top of page

$3.5B Bitcoin heist from 2020 retroactively uncovered — Arkham Intel

 $3.5B Bitcoin heist from 2020 retroactively uncovered — Arkham Intel
Published date:
Source:
BB Finews
8/9/25, 6:46 AM

Chinese mining pool LuBian was hacked in 2020 for 127,426 Bitcoin (BTC), valued at about $3.5 billion at the time, making it the biggest crypto hack in history, according to blockchain analytics platform Arkham Intelligence.

The platform retroactively uncovered the heist on Saturday, claiming that LuBian, which emerged as the sixth-largest BTC mining pool at the time, was first hacked on December 28, 2020. 

About 90% of the pool’s BTC was stolen by the threat actor before LuBian was able to move its remaining 11,886 BTC to recovery wallets. Neither the platform nor the hacker publicized the attack at the time, the intelligence platform said.

Cybercrime, Mining Pools, Cybersecurity, Hacks
Funds stolen from LuBian through multiple transactions. Source: Arkham Intelligence

The mining pool embedded an OP_RETURN message to each of the wallet addresses belonging to the hacker in 1,516 different messages, which cost it about 1.4 BTC. Arkham’s team also wrote:

“It appears that LuBian was using an algorithm to generate its private keys that was susceptible to brute-force attacks. This may have been the vulnerability exploited by the hackers.”

The stolen Bitcoin is now worth about $14.5 billion at current prices, and the attack highlights the need for crypto users to practice proactive safety measures and private key management, relying on only the most robust random number generators to create keys.

Cybercrime, Mining Pools, Cybersecurity, Hacks
The OP_Return messages sent from LuBian to the hacker addresses. Source: Arkham Intelligence

Related: Crypto hacks top $142M in July, with CoinDCX leading losses

LuBian hack tops the ByBit hack and other infamous crypto heists

In February, the ByBit exchange was hacked for $1.5 billion and the attack was reported as the single biggest crypto hack in history at the time.

The ByBit attack was attributed to a compromised SafeWallet developer machine, according to a post-mortem report from SafeWallet and cybersecurity firm Mandiant.

These hackers likely exploited the developer’s machine by installing malware on the system and then using that developer’s Amazon Web Services (AWS) tokens while the developer was online and active.

This allowed the hackers to access sensitive systems without setting off any alarm bells or triggering a response from the team.

In April, an elderly individual lost $330 million in Bitcoin through a social engineering attack, which was laundered through 300 different wallet addresses.

The BTC heist was considered the fifth-largest crypto heist in history at the time, and only $7 million of the $330 million was frozen in the immediate wake of the attack.

Magazine: Inside a 30,000 phone bot farm stealing crypto airdrops from real users

24 Hot News

Bitcoin’s price drops below $115K – Watch out for THESE 4 reversal signs!

Bitcoin’s price drops below $115K – Watch out for THESE 4 reversal signs!

BB Finews
 Taiwan’s first Bitcoin treasury Top Win raises $10M for BTC purchases

Taiwan’s first Bitcoin treasury Top Win raises $10M for BTC purchases

BB Finews
Ripple – 3 signals hint XRP could lead altcoins into Q3

Ripple – 3 signals hint XRP could lead altcoins into Q3

BB Finews
Inside the Aave – WLFI proposal: Rumors, revenue sharing, and governance?

Inside the Aave – WLFI proposal: Rumors, revenue sharing, and governance?

BB Finews
 Kraken pauses Monero deposits following 51% attack

Kraken pauses Monero deposits following 51% attack

BB Finews
Big chocolate has a growing taste for lab-grown cocoa

Big chocolate has a growing taste for lab-grown cocoa

BB Finews
Mantle dips 9% as outflows rise: Can THIS group’s $60 mln buy help?

Mantle dips 9% as outflows rise: Can THIS group’s $60 mln buy help?

BB Finews
5 bold crypto predictions for 2026

5 bold crypto predictions for 2026

BB Finews
 US Fed to end oversight program for banks’ crypto activities

US Fed to end oversight program for banks’ crypto activities

BB Finews
  • Page 11

Disclaimer:

This article is an original work by BBFinews, with copyright owned by Jinse Finance. Unauthorized reproduction is prohibited. Authorized media must indicate: “Source: BBFinews” when using this content. Violators will be held legally accountable.

 

Risk Warning:

Investment involves risks. Please exercise caution when entering the market. This content does not constitute investment or financial advice.

bottom of page