinLive ↗
Sources checked 07.08.2026
On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.