Odin.fun's Third Bitcoin DeFi Breach in Six Months Drains $7 Million
In under two hours on August 12, 2025, attackers drained 58.2 BTC from Odin.fun, the Bitcoin-token trading platform built by founder Bob Bodily and marketed as the "world's fastest Bitcoin token trading" venue. The roughly $7 million loss marked the platform's third significant security failure in six months, following a deposit-synchronization glitch in March and a compromise of Bodily's personal account in April.
01How the exploit unfolded

According to on-chain analysis from PeckShield, the attackers deposited low-value SATOSHI tokens into Odin's automated market maker, used them to distort the AMM's internal price ratios, and then withdrew genuine Bitcoin at the inflated exchange rate. Coverage from CoinDesk describes the sequence plainly: deposit worthless tokens, manipulate the pool's pricing without external validation, withdraw at the manipulated rate, exit with real BTC.
The underlying flaw was that Odin's recently updated AMM relied on its own internal pricing math rather than checking it against outside market data — a design choice that let the attack drain funds in under two hours.
Bodily's first public acknowledgment came only after the platform's Bitcoin reserves had already fallen from 291 BTC to 232.8 BTC: "Hi everyone - we're looking deeper into the recent withdrawals from the platform, so we've paused trading to ensure we can protect user funds." A further eight hours passed in silence before any additional update followed — time during which the stolen 58.2 BTC moved through multiple wallets.
02The wallets behind the attack
PeckShield traced the theft to two accounts. Because Odin.fun runs on the Internet Computer Protocol, users are identified by ICP principals rather than conventional blockchain addresses:
- "Fresh Attack": urguz-m32zo-jlld6-pyy4l-z3c24-jv4pt-5fmll-gq2xd-6siiz-oxkao-xae
- "Sleeper Cell": jeypm-z6t4p-uqshx-dtay4-qgw5d-ca7j5-alviu-fch2d-nmsnc-c4k3k-aae
The timeline behind these two accounts points to advance preparation rather than opportunistic discovery. The Fresh Attack account was created on August 12, roughly one hour before Bodily's suspension announcement, and was funded and put to use immediately. The Sleeper Cell account, by contrast, was created back on June 20, made a handful of small SATOSHI purchases, and then sat dormant for 53 days. On August 12, that dormant account reactivated; twenty-three minutes later, the Fresh Attack account appeared, funded and ready.
Both accounts remain active on Odin.fun, their full transaction histories publicly visible and showing a repeated pattern: buy tokens, add liquidity, push prices up, withdraw Bitcoin, repeat. Sleeper Cell concentrated on SATOSHI, the token PeckShield identified as the core attack vector, while Fresh Attack also touched ODINPEPE and several other tokens. Reporting also references additional fresh accounts running the same pattern, with funds routed through intermediary wallets before being cashed out.
The manipulation technique itself was not novel. Similar AMM-pricing exploits had previously hit Midas Capital twice in 2023 (again) and Hundred Finance the same year, with post-mortems and mitigations already public well before Odin's August incident.
03The response and the "China" claim
In his follow-up statement, Bodily wrote: "Several malicious users, primarily linked to groups in China, took advantage of this vulnerability to steal a significant amount of BTC from the platform." He added that the team had "identified several groups who profited from the exploit" and issued a warning to them: "You have a short window to return the funds before it is too late. This is not a negotiation."
Observers noted the mismatch between that framing and the evidence: the exploit itself required no advanced technique beyond basic AMM manipulation, and the attackers left complete, traceable transaction histories on Odin's own platform — not typical tradecraft for sophisticated, state-linked actors. Bodily also said the platform's treasury was insufficient to cover the losses, promising "concrete plans" without a timeline. Reported response measures included contact with U.S. authorities and coordination with Binance and OKX alongside Chinese officials, plus blockchain forensics work. Despite this, Bodily maintained an optimistic tone: "We believe the future of Bitcoin DeFi is massive, and we want you with us when we get there."
04Not the first incident
August was Odin's third security failure since its February 2025 launch. On March 7, a deposit-synchronization bug caused 74 BTC to disappear from user balances while the corresponding mainnet transactions failed to reconcile properly; the issue was resolved within hours and was not classified as a theft.
On April 14, Bodily's personal account was compromised, resulting in $178,700 in liquidated assets. The incident was later attributed to flaws in the platform's "Sign-In With Bitcoin" authentication system. Odin.fun suspended trading platform-wide even though only one account had reportedly been affected, and the ODINDOG token fell 50% amid the panic.
05Founder background and warnings ignored
Bob Bodily's public profile lists a PhD in Educational/Instructional Technology from BYU, along with roles as Co-Founder and CEO of Toniq Labs and Co-Founder and CEO of the Bioniq Bitcoin Ordinals marketplace. His technical background in blockchain dates to 2021, with shipped products to his name.
Security commentators were unsparing about the August exploit's basic nature. "Anyone having some knowledge on DEX pools would know this," s0xToolman of Bubblemaps told Decrypt. "There's no excuse for the team to not know this could happen."
Community warnings had preceded the hack. businessman.eth said he had been telling people for months to withdraw funds from Odin.fun — advice that reportedly got him blocked by Bodily on Twitter. Notably, those warnings overlapped with the period when the Sleeper Cell account was already sitting dormant, pre-loaded with SATOSHI tokens. Separately, Raven Thorogood III summed up the pattern: "Odin.fun launched 6 months ago and has had 3 legit hacks. Averaging a major hack every 2 months. Honestly impressive, just a few more multi million dollar hacks then up only."
Odin.fun launched in February 2025, timed to the height of the memecoin trading boom, as Bodily shifted focus from his earlier ICP ventures toward the Bitcoin-based platform.

06Fallout for the community
Odin's user base split in the aftermath, with some users still accepting the "sophisticated attack" framing and waiting on compensation plans, while longtime critics who had warned about the platform — several while blocked on social media by the founder — saw their concerns validated. The ODINDOG token, which had crashed 50% back in April, took a fresh hit, hurting users who had already absorbed losses from the earlier incident. The timing was particularly stark given that Odin.fun had set volume records in early April, with ODINDOG at one point ranking as the second-highest-volume Bitcoin token of all time.
07A familiar pattern in DeFi
Odin's subsequent public updates described meetings in San Francisco with "strategic partners" and the onboarding of external reviewers. A day later, Bodily reported that "one audit" was underway with "a smaller group, but fast and nimble." At the time of writing, Odin.fun's own website carries no security audit reports or technical documentation, only links to its Twitter and Discord; its CertiK project page likewise shows no completed audits. Bodily's update also referenced FBI involvement and blockchain-forensics support, alongside a message calling the "ODIN•FUN community... the most incredible community in all of crypto."
Repeat exploitation is not unique to Odin.fun in DeFi's history. Midas Capital was hit twice in 2023 — $660K and then $600K — rebranded as Ionic, was then socially engineered out of $6.9M by parties posing as Lombard Finance representatives, and was hacked again as Ionic Money in February 2025. Onyx Protocol suffered a $2.1M exploit in 2023 and a $3.8M repeat in 2024 using the same underlying Compound v2 vulnerability, despite a fix having been published between the two incidents; after the second hack, Onyx shut down and relaunched under a new protocol name. Radiant Capital was hit twice in 2024 — $4.5M via a known Aave-fork bug, then $53M when its 3-of-11 multisig was compromised — though it subsequently ran a structured remediation program offering 70% compensation on smaller deposits. DeltaPrime lost $6M to a private-key issue and then $4.85M to an input-validation flaw roughly two months later in late 2024 — vulnerabilities PeckShield had reportedly flagged in advance — but its founders gave up 33% of their token allocation and committed to paying victims 140% of losses through future revenue, working through roughly $11M in total damages.
What sets Odin.fun apart is the compressed timeline: three separate security failures inside six months, each involving Bodily directly as founder or as the account holder himself, with no gap between incidents comparable to the other cases above.
As of publication, the treasury remains unable to cover the losses, no firm compensation timeline has been announced, and the two attacker accounts identified by PeckShield remain active on Odin.fun with their transaction histories intact.
Get new scam files the moment we publish them — usually 2–3 emails a week.