Incident case

HECO Bridge 2023 operator-key compromise

On November 22, 2023, HECO Bridge was drained after the bridge operator wallet was compromised. HTX confirmed a cyberattack affecting HTX and HECO Chain and suspended affected transfer services; independent security analysis attributed the bridge component to operator-key compromise and estimated approximately $86.6 million drained from HECO Bridge.

reviewedcurrent

Incident facts

Incident title
HECO Bridge 2023 operator-key compromise
Bridge
HECO Bridge
Incident date
2023-11-22
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum, Unknown
Affected assets
Unknown
Attack category
Private Key Compromise
Reported loss
Approximately $86.6 million
Amount confidence
Medium
Loss amount basis
Independent Security Analysis Corroborated By Contemporaneous Reporting
Recovery
Unknown
Reimbursement
Unknown
Restart
Paused
Current outcome
Unknown
Postmortem
Partial
Resolution
Unresolved
Last reviewed
2026-09-04
Last verified
2026-09-04

Amount and valuation

Independent security analysis and contemporaneous reporting estimated approximately $86.6 million drained from HECO Bridge. HTX separately reported hot-wallet losses; those exchange losses are excluded from this bridge amount.

The canonical amount is bridge-specific. It must not be combined with HTX hot-wallet losses disclosed in the same incident window.

Why this remains unresolved

Timeline events

  • HECO Bridge compromised and affected transfer services suspended2023-11-22

    HTX confirmed a cyberattack affecting HTX and HECO Chain and suspended affected deposits, withdrawals, and the HECO Chain gateway while investigating. Independent analysis attributed the bridge drain to compromise of the bridge operator wallet.

    Exploit Detected And Bridge PausedHigh

    HTX hot-wallet compensation is outside the HECO Bridge reimbursement boundary.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.