Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› BitMart Hot Wallet Hack 2021: How One Stolen…
Breach analysis Incident: 4 Dec 2021

BitMart Hot Wallet Hack 2021: How One Stolen Private Key Drained About $150 Million

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 10 min read
Category: NHI
On this page

On Saturday 4 December 2021, blockchain security firm PeckShield spotted tens of millions of dollars flowing out of an address belonging to BitMart, a Cayman Islands-based cryptocurrency exchange. Over the weekend the attacker emptied two of BitMart's hot wallets, one on Ethereum and one on Binance Smart Chain. BitMart put the loss at about $150 million; PeckShield estimated it at close to $200 million. On Monday 6 December, BitMart chief executive Sheldon Xia confirmed the cause: "This security breach was mainly caused by a stolen private key that had two of our hot wallets compromised." No smart contract was broken. Whoever held the key could sign transactions as BitMart, and the blockchain treated them as legitimate. BitMart has never publicly explained how the key was stolen. It suspended withdrawals, promised to cover losses from its own funds and began reopening withdrawals from 7 December, but a month later some users told CNBC they were still waiting to be repaid.

Key takeaways

  • BitMart confirmed that a stolen private key let an attacker drain two hot wallets in December 2021, one on Ethereum and one on Binance Smart Chain.
  • BitMart put the loss at about $150 million; PeckShield estimated about $200 million, roughly $100 million on Ethereum and $96 million on Binance Smart Chain, according to Decrypt.
  • PeckShield described the theft as "Pretty straightforward: transfer-out, swap, and wash", with tokens swapped through 1inch and laundered through Tornado Cash.
  • BitMart has not disclosed how the key was stolen. It pledged to compensate users from its own funds, but CNBC reported in January 2022 that some users were still waiting.
  • The identity lesson: a hot wallet key is a machine credential with direct authority over money, and one copy of it in the wrong hands is enough.

At a glance

OrganisationBitMart, a cryptocurrency exchange based in the Cayman Islands
WhenTheft on Saturday 4 December 2021, reported publicly by PeckShield the same day; BitMart confirmed the stolen key on 6 December 2021
AttackerUnknown; no attribution has been published
Entry pointNot disclosed. BitMart says a private key for two hot wallets was stolen; how it was obtained has not been made public
Identities abusedThe private key (or keys) controlling BitMart's Ethereum and Binance Smart Chain hot wallets
ImpactAbout $150 million in tokens stolen according to BitMart, about $200 million according to PeckShield; withdrawals suspended; BitMart pledged to repay users from its own funds
CategoryNHI. Incident class: confirmed NHI breach (stolen wallet private key used to drain funds)

What happened

Exchanges keep most customer funds in cold wallets, whose keys are kept offline, and a smaller float in hot wallets, whose keys are online so that withdrawals can be signed automatically. BitMart, which Cayman Compass reported had more than 9 million users and had just closed a Series B round at a $300 million valuation, ran hot wallets on Ethereum and on Binance Smart Chain. On Saturday night, PeckShield noticed large outflows from one BitMart address and raised the alarm, according to Decrypt and Cayman Compass.

The pattern PeckShield saw was simple. "Pretty straightforward: transfer-out, swap, and wash," the firm said. The attacker moved tokens out of the wallets, swapped them through the 1inch aggregator and passed the proceeds through the Tornado Cash mixer to hide where they went, Decrypt reported. PeckShield put the haul at about $100 million in Ethereum-based assets and about $96 million on Binance Smart Chain. Tom's Hardware noted that the theft was the second-largest crypto heist of 2021 behind the $600 million Poly Network hack, whose funds were returned.

BitMart suspended withdrawals that weekend while it ran a security review. On Monday, Sheldon Xia wrote on Twitter: "This security breach was mainly caused by a stolen private key that had two of our hot wallets compromised." He added: "Other assets with BitMart are safe and unharmed." The company said that "The affected ETH hot wallet and BSC hot wallet carry a small percentage of assets on BitMart", and in a second notice Xia said: "BitMart will use our own funding to cover the incident and compensate affected users." BitMart planned to reopen deposits and withdrawals gradually from 7 December.

The cause matters for how this incident is classified. Many 2021 crypto thefts, such as the MonoX attack The Hacker News mentioned alongside BitMart, exploited bugs in smart contract code. BitMart's was different: the exchange itself said a key was stolen, so the attacker did not need any flaw in the blockchain or in a contract. The open question is how the key left BitMart's control. Neither BitMart's statements nor the reporting we read explain it, and Decrypt and CNBC both say it was not explained.

Timeline

DateEvent
4 December 2021PeckShield detects large outflows from a BitMart address and reports the hack publicly; the attacker drains BitMart's Ethereum and Binance Smart Chain hot wallets.
December 2021BitMart suspends withdrawals over the weekend and starts a security review.
6 December 2021CEO Sheldon Xia confirms that a stolen private key compromised two hot wallets and says BitMart will compensate users from its own funds.
7 December 2021BitMart begins gradually restoring deposits and withdrawals.
7 January 2022CNBC reports that some users, particularly safemoon holders, are still waiting to be reimbursed.

How it happened: the identity attack path

  1. Online signing key. BitMart's hot wallets were controlled by private keys kept online so that customer withdrawals could be signed without manual steps.
  2. Key theft. An attacker obtained the private key for the Ethereum and Binance Smart Chain hot wallets. BitMart has not said whether this came from a server compromise, an insider, a leaked backup or something else.
  3. Signed transfers. With the key, the attacker signed transfers out of both wallets. To the blockchain these were valid transactions from BitMart.
  4. Swap and launder. The tokens were swapped through 1inch and moved through Tornado Cash, according to PeckShield and Decrypt.
  5. Containment. BitMart suspended withdrawals, confirmed the key theft and later reopened withdrawals in stages.

Impact

  • Confirmed by BitMart: a stolen private key compromised two hot wallets; about $150 million in tokens was taken; BitMart said the wallets held a small percentage of its assets and that other assets were unharmed.
  • Estimated by PeckShield: close to $200 million in total, about $100 million on Ethereum and $96 million on Binance Smart Chain.
  • Customer impact: withdrawals were suspended for several days. CNBC reported in January 2022 that some safemoon holders had not been repaid about five weeks after BitMart's pledge; BitMart told CNBC "We will support all user withdrawals" and declined to say whether it would use insurance or run an internal audit.
  • Unknown: how the key was stolen, who stole it and whether any funds were recovered have not been publicly confirmed.

What this means for NHI governance

A hot wallet key is a non-human identity in its purest form. It is a secret held by software, it authenticates without a person present, and anything it signs is accepted as genuine. There is no password reset, no second factor and no bank to reverse a payment. Once the attacker had the key, the only remaining controls were the ones BitMart had placed around it: how much value it could reach, how fast transfers were allowed to leave and how quickly someone noticed. In this case an outside firm watching the chain spotted the theft first.

The same pattern appears in other key theft cases in our database, from the stolen Microsoft signing key in the Microsoft Storm-0558 key breach to the developer session tokens behind the Bybit hack. Signing keys should live in hardware security modules or multi-party computation schemes, so that no single system or person ever holds a complete usable key, and the value any single key can move should be capped. Our Cryptographic Key Management Guide and Financial Services Identity Security Guide cover these controls.

Recommendations

  • Keep signing keys in hardware or split them. Use HSMs, multi-signature wallets or multi-party computation so that one stolen file or one compromised server cannot sign alone. See our Cryptographic Key Management Guide.
  • Limit what a hot key can reach. Hold only the float needed for withdrawals in hot wallets and refill them from cold storage in controlled steps.
  • Enforce transaction policy outside the key. Apply velocity limits, destination allow-lists and approval thresholds in a separate policy engine that a key holder cannot bypass.
  • Monitor on-chain outflows in real time. Alert on unusual volume and on transfers to swap aggregators or mixers; in this case an outside firm saw the drain first. See our ITDR Guide.
  • Restrict and log access to key material. Treat systems and people that can reach signing keys as privileged, with just-in-time access and full audit. See our Privileged Access Management Guide.
  • Prepare a key compromise runbook. Decide in advance how to freeze withdrawals, move remaining funds to new keys and inform users. See the Leaked Credential Response Playbook.

Frequently asked questions

How was BitMart hacked in 2021?

BitMart said an attacker used a stolen private key to take control of two hot wallets, one on Ethereum and one on Binance Smart Chain, and transferred out about $150 million in tokens on 4 December 2021. PeckShield estimated the loss at close to $200 million. BitMart has not said how the key was stolen.

Was the BitMart hack a smart contract exploit?

No. BitMart's chief executive said the breach was mainly caused by a stolen private key. The attacker signed transfers with BitMart's own key, so the transactions were valid on chain and no contract flaw was needed.

Did BitMart repay the users affected by the hack?

BitMart pledged on 6 December 2021 to cover the losses from its own funds and began restoring withdrawals from 7 December. CNBC reported on 7 January 2022 that some users had been reimbursed for certain tokens but that many safemoon holders were still waiting.

Bybit Hack 2025 · Solana web3.js npm Compromise 2024 · Microsoft Storm-0558 Key Breach 2023 · Cryptographic Key Management Guide · Financial Services Identity Security Guide

How NHI Mgmt Group can help

Signing keys, wallet keys and API secrets are machine identities that move money and data without a person in the loop. We help organisations find where those keys live, who and what can reach them, and how to put hardware protection, limits and monitoring around them. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org