On September 25, Bitget CEO Gracy Chen stated during a live broadcast regarding the platform's attack incident that the security team is currently focused on identifying the root cause and resolving the issue. Based on the information available at this stage, the incident is somewhat similar to a supply chain attack: the attacker may have compromised a third-party tool frequently used by Bitget, thereby affecting an important backend system of the wallet service. Gracy Chen mentioned that the compromised service forged transfer information and invoked a signing machine to transfer funds. This incident does not involve private key leakage; based on current investigations, the likelihood of internal personnel being involved is also low. However, she noted that the final attack path still needs further confirmation from the security team. She added that hacker attacks are usually not of a single type, and a single attack may simultaneously use a combination of two to three methods from six to seven different types. She cited the previous attack incident on Bybit as an example, which involved both the signing authorization process and a supply chain attack on the Safe multi-signature page it used. Common attack methods against trading platforms also include private key leakage, smart contract vulnerabilities, internal personnel involvement, and social engineering attacks.
All Comments