HostDeFi › Is HTX safe
Is HTX safe? The exchange that got hit four times — and covered every time
HTX, the exchange formerly known as Huobi, holds the strangest safety record in this corpus: in roughly two months of late 2023, the Justin Sun orbit of platforms was hit at least four times — HTX twice, Poloniex, and the HECO bridge — for a combined ~$208 million. And every incident ends the same documented way: Sun announces the loss, calls it small against the book, and covers it completely. That is simultaneously the richest loss record and the strongest cover record in the second tier — a page about whether an exchange that keeps getting robbed but keeps paying is "safe."
What HTX is
HTX is the renamed Huobi — founded 2013 in China, once a top-three global exchange, pushed offshore by China's 2021 crackdown and acquired by entities linked to Justin Sun in October 2022; rebranded Huobi→HTX in September 2023. Custody is standard CEX, but the relevant context for this page is ownership: HTX sits in the Sun constellation alongside Poloniex and the HECO chain, and late 2023 demonstrated what that adjacency means — the platforms got attacked as a group. Sun's role is officially "advisor," which the record treats as owner-adjacent in every practical sense.
September 24, 2023: the rebrand month hack
Eleven days after the rebrand, an attacker pulled ~5,000 ETH (~$7.9M) from an HTX hot wallet. Sun disclosed it on X within a day, framed it as "two weeks' revenue" against $3B in user assets, and did something few venues do: offered the hacker a 5% white-hat bounty (~$400K) plus a security-advisor job if the funds came back. Per Blockscope's tracing, the attacker took the deal — ~250 ETH bounty claimed, the rest returned. HTX separately stated it had fully covered the loss regardless. First incident: loss ~$8M, resolution complete.
The pattern that makes this page unusual starts here: the venue's response to being robbed was to negotiate, in public, on-chain — and it worked. Whether you read "hacker kept 5% and gave back 95%" as clever incident response or as paying a ransom with extra steps is a fair question this page leaves open; the user-facing outcome is unambiguous.
November 2023: the constellation gets hit
The next two months turned one incident into a cluster. November 10: Poloniex — Sun-acquired 2019 — lost ~$114M from its hot wallets; CertiK assessed "likely a private key compromise"; withdrawals froze while Sun committed to full coverage. November 22: the HECO bridge — HTX's ecosystem chain — lost ~$86M+ moving assets to suspicious addresses (combined HTX+HECO exposure ~$97M). A second HTX incident (~$13.6M) via another hot-wallet breach landed in the same window. The running total across the Sun platforms: at least four hits, ~$208M, in roughly two months.
And the other half of the record, stated with equal weight: Sun's December 2023 accounting — HTX ~95% of assets resumed, Poloniex ~85%, and "we have already covered all of the loss… 100% of assets are 100% safe" — checked out as advertised. Users did not eat any of the ~$208M. The venue absorbed it and kept operating. The honest framing this page owes you: a platform that can cover $208M in a quarter is genuinely solvent; a platform that needs to cover $208M in a quarter is also telling you something about its security posture. Both sentences are load-bearing.
The Sun factor, priced in
HTX's risk profile is inseparable from the name on its cap table. The case for: the largest documented cover-everything reflex in the corpus — four incidents, zero user losses, no bankruptcy, no withdrawal freeze that outlasted the response; plus monthly proof-of-reserves publications that let users verify holdings. The case against: the orbit attracts attack (four hits in two months is not bad luck, it is a threat-model signal); key compromises recurring across related platforms suggests shared operational DNA; and the same constellation's history includes the market-structure controversies attached to Sun's other properties, which a thorough safety page can't un-know even though they're not custody events.
The cleanest summary the record supports: on every occasion users needed the backstop, the backstop paid — which is either the best evidence HTX is safe or the clearest evidence it gets attacked often enough to need the backstop quarterly. This page prices it as both, in that order.
Where HTX stands
The dated read: the highest-attack-frequency / highest-cover-reliability combination in the corpus — ~$208M in documented late-2023 losses across the Sun platforms, $0 in documented user losses. The residual risk math differs from every other venue in this batch: here the question is not "what happens if they get hit" (answered, four times) but "how often do they get hit, and does the cover hold at scale." For a trading surface the answer so far is yes, demonstrated; for a vault, the whole family's rule applies with extra emphasis — a venue this tested belongs in the hot-money column of your allocation, not the cold one.
Frequently asked questions
Has HTX been hacked?
Four documented hits in ~2 months of late 2023, all in the Justin Sun orbit: Sep-24 HTX ~5,000 ETH (~$8M — attacker returned most for a 5% bounty + advisor offer); Nov-10 Poloniex ~$114M (CertiK: likely private-key compromise); Nov-22 HECO bridge ~$86M; a second ~$13.6M HTX hot-wallet breach in the same window. ~$208M combined. User-facing outcome per Sun and the record: every loss covered — zero documented user losses across all four.
Is HTX the same as Huobi?
Same exchange — Huobi (founded 2013, once a top-three global venue) rebranded to HTX in September 2023 after the 2022 acquisition by Sun-linked entities and China's push of exchanges offshore. The brand change matters to safety pages for one reason: the late-2023 incident cluster started eleven days after the rebrand — the attacks targeted the Sun platform constellation (HTX, Poloniex, HECO) as a group.
Did HTX users lose money in the hacks?
No documented user losses — the defining feature of this record. Sep-2023: most funds returned via white-hat bounty, remainder covered. Nov-2023 Poloniex/HECO/HTX #2: Sun stated all losses covered at platform level, assets "100% safe," withdrawals resumed progressively (~95% HTX / ~85% Poloniex by Dec-2023). The honest caveat: covered by the platform's own balance sheet, not an insurance fund or third party — which makes the cover exactly as strong as the operator's ongoing solvency.
What are the risks of using HTX?
The documented set: (1) attack frequency — four incidents in ~2 months in 2023 is a threat-model signal, not coincidence — the Sun orbit is a target; (2) private-key compromise recurring across related platforms (Poloniex, HECO, HTX) — suggests shared operational DNA in key management; (3) owner-adjacent governance — "advisor" Sun is functionally the owner, and his properties carry their own controversy record; (4) the standard custodial set. Mitigating all of it: the cover reflex has now paid four times running.
Is HTX regulated?
HTX operates from Seychelles and carries the typical offshore-registration profile of its tier — thinner formal licensing than Coinbase/Kraken/Bitstamp, roughly comparable to MEXC/Gate. It publishes monthly proof-of-reserves — verifiable, with the standard snapshot caveat. Honest read: on regulation it sits in the second tier's unregulated end; on demonstrated make-whole behavior it sits at the top of the corpus. Whether the second outweighs the first is position-size math, not marketing.
Is HTX safer than KuCoin or MEXC?
Different risk shapes. KuCoin: one giant breach, one giant recovery, then costly regulatory reckoning. MEXC: audited books, funded backstop, zero incidents tested. HTX: four incidents absorbed with zero user loss — the most-proven cover in the group attached to the most-attacked platform in the group. For frequent trading HTX's record is arguably the most honest evidence available — it has been tested and paid every time; for custody-length decisions, "tested quarterly" is itself the datum.