A compromised operator drained the Heco bridge for over $86M
Two weeks after Poloniex, a second Justin Sun-linked platform fell in November 2023: a cross-chain bridge lost more than $86M, with the HTX exchange hit in the same day.
On November 22, 2023, the Heco Chain bridge — the cross-chain link tied to Justin Sun's HTX exchange, formerly Huobi — began pushing out large withdrawals. PeckShield first flagged a suspicious transfer of 10,145 ETH, worth about $19 million, and the total drained from the bridge topped $86.6 million, Cointelegraph reported.
The stolen assets spanned ether, USDC, LINK, SHIB and other tokens, per Cointelegraph. Crucially, PeckShield noted the withdrawals were initiated by the bridge's own operator account — the privileged key that runs the bridge — pointing to a compromised operator rather than a flaw in the code.
One bad key, two platforms
The bridge was not the only casualty. In the same window, HTX's exchange hot wallet was drained as well; estimates of that separate loss ran from roughly $13.6 million to more than $23 million, and outlets put the combined damage near or above $100 million. PeckShield observed that the compromised operator account had been active since October 2022, suggesting the key was exposed long before it was finally used, per Il Cryptonomista.
It was the second Sun-linked platform breached in two weeks, after the Poloniex theft — and PeckShield noted on-chain overlap between the incidents, per Il Cryptonomista. Sun said HTX would fully compensate users for the hot-wallet losses and paused deposits and withdrawals, Cointelegraph reported.
The pattern was becoming familiar. As security firms documented across 2023's exchange breaches, the biggest losses rarely came from clever contract exploits; they came from stolen keys and hijacked privileged accounts. A bridge magnifies that danger, because one operator key can command a pool of assets belonging to thousands of users at once.
Why bridges are a bigger target
- Bridges concentrate risk. A single operator key can control a pool of many users' assets across chains — one leak can empty the lot.
- Privileged access is the prize. Most large 2023 losses came from stolen keys and operator accounts, not exotic contract bugs.
- Long-dormant compromises are real. A key can be stolen months before the funds move; a quiet wallet is not proof of safety.
- Minimize time on bridges. Move assets across and then off; do not leave balances parked in a bridge contract.
For everyday users the takeaway is narrow and firm: cross-chain bridges are among the most heavily attacked plumbing in crypto, and the less time your money spends sitting inside one, the smaller your exposure.
— Sources: [Cointelegraph](https://cointelegraph.com/news/heco-chain-bridge-hack-86-million-lost) · [Il Cryptonomista](https://en.cryptonomist.ch/2023/11/22/new-110-million-crypto-hack-heco-bridge/)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING