News linked to both this project and an event.
Odaily reports: A wallet linked to the $387.5 million Bitget exploit transferred 2,746 ZEC into Zcash's Ironwood privacy pool on Wednesday across three transactions, worth approximately $3.9 million.The funds account for roughly 15% of the ZEC stolen on September 24. The Ironwood privacy pool can conceal the sender, recipient, and transfer amount, but investigators may still be able to trace the path of funds returning to public addresses through transaction timing and amounts. (CoinDesk)
Odaily News: Cosine disclosed the interim investigation reports by SlowMist and Google Cloud's Mandiant on the Bitget hot wallet breach. Both reports indicate that the attackers first compromised systems related to third-party security products, then moved laterally into Bitget's wallet business environment.SlowMist's investigation revealed that one of the third-party security product nodes had a zero-day vulnerability, with related malicious activity traced back to as early as August 31. On September 25, the attackers also used an internal employee identity to access the management platform of another third-party security product and used highly customized withdrawal tools to interact with the wallet system's withdrawal logic. Mandiant stated that after gaining persistent access through third-party security devices, the attackers moved laterally to production wallet task servers and deployed malicious programs.Mandiant also stated that no evidence of Bitget private key leakage has been found so far, and cold wallets were not affected. Both security teams are continuing to investigate the specific intrusion paths the attackers took between the relevant systems.
Odaily reports: Bitget stated on X platform that an investigation by Google Cloud's Mandiant into Bitget's September 24 security incident found that attackers gained unauthorized access to certain third-party security devices, then laterally moved into Bitget's exchange wallet environment and obtained access to both warm and hot wallets. The investigation findings are consistent with the attack path previously disclosed by Bitget.
Odaily News — SlowMist security team has disclosed preliminary investigation findings on the September 25 theft of assets from Bitget's hot wallet. The investigation found that the attack involved certain third-party security products and wallet application hosts, with a zero-day vulnerability present in one of the third-party products. The attacker also gained unauthorized access to a third-party product management platform by impersonating an internal employee.SlowMist stated that the team has obtained the custom withdrawal tool used by the attacker to interact with the wallet system's withdrawal logic. On-chain attack activity began at 2:31 on September 25, lasted approximately 2 hours and 52 minutes, and involved multiple blockchains. The attacker subsequently attempted to tamper with withdrawal records and trigger additional BTC withdrawals. The team is still investigating how the attacker moved laterally between the affected systems.
Odaily News — Gracy Chen, CEO of cryptocurrency exchange Bitget, said the company is not optimistic about recovering the $388 million in crypto assets lost in last week's security incident. Citing the Bybit hack in 2025 as a reference, she noted that approximately one year after that incident, only about 3.5% of the stolen funds had been frozen, and that this does not equate to a completed recovery.Bitget has set up a bounty program offering 5% rewards for frozen funds and recovered funds respectively. The NEAR Intents team said it has intercepted over $50 million in assets related to the attack and frozen approximately $500,000. Tether and Circle have blacklisted the relevant wallets, freezing $318,000 worth of USDT and USDC.Gracy Chen stated that preliminary investigations indicate the attack may match VPN addresses used by North Korea-linked groups, but Bitget has not yet fully ruled out the possibility of an insider job. Bitget has resumed withdrawals in phases, starting with Bitcoin transactions on Monday and continuing with ETH transactions on Tuesday. (Cointelegraph)
Odaily News: According to Bitget monitoring, Mandiant and SlowMist are continuing to support the investigation and on-chain tracing of this incident. Bitget has published the identified attacker addresses and related tracing data to support industry collaboration and asset recovery efforts.Bitget expects to complete its internal security report this week and will release further updates once the investigation findings are verified. Bitget stated that the September 24 incident was the first such security event in its 8 years of exchange operations.
Bitget CEO Gracy Chen thanked Circle and Tether for their swift action. The Bitget Asset Recovery Bounty Program has now been launched, offering a 5% reward respectively to participants who assist in freezing the attacker's funds and recovering the assets, and calls on exchanges, security researchers, and on-chain investigators to participate.
Odaily News: Bitget posted on X platform that the vulnerability involved in the September 24 security incident has been identified and fixed. The team is conducting additional verification and security checks on the withdrawal infrastructure, with Mandiant and SlowMist continuing to assist with the investigation. The temporary suspension of withdrawals is a security measure and is unrelated to the availability of user assets; user account balances have not been affected, and the Bitget Protection Fund will cover the financial impact of this platform-wide incident.Bitget plans to resume withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on the Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on the Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate, and users do not need to take any action in advance.
Xie Jiayin, Head of Greater China at Bitget, announced the latest updates on the security incident, stating that the security team has accurately identified the hackers' attack vectors and methodologies, and obtained details on how the attackers bypassed security protocols. Tracing the attack back to its source is now highly imminent. Third-party security firms Mandiant and SlowMist are continuing their incident investigation and will release a detailed report subsequently. On-chain tracking confirms that approximately $387.5 million in assets were transferred to attacker addresses, an upward revision from the previously estimated $351.6 million. This adjustment simply incorporates ZEC and TRX into the total and does not indicate any new assets were stolen. No other unauthorized transfers have been detected. Bitget stated that all stolen funds at the platform level will be fully covered by the User Protection Fund, ensuring user assets remain unaffected. Bitget has also officially launched its Fund Recovery Bounty Program. Individuals or entities that voluntarily freeze or proactively retrieve attacker funds will be eligible for a 5% bounty, with prior assistance remaining eligible. The platform has published the attacker's addresses, a real-time fund tracking dashboard, and an information submission portal, and pledged to announce withdrawal times by 12:00 PM on September 26.
Bitget CEO Gracy Chen 发布安全事件最新进展称,平台正与独立第三方安全团队 Mandiant 和慢雾合作,对此次事件展开全面调查。 Gracy Chen 表示,目前用户账户余额保持完整,此次平台层面安全事件造成的影响将由 Bitget 用户保护基金覆盖;Bitget Wallet 采用自托管模式,其基础设施与 Bitget Exchange 相互独立,因此未受到此次事件影响。 目前 Bitget Exchange 的充值、交易及奖励等功能继续运行,但提币仍暂时暂停,平台正在进行额外安全核查,确认安全后将恢复。Bitget 官方公告也显示,提币服务目前仍处于暂停状态,充值和交易正常运行。 Bitget 表示,后续调查进展及安全事件相关信息将通过官方渠道持续公布。
Bitget CEO Gracy Chen posted a 12-hour progress report on the security incident on X, including:1. Affected assets include ETH, XRP (largest single-chain loss), BNB, AVAX, USDT, USDC, and other tokens. Affected chains include: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. All on-chain cold wallets have been confirmed secure and unaffected.2. All foundations of the affected chains have been contacted, and some foundations have confirmed the freezing of the hacker's wallet addresses.3. Based on IP behavioral characteristics and on-chain analysis, the attack methodology is highly consistent with known patterns of North Korean hacker groups. Relevant authorities have been notified, and full cooperation is being provided for a global investigation.4. Bitget Wallet (decentralized wallet) operates completely independently from Bitget exchange infrastructure, and this incident has no impact on it. Bitget Wallet assets are completely safe.5. Transparent disclosure regarding the platform's financial status: In addition to over $464 million in protection funds (all held in publicly verifiable wallet addresses), Bitget's own assets exceed $1 billion. User funds are covered at a 1:1 ratio, and all data can be verified on-chain.6. Regarding withdrawal recovery timing: The goal is to achieve full recovery as soon as possible. Once a specific time window is confirmed, an announcement will be made immediately. No commitment will be made to timelines that cannot be fulfilled.
Xie Jiayin stated that Bitget has sufficient user protection funds to cover the related losses, and withdrawals will be resumed immediately once all potential security risks are resolved, with the results to be published upon completion of the investigation.
Gracy Chen 称,目前确认相关损失已经完成,平台不存在进一步资金流失风险,黑客具体入侵手法仍在技术核查中,完整报告将在调查结束后发布。
Odaily news: Bitget spokesperson Xie Jiayin stated on X that the platform's security system detected abnormal transfers from some hot wallets at 2:31 a.m., and immediately activated its emergency response mechanism.According to Bitget's disclosure, the initial assessment indicates that the incident involves approximately $351.6 million. The platform said that cold wallets and the vast majority of assets were unaffected, user funds are safe, and the related losses are fully covered by the Bitget User Protection Fund, which currently exceeds $464 million.Bitget stated that within minutes of the incident, it activated an emergency response team and flagged and reported the addresses involved in the abnormal transfers. At the same time, for the sake of fund security, the platform has temporarily suspended withdrawals, which will be restored in an orderly manner after the security review is completed. Deposits and trading functions are currently still operating normally.The platform also said it has notified law enforcement agencies and on-chain security firms to intervene in the investigation.
Bitget exchange has responded to allegations of a $178 million security breach and withdrawal, stating that these rumors are unsubstantiated. The platform said it is cooperating with law enforcement agencies in the investigation and confirmed that user cold wallet funds remain secure.
According to Odaily, the latest data from Reality shows that trading activity for its Nvidia stock token (rNVDA) has surged, with single-day trading volume reaching $38.86 million, setting a new high since its launch.It is reported that rTokens, identified by the letter "r" plus the stock ticker (e.g., rNVDA for Nvidia), are issued by Bitget's licensed RWA protocol Reality. Through a partnership with compliant brokerage Alpaca, they connect directly to global liquidity pools including Nasdaq and the NYSE. Their features include: 1:1 reserve backing of underlying assets held by licensed custodians, stock dividends distributed 1:1 in token form, support for synchronous mapping of corporate actions (such as stock splits and reverse splits), and positions usable as joint margin for Bitget's Unified Account and USDT-margined futures, allowing users to flexibly manage their funds while holding global stock assets.
Bitget Chief Legal Officer Hon Ng has released an open letter on the occasion of the platform's eighth anniversary. As the platform continues to evolve into a Universal Exchange (UEX), Bitget has further upgraded its Proof of Reserves (PoR) system, expanding the scope of verifiable assets from four original cryptocurrencies to 19 major assets. Data shows that as of September 2026, Bitget has consecutively published 46 PoR reports. In his letter, Hon Ng noted, "Growth and responsibility are never two separate pursuits." As the platform's scale, asset categories, and market boundaries continue to expand, security, transparency, and compliance standards must also be upgraded in tandem. "Making trust visible and verifiable remains a cornerstone of Bitget's commitment to long-termism." On the security front, account-level protections cover 2FA, FIDO2, WebAuthn Passkeys, and anti-phishing codes, while platform security mechanisms integrate withdrawal protection, anomaly detection, and anti-fraud systems, providing backend safeguards for every user interaction. The Market Order & Token Responsibility Framework introduced this year further strengthens continuous monitoring and risk management of listed assets, project teams, and market makers. By continuously optimizing mechanisms and enhancing transparency, it maintains a fair and orderly trading environment. From a compliance perspective, Bitget has secured corresponding registrations, licenses, or regulatory approvals in multiple jurisdictions, including Argentina, Australia, New Zealand, Switzerland, and the United Kingdom, and holds
Bitget Chief Legal Officer Hon Ng has published an open letter on the occasion of the platform's 8th anniversary. As the platform continues to evolve toward a Universal Exchange (UEX), Bitget has further upgraded its Proof of Reserves (PoR) system, expanding the scope of verifiable assets from the original 4 cryptocurrencies to 19 major assets. Data shows that as of September 2026, Bitget has published 46 consecutive PoR reports. In the letter, Hon Ng noted, "Growth and responsibility have never been two separate things." As the platform's scale, asset categories, and market boundaries continue to expand, security, transparency, and compliance standards must also be upgraded in tandem. "Making trust visible and verifiable has always been an important cornerstone of Bitget's commitment to long-termism."On the security front, the account level covers 2FA, FIDO2, WebAuthn Passkeys, and anti-phishing codes, while the platform's security mechanisms integrate withdrawal protection, abnormal behavior detection, and anti-fraud systems, providing back-end safeguards for every user operation. The "Market Order and Token Responsibility Framework" launched this year further strengthened continuous monitoring and risk management of listed assets, project teams, and market makers. Through ongoing mechanism optimization and transparency initiatives, the platform continues to maintain a fair and orderly trading environment.On the compliance front, Bitget has obtained corresponding registrations, licenses, or regulatory approvals in multiple jurisdictions, including Argentina, Australia, New Zealand, Switzerland, and the United Kingdom, and continues to improve its compliance systems, including KYC, KYB, AML, CFT, and sanctions list screening, to adapt to the regulatory requirements of different markets and asset categories.
Odaily News: Bitget has announced an upgrade to its Proof of Reserves (PoR) system, expanding asset coverage from the original 4 cryptocurrencies to 19 major assets, with newly added tokens including XAUT, SOL, BNB, USDGO, and others. This upgrade simultaneously expands the scope of platform-level reserve disclosure and individual asset proof verification. Users can view each asset's reserve ratio, scale, and on-chain distribution through the PoR page, and use Merkle Tree to independently verify whether their personal holdings are included in the reserve snapshot.Bitget has been publishing monthly reserve reports since December 2022, and as of August 2026, has published 45 consecutive issues, with the latest overall reserve ratio at 122%. Bitget CEO Gracy stated that as the variety of assets supported by the platform continues to increase, reserve transparency and verification capabilities also need to expand in tandem, enabling more users to independently verify their assets and further enhancing platform transparency.
Odaily News: Bitget Wallet has announced its integration with RWA protocol Reality, opening trading access to over 1,700 rToken tokenized US stocks. Through this integration, users can trade tokenized US stocks 24/7 on Arbitrum and Morph without needing to open an overseas brokerage account, submit KYC, complete a W-8BEN form, or arrange a wire transfer. Dividends generated by the corresponding underlying assets will be credited to Bitget Wallet in USDT at a 1:1 ratio.Reality is a compliant tokenized asset issuance platform, licensed under El Salvador's digital asset issuance law framework. Its issued rTokens are backed 1:1 by real US stocks, currently supporting over 1,700 tokenized US stocks including rTSM, rNVDA, rAAPL, and rQQQ, covering approximately 95% of US market trading volume. rTokens can connect directly to liquidity across all US markets including Nasdaq and the NYSE, with underlying assets compliantly custodied by FINRA-licensed broker-dealer Alpaca Securities, maintaining a reserve ratio exceeding 100%, with third-party CPA firms issuing daily real-time Proof of Reserve (PoR). This integration will further advance Bitget Wallet's Everyday Finance strategy, aiming to enable users to seamlessly conduct everyday transactions of traditional financial assets through an on-chain wallet.