CryptoReal
CASE FILE — Nov 10, 2023

Poloniex Hot Wallets Drained of $126M in Suspected Off-Chain Breach

Justin Sun's exchange Poloniex had its hot wallets drained of $126 million, an incident that quickly overshadowed the market's recent rally.

Alerts were first raised by Cyvers and PeckShield shortly after suspicious outflows began. Roughly thirty minutes into the drain, Poloniex told users its wallet had simply been "disabled for maintenance."

Another thirty minutes later, Justin Sun addressed the incident more directly, pledging to cover losses: "We are currently investigating the Poloniex hack incident. Poloniex maintains a healthy financial position and will fully reimburse the affected funds. Additionally, we are exploring opportunities for collaboration with other exchanges to facilitate the recovery of these funds."

As the scale of the loss became clear, Poloniex announced a whitehat bounty equal to 5% of any returned funds, while blockchain analytics firm Arkham separately offered a $4,000 reward for information identifying the attacker.

Credit: Arkham, SlowMist

Sums referenced in this case file

Exchange breaches of this kind typically trace back to off-chain compromise — an employee or device targeted to extract private keys — rather than a flaw in on-chain code. North Korea's Lazarus Group, known for running extensive phishing operations, has been linked to more than $250 million in stolen funds so far this year, including the Atomic Wallet, AlphaPo, Stake, and CoinEx incidents, leaving open the question of whether the group was behind this attack too.

Whoever was responsible, the drain began at 10:30 AM UTC with a transaction removing 4,900 ETH (about $10 million) from the Etherscan-labeled address "Poloniex 4." The theft then continued across Ethereum, TRON, and Bitcoin. Per Arkham's attacker profile, the $126 million total broke down into $59.2 million on Ethereum, $48.6 million on TRON, and $18.6 million on Bitcoin.

The main attacker-controlled addresses identified were 0x0a5984f86200415894821bfefc1c1de036dbf9e7 on Ethereum, TKK6d1YALy8HCSoCSWWd1ZJhyC9NPPx4wa on TRON, and bc1qnpc7u2ha7ct9c458rrqsawylz9e9j6jvkvzttt on Bitcoin. Stolen funds were also spread across a wider set of Ethereum addresses used to swap tokens into ETH and either hold or further disperse them: 2, 3, 4, 5, 6, 7, 8, 9, 11, 12, 13, 14, and 15.

By asset, the largest losses were 33 million USDT (22 million on TRON, 11 million on Ethereum), 4,900 ETH ($10 million) on Ethereum, $18.6 million in native BTC, a further $14 million in BTC on TRON, and $5 million in USDC on Ethereum. SlowMist compiled an ongoing, not-yet-complete breakdown of the stolen assets.

The attacker's on-chain moves produced some unintended side effects. Converting the freezable USDT stolen on TRON into TRX pushed up the price of Sun's own TRX holdings by roughly 25% — a small, indirect offset against the losses he pledged to cover. Separately, while liquidating stolen assets, the attacker also destroyed almost $2.6 million worth of Golem Network's GLM token by sending it directly to the token's own contract rather than to a wallet.

This isn't the first major breach at an exchange under Sun's influence. HTX (formerly Huobi) lost $7.9 million in late September, with Sun suggesting that reimbursing users would be minor given his available resources. In that case he ultimately avoided a costly payout when the stolen funds were returned less than two weeks later.

This time, the amount Sun has promised to cover is more than ten times larger, and the incentive on offer — a 5% bounty, below the going rate, with a seven-day window for the attacker to decide — leaves open the question of whether it will be enough to secure a return of the funds, and just how far his resources can stretch if it isn't.

CEXJustin SunPoloniex
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.