BitoPro Hack: Lazarus Group Linked to $11M Crypto Theft
- taiwanese cryptocurrency exchange BitoPro is pointing fingers at the Lazarus Group, a North Korean hacking association, following a May 8 cyberattack.
- BitoPro attributed the cryptocurrency theft to Lazarus after internal investigations revealed similarities to past attacks.
- The company said the attack patterns mirrored those used in previous major international incidents, including illicit transfers from global bank SWIFT systems and asset theft incidents from major...
BitoPro, a Taiwanese cryptocurrency exchange, suffered an $11 million crypto heist orchestrated by the infamous Lazarus Group. this cyberattack involved compromised cloud infrastructure, resulting in the theft across multiple blockchains, including Ethereum and Solana. The attackers, employing sophisticated tactics, hijacked AWS session tokens to bypass security measures.The stolen funds were then laundered through decentralized exchanges. BitoPro,while confirming no internal involvement,is now enhancing its security and collaborating with law enforcement. For more insights into blockchain security breaches and how the industry is fighting back, visit News Directory 3. Discover what’s next in the ongoing battle against cyber threats in the crypto space.
Taiwan’s BitoPro Exchange Claims $11M Crypto Hack by Lazarus Group
Updated June 21, 2025
taiwanese cryptocurrency exchange BitoPro is pointing fingers at the Lazarus Group, a North Korean hacking association, following a May 8 cyberattack. The exchange says the attack resulted in the theft of cryptocurrency worth $11 million.
BitoPro attributed the cryptocurrency theft to Lazarus after internal investigations revealed similarities to past attacks. The exchange supports fiat deposits and withdrawals in TWD and a variety of crypto assets, serving primarily Taiwanese users. It boasts over 800,000 registered users and a daily trading volume around $30 million.
The company said the attack patterns mirrored those used in previous major international incidents, including illicit transfers from global bank SWIFT systems and asset theft incidents from major international cryptocurrency exchanges.

The May 8 incident occurred during a hot wallet system update. hackers executed unauthorized withdrawals from an older hot wallet across multiple blockchains, including Ethereum, Tron, Solana, and Polygon. The stolen funds were later laundered through decentralized exchanges (DEXs) and mixers such as Tornado Cash, thorchain, and Wasabi Wallet.
BitoPro publicly acknowledged the incident June 2, noting operations remained unaffected and impacted hot wallets were replenished. The exchange stated that the investigation confirmed no internal involvement, despite attackers launching a social engineering attack and implanting malware on an employee’s device managing cloud operations.
Attackers hijacked Amazon Web Services (AWS) session tokens to bypass multi-factor authentication (MFA), gaining control of BitoPro’s cloud infrastructure. A command-and-control (C2) server then delivered commands to the implant, injecting scripts into the hot wallet host as the attack was prepared. During the wallet upgrade and asset transfer, the cryptocurrency theft occurred while simulating normal operational behavior to avoid immediate detection.
Upon detecting the compromise, BitoPro shut down the hot wallet system and rotated cryptographic keys. The company reported the incident to authorities and engaged a cybersecurity expert, completing the investigation June 11.
The Lazarus Group is known for targeting cryptocurrency and decentralized finance entities. The group is believed to be responsible for important digital asset heists, including a $1.5 billion theft from Bybit.
What’s next
BitoPro is enhancing its security protocols and working with law enforcement to recover the stolen funds and prevent future attacks. The incident highlights the ongoing threat of sophisticated cyberattacks targeting cryptocurrency exchanges.
