HTX acknowledged on November 22, 2023 that its exchange and the Heco network had been targeted in a cyberattack, while Ethereum records showed 10,145 ETH leaving the Heco bridge in a transaction at 09:59:35 UTC. HTX temporarily suspended deposits and withdrawals on its platform and through the Heco gateway as it investigated.
The development mattered because it joined two forms of concentrated crypto infrastructure risk. A cross-chain bridge depended on privileged controls to release assets held on Ethereum, while exchange customers depended on HTX to keep hot-wallet assets secure and withdrawals available. One incident therefore impaired both a protocol connection and a centralized service boundary.
What was verified on November 22
The Ethereum transaction succeeded in block 18,626,540. Its internal trace records 10,145 ETH moving from the Heco bridge contract to the receiving address later labeled “Heco Bridge Exploiter” by Etherscan. The call came from the address labeled HTX 54 and invoked the bridge’s native-withdrawal function. The ledger establishes the time, quantity, addresses and successful execution. Address labels are explorer metadata, however, and do not independently identify the person controlling a wallet or prove how authorization was obtained.
HTX’s notice, timestamped 21:38 in UTC+8, said the company had detected attacks involving HTX and Heco, begun an investigation and taken emergency protective measures. It estimated that $30 million of assets in an HTX hot wallet were affected and promised to compensate HTX users for hot-wallet losses. That amount and reimbursement pledge were company statements, not an independent loss audit or proof that compensation had occurred on November 22.
Contemporaneous analysis reported by The Block placed the Heco bridge outflow at approximately $86.6 million, attributing the estimate to PeckShield and Wintermute research head Igor Igamberdiev. The report separately described about $23.4 million in suspicious HTX transfers. Those were analyst estimates based on observed token movements and then-current values; they should not be added mechanically to HTX’s later $30 million figure, which used a different scope and undisclosed valuation method.
Why the bridge failure mattered
A bridge can hold assets on one chain while authorizing corresponding value to move elsewhere. That design makes the authority controlling withdrawals a critical security boundary. The November 22 transaction did not show a failure of Ethereum consensus: Ethereum finalized a call presented to the bridge contract. The unresolved question was why a withdrawal of that size had valid authority.
The distinction is institutional as well as technical. Users could see transfers on a public ledger, but only HTX and Heco’s operators could immediately explain their internal key management, monitoring and recovery controls. Suspending deposits and withdrawals limited further operational exposure, while also preventing customers from moving assets during the investigation. HTX’s assurance that other funds were secure remained an attributable claim rather than independently verified proof of reserves.
Limits of the event-day record
By the end of November 22, the public record did not establish the attacker’s identity, whether one actor controlled both sets of transfers, the final net loss, the number of affected users or the amount recoverable through freezes and negotiations. The approximate dollar figures also mixed fixed token quantities with market prices sampled at unspecified moments and venues. No defensible event-window price or trading-volume effect can be isolated from the wider crypto market, so this reconstruction makes no market-causation claim.
Later clarification
On November 23, security firm CertiK described the Heco bridge event as an operator-wallet compromise and catalogued 10,145 ETH plus USDT, HBTC, SHIB, UNI, USDC, LINK and TUSD withdrawals worth approximately $87 million at its measurement time. CertiK estimated suspicious Heco and HTX movements at about $113.3 million overall, but included an unconfirmed 73.797 BTC transfer and excluded illiquid tokens from part of its calculation. That analysis sharpened the suspected mechanism; it did not turn the November 22 uncertainties about attribution, recoveries or customer losses into settled facts.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

