WOO X Confirms $14 Million Hot Wallet Breach Across Five Blockchains After Phishing Attack
WOO X, the centralized exchange arm of the WOO Network, disclosed a $14 million security breach that began on Thursday, July 24, 2025, after a targeted phishing attack compromised a team member's device. That access allowed attackers to reach WOO X's development environment and, from there, its hot wallets across five separate blockchain networks: Ethereum, Bitcoin, BNB Chain, Arbitrum and Tron.
01Timeline

By 2:09 PM UTC on July 24, WOO X posted its first public statement, describing the situation as "a contained incident that occurred on WOO X earlier today." Within the hour, it became apparent that nine user accounts had experienced unauthorized withdrawals, with losses eventually totaling roughly $14 million spread across the affected networks.
WOO X later said it had "quickly detected" the intrusion and blocked a number of withdrawal attempts, though the $14 million in losses had already occurred by that point. By 3:04 PM UTC, blockchain security firm Cyvers Alerts was publicly tracking the outflows in real time, while WOO X's own communications continued to describe the event as "contained."
02Tracing the Funds On-Chain
WOO X's public statements initially framed the incident as a series of "user account" compromises. On-chain data, however, showed funds moving directly out of WOO X's own hot wallets to attacker-controlled addresses. A follow-up update on July 26 said the exchange would reimburse the "9 user account" losses from its company treasury.
Ethereum Hot wallet: 0x63DFE4e34A3bFC00eB0220786238a7C6cEF8Ffc4 Attacker addresses: 0x87aab7bac1308fAF2A0d59DA26b8379e18b26355, 0x889b49ef0bf787c3ddc2950bfc7d1d439320004b, 0x77167f0bc412eb39d004f354869938e7c5acd518, 0x14896E88E0F7dCe1FB88A979439C2f87b416c024
Bitcoin Hot wallet: bc1qm4hycszv0v0qel3swxqyp57nkpnnrda4rc55lm Attacker addresses: bc1q4xm6y972qa82f4cudr4d28xdhxa4e68v5atrej, bc1qut0g2uflywfcycuftuek7944p6hhxgm2p92fzm, bc1qvd58w5kperw3hzu7j5gkca8rxkzwd7vjxtu2gh, Bc1qtzlpu326jcqnx8tnhrkqcfxjhn9e02zfutzsch, Bc1qxvft9ytzjx50ylqnglc0fsd5ck0v6hayl2xsyh
BNB Chain (BSC) 5.03 BTCB tokens were withdrawn from WOO X's BSC hot wallet. Hot wallet: 0x63DFE4e34A3bFC00eB0220786238a7C6cEF8Ffc4 Attacker addresses: 0x87aab7bac1308fAF2A0d59DA26b8379e18b26355, 0x1891438F4CFDFf9e145285A3f15C8b2C52B571CC
Arbitrum Hot wallet: 0x63DFE4e34A3bFC00eB0220786238a7C6cEF8Ffc4 Attacker addresses: 0x889B49ef0bf787c3ddc2950bFC7D1d439320004B, 0x87aab7bac1308fAF2A0d59DA26b8379e18b26355
Tron Cyvers appears to be the only firm that publicly identified a Tron component to the attack. Rekt was sent an attack transaction trace by Meir Dolev, founder and CTO of Cyvers, confirming that 7 million TRX had been stolen across two transactions. Hot wallet: TDZeVyGHgN5bErmWumuYRtXCrYMoUzKF7L Attacker address: TUchNtdDgLXzhSSC32QaNnzKVPj2rNg8dX
Cyvers' initial estimate placed losses around $12 million; the figure later rose to WOO X's confirmed total of $14 million.
03How the Attackers Got In
WOO X later disclosed that the intrusion began with a phishing attack that compromised a team member's device in a targeted attempt. That foothold gave attackers access to WOO X's development environment, which in turn provided the time and access needed to coordinate withdrawals across the five networks. WOO X continued to describe the episode as a "contained incident" that it had "quickly detected."
Notably, two weeks before the breach, WOO X quietly paused its bug bounty program on Bugcrowd, with the program page citing only that the "client asked to pause."
04Security Claims Under Scrutiny
WOO X's marketing describes the exchange's security posture in terms including "best-in-class security," "ISO/IEC 27001 certified," "enhanced asset security through leading custodians," and an "active bug bounty program" — the last of which had been suspended two weeks prior to the breach.

WOO X's Proof of Reserves dashboard lists $123.48 million in total assets, or $169.32 million when WOO token holdings are included. The exchange names Fireblocks as its institutional custody partner and states that more than 75% of user assets are held in custody or cold storage under 24/7 monitoring. None of these measures prevented the $14 million loss from WOO X's own hot wallets.
05A Recurring Pattern
This is not the first security failure connected to the WOO ecosystem. In November 2023, Kronos Research — described elsewhere in coverage of the breach as WOO X's largest market maker and incubator — had its API keys compromised in an attack reported at $26 million in one account and $25 million in another; WOO X was forced to pause trading because Kronos served as its primary liquidity provider. In March 2024, WooFi, the DeFi arm of the WOO Network, lost $8.5 million to a flash loan attack that manipulated its oracle pricing system.
Counting the July 2025 WOO X breach, the wider WOO ecosystem has now experienced three distinct security failures in under two years, spanning API key compromise, oracle manipulation, and phishing combined with development-environment access.
The incident also fits a broader industry trend: rather than targeting smart contract code directly, attackers are increasingly compromising the individuals who hold privileged access, often through phishing. WOO X has said it intends to fully compensate affected users.
Get new scam files the moment we publish them — usually 2–3 emails a week.