Status DataClose notification

BigONE Launches $8.1M Hack Bounty for Web3 Security and Fund Recovery After $27M Exploit

Andrii Stepanov
Andrii Stepanov
Security Researcher

Introduction

In July 2025, BigONE, a global cryptocurrency exchange that provides a platform for trading various cryptocurrencies, suffered a major crypto exploit, now known as the BigONE hack, resulting in the loss of $27 million in digital assets.

To help identify the attacker and support fund recovery, BigONE has launched a hack bounty program with rewards of up to $8.1 million. The initiative invites white hat hackers and Web3 security experts to contribute to the investigation.


What Happened? (Incident Summary)

The security breach stemmed from a compromised developer environment via sophisticated social engineering techniques. Malicious code exploited a smart contract vulnerability, altering accounting logic and enabling unauthorized fund withdrawals from a hot wallet. Stolen assets were subjected to cross-chain laundering using decentralized exchanges and cross-chain bridges.


What We’re Looking For?

BigONE invites white hat hackers, OSINT researchers, and forensic analysts to submit intelligence, including:

  • Wallet addresses tied to the exploit (wallet analysis);
  • IP addresses, domains, and server infrastructure;
  • Centralized exchange activity or behavioral patterns;
  • Coin mixing strategies or cross-chain fund flows;
  • Any relevant on-chain or off-chain forensic data that can aid in attack tracing and support a broader blockchain investigation.

Rewards and Rules

This crypto bug bounty initiative features structured bounty tiers and flexible white hat rewards:

  • Low Impact: $100–1,000
  • Medium Impact: $1,000–5,000
  • High Impact: $5,000+
  • Additional Bonus: Up to 10–30% of recovered funds (maximum $8.1M bounty)

Each exploit reward is determined individually by BigONE, based on the impact, difficulty, and significance of the submission.


How to Participate

  • Analyze blockchain traces, attacker infrastructure, or transaction activity related to the BigONE exploit;
  • Report exploit details or submit vulnerability findings through the HackenProof platform;
  • Bounty program submissions can be made anonymously.

Think you can help trace the $27M exploit? Join BigONE’s $8.1M Hack Bounty Program on HackenProof. Submit intel, earn rewards, and take part in a global recovery mission!

Share article:
More topics:

Read more on HackenProof Blog