News linked to this event type.
Bitget CEO Gracy Chen posted a 12-hour progress report on the security incident on X, including:1. Affected assets include ETH, XRP (largest single-chain loss), BNB, AVAX, USDT, USDC, and other tokens. Affected chains include: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. All on-chain cold wallets have been confirmed secure and unaffected.2. All foundations of the affected chains have been contacted, and some foundations have confirmed the freezing of the hacker's wallet addresses.3. Based on IP behavioral characteristics and on-chain analysis, the attack methodology is highly consistent with known patterns of North Korean hacker groups. Relevant authorities have been notified, and full cooperation is being provided for a global investigation.4. Bitget Wallet (decentralized wallet) operates completely independently from Bitget exchange infrastructure, and this incident has no impact on it. Bitget Wallet assets are completely safe.5. Transparent disclosure regarding the platform's financial status: In addition to over $464 million in protection funds (all held in publicly verifiable wallet addresses), Bitget's own assets exceed $1 billion. User funds are covered at a 1:1 ratio, and all data can be verified on-chain.6. Regarding withdrawal recovery timing: The goal is to achieve full recovery as soon as possible. Once a specific time window is confirmed, an announcement will be made immediately. No commitment will be made to timelines that cannot be fulfilled.
Bybit co-founder and CEO Ben Zhou announced in a post that the Bybit team stands ready to assist in any capacity with the recent hacking incident targeting Bitget. Previously, when Bybit was compromised, Bitget provided support. Ben Zhou stated that Bybit is currently updating the LazarusBounty platform to help Bitget track the flow of the associated funds.
Odaily News: Bybit co-founder and CEO Ben Zhou posted that the Bybit team stands ready to assist Bitget in any way possible, noting that Bitget had previously offered assistance when Bybit suffered a hack attack.Ben Zhou stated that Bybit is updating the LazarusBounty platform to help Bitget track the flow of stolen funds and assist in recovering the related assets.
Binance Wallet announced the launch of real-time detection and risk blocking features targeting high-risk signature scenarios to prevent phishing attacks exploiting DeFi project authorization mechanisms. Binance stated that certain attacks only require tricking users into completing gas-free offline signatures, which can directly lead to stolen assets. It will continue to expand its risk identification scenarios and security protection coverage moving forward.
Bitget stated that the losses resulting from this hot wallet security incident will be covered by the protection fund following an assessment, and the fund will be replenished after use. The specific scope of compensation and terms will be announced separately.
Bitget Wallet stated on X that it operates independently from the Bitget exchange and is a self-custodial wallet. User assets always remain on-chain and are controlled by users themselves, isolated from the custodial infrastructure of the Bitget exchange.In response to the recent security incident at Bitget, Bitget Wallet has conducted preventive checks on its internal systems and found no security impact from the incident on Bitget Wallet's systems or users' self-custodied assets. Bitget Wallet is currently operating normally, and users are reminded to be vigilant against phishing and impersonation attempts and to obtain the latest information through official channels.
on-chain analyst Yu Jin has monitored that the $464 million risk protection fund Bitget claims can cover stolen assets is a total of 5,500 BTC, distributed across 3 wallet addresses.
Odaily News: According to LookonChain monitoring, the breakdown of assets stolen from Bitget is as follows:102.93 million XRP (approximately $157.48 million);31,890 ETH (valued at $85.75 million);34.75 million USDT (approximately $34.75 million);21.05 million USDC ($21.05 million);19.67 million USD₮0 ($19.67 million);3,000 XAUt (equivalent to $12.82 million);12,719 BNB (valued at $9.88 million);821,012 AVAX (valued at $8.38 million);20.59 million $TRX (approximately $7.07 million).
Odaily reports: On-chain analyst Specter has stated that they have established an on-chain connection between the Bitget attack and the AFX attack that occurred in July of this year. The latter involved approximately $24 million in stolen funds and was attributed to TraderTraitor.Specter claims that the XRP stolen from Bitget can be directly traced to the stolen funds from the AFX attack after being bridged across chains, leading them to believe that this attack may be related to Lazarus Group. The attribution is still pending further verification.
According to Lookonchain data, the assets stolen in the Bitget incident comprise 9 different token categories, totaling approximately $356.9 million in value. Of these, approximately 102.93 million XRP (worth around $157.48 million) represents the highest-valued category, alongside 31,890 ETH (approximately $85.75 million). The remaining stolen assets include approximately 34.75 million USDT ($34.75 million), 21.06 million USDC ($21.06 million), 19.67 million USD₮0 ($19.67 million), 3,000 XAUt ($12.82 million), 12,719 BNB ($9.88 million), 821,000 AVAX ($8.38 million), and 20.59 million TRX ($7.07 million).
According to the updated tracking data from SlowMist's MistTrack, the currently flagged Bitget hacker-associated addresses include 11 EVM addresses, 7 Ripple network addresses, and 1 TRON address.
Gracy Chen 称,目前确认相关损失已经完成,平台不存在进一步资金流失风险,黑客具体入侵手法仍在技术核查中,完整报告将在调查结束后发布。
Odaily reports: LayerZero Labs co-founder and CEO Bryan Pellegrino posted on X platform that KelpDAO has filed a civil claim lawsuit against him and LayerZero. Bryan Pellegrino stated that the claim is baseless and that he will face them in court in Vancouver to defend himself.It is reported that in April of this year, KelpDAO suffered a hack resulting in losses exceeding $292 million. The attacker used social engineering tactics to compromise a LayerZero developer account. Because KelpDAO employed a "single-verifier" configuration, the target contract executed asset release upon receiving only a single valid signature, leading to the theft of rsETH.
Odaily News: According to monitoring by Yu Chen, the assets stolen from Bitget this time amounted to about $351.6 million, of which about $192.6 million were stolen on EVM chains, mainly including stablecoins and ETH.Over the past few hours, the hacker has successively converted the stablecoins and other assets stolen on EVM chains into ETH. Currently, the relevant hacker EVM address holds a total of about 68,500 ETH, worth about $184 million.
Chainalysis data shows 9 Asian countries rank in the top 20 globally for crypto adoption; Bitget confirms $350 million was stolen, with the user protection fund covering the losses.
according to Bitcoin News monitoring, this batch of Bitcoin is worth over $4 million, accounting for approximately 2.8% of the total Bitcoin related to the Coldcard vulnerability. Crypto Recovery Trust will verify the ownership of the funds and attempt to return them; Galaxy Digital research director Alex Thorn stated that another 3.0134 BTC was transferred to this address in the same transaction, but its source has not yet been confirmed.
Bitget was hacked, losing approximately $352 million; the platform emphasized that the stolen assets came from its own capital, and user funds were unaffected.
Bitget exchange has responded to allegations of a $178 million security breach and withdrawal, stating that these rumors are unsubstantiated. The platform said it is cooperating with law enforcement agencies in the investigation and confirmed that user cold wallet funds remain secure.
According to Bitcoin News monitoring, $176 million worth of ETH and USDT0 was transferred from multiple Bitget wallets to a single address, in what appears to be unauthorized activity. This suspected hack did not involve Bitcoin. Bitget has not yet commented.
Bitcoin News posted on X platform stating that Blink said all account balances that suffered financial losses in the September 19 security incident have been restored to pre-incident levels.The software vulnerability had allowed attackers to transfer funds from dozens of accounts and obtain account information of approximately 3,400 other users. Blink stated that no funds were stolen from these 3,400 accounts, and the attackers did not obtain users' names, identification documents, or addresses; the company has contacted affected users and will publish a full incident review.