At 02:13 UTC on December 5, 2021, BitMart founder and chief executive Sheldon Xia confirmed that the cryptocurrency exchange had suffered what he called a large-scale security breach involving one Ethereum hot wallet and one Binance Smart Chain hot wallet. BitMart estimated that the intruder withdrew approximately $150 million in digital assets and suspended all withdrawals while it reviewed security.

The exact chronology matters. BitMart's consolidated incident page dates the abnormal activity and its internal identification to December 4. The company confirmation carried a December 5 UTC timestamp, after blockchain-security firm PeckShield had publicly flagged suspicious outflows. This archive entry therefore records the December 5 confirmation and exchange-wide withdrawal freeze, not a claim that every unauthorized transfer occurred on December 5.

Two loss estimates, neither a final audit

BitMart's approximately $150 million figure was the exchange's initial estimate. The company said the two affected hot wallets held only a small percentage of its assets and that its other wallets were secure and unharmed. Those statements described BitMart's preliminary assessment; no independently audited reserve inventory or asset-by-asset reconciliation accompanied them on December 5.

PeckShield produced a higher estimate: about $100 million in tokens on Ethereum and another $96 million on Binance Smart Chain, for roughly $196 million combined. That estimate came from token quantities attributed to the affected wallets and market values observed during a fast-moving incident. It was not equivalent to BitMart's accounting figure. Prices differed by token and observation time, and illiquid assets could not necessarily have been sold for their quoted value. The defensible event-day range was therefore not a settled loss but two clearly attributed estimates—approximately $150 million from BitMart and approximately $196 million from PeckShield.

Contemporaneous reporting described the attacker exchanging assets through the 1inch decentralized-exchange aggregator and sending ether toward Tornado Cash. Public ledgers can verify transactions from identified addresses, but wallet labels and the conclusion that multiple addresses belonged to one attacker depended on attribution by investigators and explorers. On-chain visibility did not reveal the person's identity or establish BitMart's ultimate liability to customers.

Why the freeze mattered

The incident exposed the operational tradeoff at a centralized exchange. Customers could trade many blockchain assets through one account, but BitMart controlled the signing keys and the withdrawal gateway. When two online wallets were compromised, the exchange could halt withdrawals across the platform, including for assets not identified as stolen.

That action was protective from the operator's perspective, yet it also left customers unable to remove funds while relying on BitMart's internal review. On December 5 there was no published completion time for that review, no verified schedule for restoring withdrawals and no public accounting of how losses would be allocated.

The breach also showed why a dollar estimate alone could mislead. The affected wallets held numerous tokens across two networks, so investigators had to identify transfers, value different assets and avoid double counting swaps. A large headline number did not prove that the same amount of customer claims had crystallized in dollars.

What was still unknown on December 5

BitMart had not identified the compromise method in its December 5 confirmation. It had not published a forensic report, named an attacker, documented insurance coverage or promised a specific reimbursement mechanism. Claims about a stolen private key and compensation belong to the next day's record.

Later context

On December 6, BitMart said a stolen private key had compromised the two hot wallets, pledged to use its own funding to compensate affected users and said deposits and withdrawals would begin returning gradually on December 7. Those later company statements clarify the response but were not available when the December 5 confirmation first defined the event.

Primary sourceBitMart — Security Breach Update

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.