Exchange e custodia
BitMart: the history behind the wind-down
A review of BitMart’s earlier disputes, security incidents and withdrawal concerns alongside its 2026 closure announcement.
Original publication · 26 Jul 2026. Figures, claims and opinions reflect the original publication date.
Le pubblicazioni originali sono in inglese. La navigazione è disponibile in sette lingue.

Originally published as “BitMart’s Shutdown Was Years in the Making”
BitMart’s shutdown did not come out of nowhere.
On July 26, 2026, the exchange announced an “orderly wind-down,” immediately began suspending registrations and deposits, stopped accepting new spot orders and restricted futures accounts to reduce-only mode.
All trading is scheduled to end on August 26, 2026, while the platform plans to cease operations on January 31, 2027. BitMart blamed its “operating conditions, market environment, and future strategic direction,” but published no detailed financial explanation, no balance sheet and no public asset-to-liability reconciliation alongside the announcement. Users were told to withdraw, while also being warned that withdrawals could face extended KYC, device, IP, source-of-funds, transaction-history, Travel Rule and sanctions reviews.
What the documented record does show is an exchange repeatedly appearing at the centre of security failures, frozen accounts, disputed balances, regulatory warnings, dubious token listings and markets later identified by U.S. prosecutors as venues for alleged wash trading.
BitMart survived each episode behind the usual CEX wall: customers surrendered custody, the exchange controlled the database, the exchange decided which balances were real, and the exchange decided when users were allowed to leave.
The 2020 case involving frozen profits and exposed customer data
One of the earliest documented warnings appeared in the 2020 case Jia Li and David Hsiao v. GBM Foundation Company d/b/a BitMart, filed in the U.S. District Court for New Jersey. Li had deposited 157,862.57 USDT and Hsiao approximately 200,000 USDT before buying TWEE. After selling on September 4, 2020, Li’s position was valued at $642,676.48 and Hsiao’s at $1,011,000.47.
BitMart then froze withdrawals associated with TWEE, citing extreme volatility. Hsiao managed to withdraw approximately 1,000,000 USDT, but a subsequent withdrawal failed. Li recovered her original 157,862.27 USDT while, according to the complaint, another 484,814.21 USDT remained withheld.
The plaintiffs said BitMart instructed them to negotiate directly with associates of the TWEE project. They further alleged that their identification details, contact information and transaction records had been exposed, and that TWEE associates threatened legal action and public disclosure of their personal information unless funds were sent to them. The judge denied the plaintiffs’ request for emergency relief because they had not met the legal requirements for a temporary restraining order. That decision did not establish that BitMart had acted properly, nor did it decide the underlying allegations on their merits. It only rejected the requested emergency injunction.
This case is particularly relevant to claims that BitMart froze customers after they made unusually large profits. It provides documented evidence that profitable balances were frozen and disputed.
BitMart was fooled by a 51% attack in July 2021
In July 2021, 92 respondents allegedly opened BitMart accounts and exploited a 51% attack against the Bitcoin SV network. The attackers created transactions that made it appear as though they controlled approximately 91,000 BSV. BitMart credited the accounts, after which the BSV was exchanged for other assets worth more than $6 million. BitMart managed to freeze some accounts and later obtained an arbitration award calculated at $5,231,549.42.
BitMart was the victim in this incident, not the alleged perpetrator. It still exposed a serious operational weakness. A centralised exchange whose internal systems credited millions of dollars based on transactions generated during a blockchain attack had failed at one of its core responsibilities: determining whether deposited assets were final and legitimate before allowing them to be traded and withdrawn.
The December 2021 hot wallet catastrophe
On December 4, 2021, an attacker obtained a private key controlling 2 BitMart hot wallets on Ethereum and Binance Smart Chain. BitMart initially described the loss as approximately $150 million. Independent estimates were substantially higher. Merkle Science calculated $90,487,593.65 stolen on Ethereum and $120,601,070.74 on BSC, placing the total above $211 million. Elliptic estimated more than $225 million. The widely repeated $196 million figure originated from PeckShield’s analysis. The disagreement itself matters because even the basic size of the loss was never presented through a complete, independently audited public accounting.
The onchain trail was public. The compromised Ethereum hot wallet was:
0x68b22215ff74e3606bd5e6c1de8c2d68180c85f7
Funds moved to:
0x39fb0dcd13945b835d47410ae0de7181d3edf270
and subsequently:
0x4bb7d80282f5e0616705d7f832acfc59f89f7091
The compromised BSC wallet was:
0x8c128dba2cb66399341aa877315be1054be75da8
with funds sent to:
0x25fb126b6c6b5c8ef732b86822fa0f0024e16c61
The attacker swapped stolen tokens through 1inch and PancakeSwap before routing almost all of the resulting ETH and BNB through Tornado Cash. Merkle Science identified approximately $51.82 million in SafeMoon, $49.19 million in X2P, $33.07 million in SHIB and $28.66 million in SAITAMA among the stolen assets.
Founder and CEO Sheldon Xia promised that BitMart would use its own money to compensate affected users and publicly stated that no user assets would be harmed. More than 1 month later, users were still reporting that they had not been made whole. One Iranian refugee told CNBC that $53,000 in SafeMoon was trapped, including $40,000 financed through a loan. Another investor said $35,000 remained unresolved and claimed to be coordinating with approximately 6,800 other investors considering legal action. Users described vague support responses and no transparent reimbursement mechanism.
Some users were eventually compensated, but I found no independently audited final report identifying every affected account, the exact amount owed, the form of compensation and whether every victim received the full economic value lost. BitMart made an absolute public promise. What followed was a fragmented and opaque process in which customers had to campaign publicly for answers.
The FTC investigation BitMart tried to restrict
On May 11, 2022, the U.S. Federal Trade Commission issued civil investigative demands to BitMart operators Bachi.Tech Corporation and Spread Technologies. Bachi.Tech was identified as a New Jersey corporation operating BitMart, while Spread Technologies also operated the exchange. The FTC was examining possible deceptive, unfair or otherwise unlawful conduct under Section 5 of the FTC Act and the Gramm-Leach-Bliley Act.
The investigation went far beyond the hack. It covered allegations that consumers had been denied access to their accounts, BitMart’s handling and prevention of security breaches, reported fraud, customer-service practices, third parties promoting the exchange and the truthfulness of marketing claims. The FTC specifically demanded support for BitMart’s claims concerning 24/7 support, “100%” trading security, protection of digital assets, reimbursement promises and its Money Services Business registration. It also sought information about how BitMart evaluated tokens considered for listing and whether they could constitute securities.
Bachi Tech and Spread Technologies attempted to quash or limit the demands. The FTC rejected their arguments and ordered compliance. An investigation is not a conviction, and I found no public FTC enforcement order imposing a fine or establishing liability. However, claims that the investigation was simply “dismissed in 2023” should not be repeated without a proper primary source. The public FTC record confirms the investigation and BitMart’s unsuccessful attempt to restrict it.
The listing machine and markets filled with manufactured volume
BitMart built its business by listing an enormous number of speculative tokens, including projects that more cautious venues would not touch. Its historical Mission X programme directly connected exchange access to fundraising in BitMart’s own BMX token. A project reaching 1 million BMX in the Investment Lab would receive a BMX trading pair, while the cap could rise to 5 million BMX after listing. Sheldon Xia marketed this as a “self-regulated market” that allowed projects fresh from their ICO stage to reach a major exchange early.
BitMart did not maintain a transparent public schedule showing what every project paid for a conventional listing. Claims about agents demanding 5- or 6-figure packages therefore remain difficult to verify systematically. One public statement from the Robo Inu project said it supplied liquidity and paid a BitMart listing fee costing “about 6 figures,” but this was the project’s own statement rather than an audited invoice. It nevertheless provides a concrete example consistent with what many builders reported privately: access to the exchange was expensive, opaque and surrounded by brokers, agents and negotiators whose authority was often difficult to establish.
Robo Inu later appeared in a far more serious federal case. On October 9, 2024, the U.S. Department of Justice announced charges against 18 people and entities in an operation targeting crypto wash trading, market manipulation and pump-and-dump schemes. Prosecutors alleged that Robo Inu creator Vy Pham paid Gotbit to manufacture trading volume through wash trades on exchanges including BitMart. Pham agreed to plead guilty to conspiracy involving market manipulation, wire fraud and operating an unlicensed money-transmitting business.
The same DOJ operation alleged that Saitama leadership paid ZM Quant and Gotbit to wash trade SAITAMA on BitMart, LBank and XT.com. Named participants included Saitama CEO Manpreet Kohli, Haroon Mohsini, Nam Tran, Max Hernandez, Russell Armand and Vy Pham. Gotbit founder Aleksei Andriunin, directors Fedor Kedrov and Qawi Jalili, and ZM Quant employees Riqui Liu and Baijun Ou were also among those charged. Several defendants pleaded guilty or agreed to plead guilty, while other allegations still required proof in court.
BitMart itself was not charged in that DOJ announcement, and the case does not establish that BitMart knowingly participated in the manipulation. The documented conclusion is narrower but still brutal: at least 2 tokens were allegedly wash traded on BitMart by professional market manipulators while retail users saw the resulting volume and price activity presented as a real market. An exchange collecting listing fees and trading fees has a financial interest in volume, yet its customers must trust that the exchange is capable and willing to distinguish organic activity from paid market fabrication. In these cases, that protection clearly failed.
Regulators increasingly pushed BitMart out
On September 6, 2024, the UK Financial Conduct Authority warned that BitMart might be promoting financial services without permission. The FCA stated that BitMart was not authorised, might be targeting people in the UK and should be avoided. UK customers dealing with it would not have access to the Financial Ombudsman Service or protection from the Financial Services Compensation Scheme.
The Netherlands had already become inaccessible. BitMart stopped accepting new Dutch registrations on March 28, 2024, explicitly citing regulatory concerns. Trading and deposits were later disabled, and all services for existing Dutch users ended on August 23, 2024. Users who failed to withdraw in time faced liquidation of their remaining assets into potential contractual claims. BitMart estimated a 15 USDC processing cost, meaning balances worth 15 USDC or less would produce no claim at all.
France added BitMart to the Autorité des Marchés Financiers blacklist for offering crypto-asset derivatives without authorisation. Again, a warning or blacklist entry is not proof that the exchange stole funds, but it directly contradicts the image of a globally compliant platform operating comfortably within the rules of major financial jurisdictions.
Withdrawal restrictions continued shortly before the shutdown
On May 23, 2026, BitMart publicly responded to claims that users could not withdraw and that accounts were being restricted. The exchange said a malicious volume-farming operation had used 239 linked accounts to exploit platform subsidies. BitMart admitted applying restrictions and “intercepting” related funds, while promising to review edge cases and appeals.
BitMart may have had legitimate grounds to block abusive accounts. Exchanges must investigate fraud, sanctions violations and stolen funds. The problem is structural: BitMart was simultaneously the custodian, investigator, judge and gatekeeper. Users could not independently verify the exchange’s evidence or move disputed balances while appealing. The statement confirms that account restrictions and intercepted funds were real. It does not independently prove that every one of the 239 accounts was malicious or that no innocent users were caught by the controls.
BitMart also imposed a particularly hostile policy on holders of delisted assets. From March 2023, users requesting the reopening of withdrawals for a delisted token had to pay 50 USDT per token. Support would first decide whether withdrawal was technically possible, and fulfilment remained at BitMart’s discretion. A customer could therefore buy an asset on BitMart, lose normal withdrawal access after delisting and then be charged 50 USDT merely to request access to the remaining tokens.
The alleged 2025 customer database leak
Cybersecurity monitoring firms reported another unresolved incident in 2025. SOCRadar observed dark-web posts claiming that more than 1.2 million BitMart user records had been leaked, including email addresses, telephone numbers, IP addresses, locations, registration timestamps and referral information. HEROIC separately reported a dataset containing 762,293 records. The conflicting totals could represent different versions or subsets of the same database, but they could also indicate inaccurate or fraudulent dark-web claims.
I found no public BitMart confirmation, forensic report or regulatory finding authenticating the dataset. It must therefore remain labelled as an alleged breach, not an established fact. Its significance lies partly in the absence of a clear public resolution. For exchange customers, leaked emails and telephone numbers are not harmless marketing data. They are raw material for fake-support attacks, SIM swaps, targeted phishing and account-takeover attempts.
The record BitMart leaves behind
The evidence shows something familiar in crypto: a centralised platform collecting listing fees and custodying user assets while operating through several corporate entities, listing deeply speculative tokens, suffering a catastrophic private-key compromise, providing opaque compensation, restricting profitable or suspicious accounts, appearing in an FTC investigation, receiving regulatory warnings and hosting markets later identified by prosecutors as targets of professional wash trading.
Then, on July 26, 2026, users were suddenly told to close positions and withdraw before the machinery stopped.
BitMart controlled the wallets, the order books, the listing decisions, the internal account balances, the withdrawal approvals and the evidence used to freeze customers. Users controlled a login and a number on a screen. That arrangement works only for as long as the exchange remains solvent, competent, reachable and willing to honour the number.
BitMart’s final announcement is another reminder that trading on a CEX may sometimes be convenient, but leaving assets there means accepting unsecured trust in an opaque company whose rules can change overnight.
Not your keys, not your crypto.



