Skip to main content
Sign in

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·46hL5g…t3cY

Summary

BitoPro is a Taiwanese centralized cryptocurrency exchange operated by BitoGroup, serving over 800,000 users with TWD (New Taiwan Dollar) fiat on/off-ramps. On May 8, 2025, the exchange suffered an approximately $11.5 million hot wallet theft attributed to North Korea's Lazarus Group via a social-engineering and AWS-token-hijacking attack. The exchange did not publicly disclose the breach for approximately 25 days, only confirming the incident after on-chain investigator ZachXBT flagged suspicious outflows on June 2, 2025.

Connected Entities

1 entities
Organizations
BitoPro
Relationships
    Have evidence about BitoPro?

    Timeline(6 events)

    2018

    BitoPro exchange launched by BitoGroup (BitoEX team), providing TWD fiat crypto trading in Taiwan.

    8 May 2025

    Lazarus Group (alleged) exploits BitoPro hot wallets during a routine system upgrade, stealing approximately $11.5 million across Ethereum, Tron, Solana, and Polygon via malware, AWS session token hijacking, and C2-directed withdrawals.

    2 June 2025

    ZachXBT publicly flags approximately $11.5 million in suspicious hot wallet outflows from BitoPro on Telegram, stating the exchange was 'likely exploited.' ZachXBT documents the laundering trail through Tornado Cash, ThorChain, and Wasabi Wallet.

    2 June 2025

    BitoPro confirms the security breach approximately three hours after ZachXBT's public post, stating an 'old hot wallet' was compromised during a system upgrade. The exchange states user funds are unaffected and have been replenished from internal reserves.

    3 June 2025

    Major outlets including Fortune, CoinDesk, and CryptoNews report on the confirmed BitoPro hack. CoinGecko data shows a 21% drop in exchange trading volume following public disclosure.

    11 June 2025

    BitoPro announces completion of external cybersecurity investigation, attributing the attack to Lazarus Group based on TTPs consistent with prior Lazarus operations including SWIFT-system exploits and previous exchange heists.

    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (1 event).

    model: claude-sonnet

    generated: 5/4/2026, 4:05:05 PM

    last updated: 8/29/2026, 1:35:51 AM

    avoid.net — verified advice for a post-truth world