On September 26, Unchained reported that Bitget stated attackers transferred approximately $387.5 million from its exchange on Thursday, revising the initially estimated loss of $351.6 million after accounting for transfers on the Zcash and TRON chains. The attackers did not require private keys: CEO Gracy Chen mentioned that the attackers compromised key backend systems of its wallet infrastructure, forged transaction data, and triggered the authorization process, which was signed by Bitget's own system. The related vulnerability has been identified and fixed, and the withdrawal status, which has been suspended since Thursday, will be announced before midnight Eastern Time. Mandiant and SlowMist are assisting with the investigation. Chen noted that based on IP behavior patterns and on-chain signatures, this attack is consistent with methods used by North Korean-linked hacker organizations and resembles the previous $1.5 billion theft case from Bybit. Nansen tracking shows that 40,000 ETH were evenly distributed to four new addresses; as of Friday, 6:34 PM Eastern Time, eight attacker addresses held a total of approximately 68,300 ETH (about $18.4 million), with no further transactions initiated. Bitget stated that some of the funds have been frozen and is offering a 5% bounty on the recovered amounts to those who facilitate the freezing; the $464 million protection fund fully covers the losses.
All Comments