Skip to content
Yieldo

Poloniex

$126.0M
Funds stolen
Funds returned
10 Nov 2023
Date of incident
Technique
Malware
Classification
Social Engineering
Target type
CEX
Affected chains
Tron Ethereum Bitcoin
Source
No public source link

On November 10, 2023, the Tron-affiliated exchange Poloniex lost roughly $126 million from its hot wallets on Ethereum and Tron. The exchange initially described the outage as routine "maintenance" before owner Justin Sun confirmed a breach hours later. Blockchain trackers spent the following days revising the loss estimate upward from an initial ~$100 million as more outgoing transactions were identified (CoinLive, CoinGape).

How the attack worked

This was not a smart-contract exploit — there was no vulnerable code to patch. The attacker obtained the private key (or equivalent signing authority) to one or more of Poloniex's hot wallets and simply signed valid transactions moving funds out, exactly as the legitimate owner would. Poloniex has never disclosed how the key was obtained: phishing, an infrastructure breach, or an insider are all possibilities that fit the public evidence, which is why the case is classified as private-key compromise by an unknown method rather than a specific named vector (Web3 Is Going Just Great).

Once inside, the attacker moved assets — BTC, ETH, TRX, SHIB, stablecoins and others — across roughly 357 transactions, routing tokens through intermediary addresses and swapping on decentralized exchanges to convert them into TRX and other liquid assets, then spread the proceeds across hundreds of wallets to complicate tracing (CoinGape). Blockchain analysts, including Halborn, noted that the fund-splitting and DEX-laundering pattern resembled known Lazarus Group tradecraft, though this attribution rests on behavioral similarity rather than a confirmed claim.

What happened next

Sun publicly acknowledged the incident within hours and offered the attacker a 5% "white-hat" bounty — about $10 million — to return the funds by November 25, warning that law enforcement would get involved otherwise. No public evidence indicates the attacker returned any funds by that deadline. Poloniex froze withdrawals, ran a security review with CertiK tracing the outflows across roughly 681 wallets, and resumed deposits and withdrawals around mid-November (CoinLive). Sun committed to reimbursing affected users in full from company reserves rather than from recovered stolen funds — a distinction that matters: the $126 million itself was never clawed back, it was absorbed by the exchange (DeFi Teller). Poloniex continued operating after the incident.

What this means

  • The exploit sat entirely in exchange operations, not in any smart contract users interacted with — no amount of due diligence on a token or protocol would have flagged this risk in advance.
  • Hot-wallet key compromises are invisible to depositors until the exchange discloses them; the only mitigant available to users is capping the balance held on any single exchange, not trying to assess key-management practices from outside.
  • A same-day "we're doing maintenance" statement followed by a slow, incremental upward revision of the damage estimate (~$100M to $126M) is a recurring pattern across CEX hacks — initial official statements tend to understate scope.
  • Reimbursement funded from company treasury rather than recovered assets means an exchange's solvency after a hack depends on its own balance sheet — a detail rarely visible to users when they choose where to custody funds.

On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.