Open app

NexFlow › Is BitMart safe

Is BitMart safe? The exchange whose 'we'll cover it' took a lot longer than its hack

BitMart is this family's honesty check on the phrase every breached exchange uses: 'users will be compensated.' In December 2021 a stolen private key emptied two hot wallets for ~$196 million — one of that year's biggest thefts. The CEO promised company-funded reimbursement within days, and the promise was real. What CNBC documented five weeks later is the part the press release left out: users were still waiting, some tokens were reimbursed while others sat in limbo, and the CEO's listed email bounced. The make-whole reflex existed. So did the gap between pledge and payout.

Updated September 28, 2026 · By the NexFlow editorial desk · Sources linked throughout; vendor claims labeled.

What BitMart is

BitMart is a Cayman Islands-registered centralized exchange founded 2017, claiming several million users across a long-tail listing catalog — the venue class where new tokens list early and liquidity lives on the venue's books. Custody is the standard custodial model: the exchange holds keys, and its hot wallets carry the operational float behind withdrawals.

The December 2021 incident is the record that defines the venue for this family — not because it was the largest hack of its year, but because of what happened in the weeks after the pledge.

December 4-5, 2021: one key, two wallets, ~$196M

PeckShield caught it first: a steady outflow of tens of millions from a BitMart address into what Etherscan labeled the 'BitMart Hacker' wallet — roughly $100 million in Ethereum-chain assets plus ~$96 million on Binance Smart Chain, a mix of more than 45 tokens (BNB, SHIB, and a hefty slice of SafeMoon among them). BitMart's own figure was ~$150 million; PeckShield's on-chain count ran closer to $196 million — a $46 million gap the exchange never explained, which is itself data about how seriously a venue takes its disclosure duty at the worst possible moment.

The mechanism, per CEO Sheldon Xia: a stolen private key controlling two hot wallets — the operational-float wallets, which BitMart said held 'a small percentage' of total assets. The laundering was textbook: swapped through the 1inch aggregator, washed through Tornado Cash — the standard kit for making $196M untraceable — the same laundering path the corpus's Binance and Bitstamp files record. Deposits and withdrawals froze platform-wide pending a security review, and Xia took to Twitter personally within 48 hours to own the narrative.

The pledge — and the five-week gap

On December 6 Xia tweeted the line this family now prices: 'BitMart will use our own funding to cover the incident and compensate affected users… No user assets will be harmed.' Trading resumed December 7; the commitment was public and unconditional-sounding.

What the public record then shows is slower and messier. On January 7, 2022 — five weeks out — CNBC reported victims still unpaid: a SafeMoon holder with $53,000 in tokens (much of it borrowed at 4% interest) frozen in limbo; reimbursements trickling for some tokens (Saitama holders reported payment) while SafeMoon holders waited, missing even their 'reflection' distributions; and Xia's publicly listed email bouncing when CNBC tried it twice. BitMart's spokesperson repeated 'we will support all user withdrawals' — true eventually, and worth precisely what the delay cost the users who needed the money when the pledge was made.

That gap is the lesson this page exists to carry: a cover promise has a price tag AND a timeline, and the second number is the one that determines whether users eat the float. BitMart's pledge eventually functioned — the exchange survived, withdrawals continued, no second incident of that class is on record — but 'eventually' is a different product than 'covered' — and for the SafeMoon holder servicing a 4% loan against tokens he couldn't move, the difference was measured in real interest on real debt, not in adjectives.

What the incident did and didn't establish

The favorable column is real: the breach was scoped to two hot wallets, cold-side and other wallets were untouched, the company did fund compensation from its own pocket rather than socializing the loss, and no subsequent custody failure of this scale is documented — four-plus years of post-incident operation that, fairly, is the strongest line in BitMart's favor on this page. The unfavorable column is also real: a private key walked out of the venue at all; the company's own loss figure and PeckShield's differed by ~$46M without explanation; and the compensation timeline ran on the company's schedule, not users' needs.

The family calibration applies directly: breached + covered is a meaningfully better record than breached + folded — the KuCoin and Binance files make that comparison — but the quality of the cover is measured in days and completeness, not press-release adjectives.

Where BitMart stands

In the breached-and-covered tier, BitMart is the pledge-lag entry: the theft was large, the key compromise damning, the recovery genuine but demonstrably slower than the commitment implied. For a user pricing the venue today, the honest summary is: the hot-wallet layer failed once at scale, the treasury answered over a stretched timeline, and the exchange's subsequent four years carry no repeat — a record to weigh as 'tested, slow, survived' rather than either 'unsafe' or 'proven' — the middle verdict the safety family reserves for venues whose worst day is documented and whose recovery is real but was demonstrably on the venue's schedule, not the user's.

Frequently asked questions

Was BitMart hacked?

Yes — December 4-5, 2021. A stolen private key opened two hot wallets (one Ethereum, one BSC) and drained ~$196M by PeckShield's count (~$150M by BitMart's own figure — a $46M discrepancy never explained). Over 45 tokens went out via 1inch swaps into Tornado Cash. It was among the largest exchange thefts of 2021.

Did BitMart reimburse the hack victims?

Eventually, from company funds — CEO Sheldon Xia pledged full compensation on Dec-6 and trading resumed Dec-7. But CNBC's January-2022 follow-up documented the honest caveat: five weeks in, some tokens were reimbursed while others (notably SafeMoon holders) still waited, and the commitment ran on the company's timeline. Pledge real, payout slow — the distinction this page is built on.

How was only ~$196M affected if the key was stolen?

The stolen key controlled two hot wallets — the operational float used for withdrawals — not BitMart's cold storage or other addresses, which the company says held the bulk of assets and were 'secure and unharmed.' That's the standing hot/cold trade in this corpus: the wallet connected to the internet is the wallet the attacker can reach, and sizing the float is how venues cap the blast radius.

Is BitMart safe to use now?

The honest read from this family: the 2021 breach was a real failure with a real-but-lagged recovery, and no documented repeat in four-plus years since. That prices as 'tested, slow, survived' — better than venues with unresolved losses, weaker than the never-breached or fast-covered tier (CoinEx rebuilt in nine days; Deribit covered same-day). Small balances and faster withdrawals remain the correct posture on any long-tail listing venue.

Who is behind BitMart?

Founded 2017, registered in the Cayman Islands, founded/led by CEO Sheldon Xia. It operates the long-tail listing model — hundreds of tokens including early-stage memecoins — which is worth pricing into the safety question: the venue's custody record is one risk; the risk profile of what's listed on it is another, and this corpus scores them separately.

BitMart vs KuCoin — same incident shape?

Same shape, different execution. Both lost hot-wallet keys to theft (KuCoin ~$281M Sep-2020, BitMart ~$196M Dec-2021), both promised company-funded cover. KuCoin's recovery was engineered — ~84% recovered via freezes and project cooperation, ~16% insurance, users whole on a documented schedule. BitMart's was pledged fast and paid unevenly over weeks. 'Covered' is a spectrum; the timeline is the metric.

NexFlow is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a NexFlow product