Worked example · 2021-12
BitMart hot-wallet compromise — Ethereum/BNB Chain — 2021-12-05
Summary
On 2021-12-05, an attacker extracted BitMart's hot-wallet private key — likely via a compromise of the exchange operator's 1Password vault or an equivalent operational credential store — and used the compromised private key to drain approximately $196M in assets from BitMart's Ethereum and BSC hot wallets simultaneously. The Ethereum-side extraction was approximately $100M; the BSC-side extraction was approximately $96M. The attacker then routed stolen assets through 1inch aggregation swaps into Tornado Cash, mixing the proceeds through standard mixer-hop chains.
BitMart CEO Sheldon Xia publicly confirmed the breach and identified the hot-wallet private-key compromise as the root cause. The 1Password compromise vector was widely reported in forensic analyses and industry post-mortems of the period, though BitMart's official statements did not confirm the specific credential-store product. The laundering pattern (1inch → Tornado Cash) was the dominant mixing pathway of the Q4 2021 incident cohort.
BitMart continued operating after the incident, with the exchange absorbing the loss and restructuring its hot-wallet custody architecture. Partial funds were frozen across cooperating exchanges, though the bulk of the extracted proceeds were successfully laundered through Tornado Cash.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2021-12-04 to 2021-12-05 (pre-event) | Attacker gains access to BitMart's 1Password vault or operational credential store, extracting the Ethereum and BSC hot-wallet private keys | T11.001 (initial access — signing-vendor compromise) |
| 2021-12-05 | Attacker drains ~$100M from BitMart's Ethereum hot wallet | T5.001 (extraction — chain 1) |
| 2021-12-05 | Attacker drains ~$96M from BitMart's BSC hot wallet | T5.001 (extraction — chain 2) |
| 2021-12-05 (within hours) | Attacker routes stolen assets through 1inch aggregation swaps into Tornado Cash | T7.001 (mixer-routed hop) |
| 2021-12-05 | BitMart CEO Sheldon Xia publicly confirms the breach; exchange suspends withdrawals | (operator response) |
| 2021-12-05 onward | Partial fund freezes across cooperating exchanges; BitMart restructures hot-wallet custody architecture | (recovery — partial freeze) |
Public references
- BitMart official incident statement via CEO Sheldon Xia, December 2021 —
[bitmartpostmortem2021]. - PeckShield on-chain trace of the Ethereum and BSC extraction transactions —
[peckshieldbitmart2021]. - SlowMist forensic analysis of the 1Password-to-Tornado-Cash attack chain —
[slowmistbitmart2021]. - Rekt News public-facing summary —
[rektbitmart2021]. - Cross-reference: T11.001 (Third-Party Signing Vendor Compromise) at
techniques/T11.001-third-party-signing-vendor-compromise.md. - Cross-reference: T7.001 (Mixer-Routed Hop) at
techniques/T7.001-mixer-routed-hop.md. - Cross-reference: T5.001 (Hard LP / Treasury Drain) at
techniques/T5.001-hard-lp-treasury-drain.md.
Discussion
BitMart is the largest recorded 1Password / credential-store-compromise incident in the crypto exchange sector and is the canonical worked example for the operator-side-credential-vendor T11.001 sub-pattern — distinct from blockchain-custodian compromise (e.g., Fireblocks, Copper) and wallet-infrastructure compromise (e.g., Venly / Vulcan Forged). The classification as T11.001 is structurally correct because the load-bearing primitives are identical: signing-authority compromise via a third-party credential vendor, with the resulting on-chain extraction being a downstream consequence of the off-chain secret-theft.
The $196M magnitude makes BitMart the second-largest centralised exchange hot-wallet compromise in the 2021 record by dollar value, behind only Poly Network ($611M, though Poly Network was a cross-chain bridge operator, not a CEX). The 1inch → Tornado Cash laundering pathway is the dominant Q4 2021 mixer-hop pattern and recurs across multiple incidents in the same quarter (BadgerDAO December 2021, AscendEX December 2021, Cream Finance October 2021).