GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Bitget Announces Resumption of Normal Operations After $388 Million Hacker Attack

Bitget announced it will gradually resume normal operations following a fund loss incident of approximately $388 million. Its protected Operations Protection Fund absorbed the financial impact of the loss, though the cause of the attack has not yet been fully determined.

Bitget hacker transfers $3.9 million in ZEC into Zcash privacy pool

Odaily reports: A wallet linked to the $387.5 million Bitget exploit transferred 2,746 ZEC into Zcash's Ironwood privacy pool on Wednesday across three transactions, worth approximately $3.9 million.The funds account for roughly 15% of the ZEC stolen on September 24. The Ironwood privacy pool can conceal the sender, recipient, and transfer amount, but investigators may still be able to trace the path of funds returning to public addresses through transaction timing and amounts. (CoinDesk)

ZachXBT: Bitget attacker begins transferring approximately 2,700 ZEC to the Ironwood mixer.

链上侦探 ZachXBT 发文表示,Bitget 被盗事件中疑似朝鲜关联的攻击者已开始将约 2700 枚 ZEC(约 380 万美元)转入 Zcash 的 Ironwood 屏蔽池。Bitget 热钱包此前共被盗约 1.89 万枚 ZEC,价值约 2830 万美元。

Cosine: Bitget attacker breached third-party security products before moving laterally into wallet systems, no private key leakage found

Odaily News: Cosine disclosed the interim investigation reports by SlowMist and Google Cloud's Mandiant on the Bitget hot wallet breach. Both reports indicate that the attackers first compromised systems related to third-party security products, then moved laterally into Bitget's wallet business environment.SlowMist's investigation revealed that one of the third-party security product nodes had a zero-day vulnerability, with related malicious activity traced back to as early as August 31. On September 25, the attackers also used an internal employee identity to access the management platform of another third-party security product and used highly customized withdrawal tools to interact with the wallet system's withdrawal logic. Mandiant stated that after gaining persistent access through third-party security devices, the attackers moved laterally to production wallet task servers and deployed malicious programs.Mandiant also stated that no evidence of Bitget private key leakage has been found so far, and cold wallets were not affected. Both security teams are continuing to investigate the specific intrusion paths the attackers took between the relevant systems.

Mandiant Investigation: Attackers Gained Access to Bitget Wallet Environment Through Third-Party Security Devices

Odaily reports: Bitget stated on X platform that an investigation by Google Cloud's Mandiant into Bitget's September 24 security incident found that attackers gained unauthorized access to certain third-party security devices, then laterally moved into Bitget's exchange wallet environment and obtained access to both warm and hot wallets. The investigation findings are consistent with the attack path previously disclosed by Bitget.

SlowMist: Bitget hack involved a zero-day vulnerability in a third-party security product, attacker used custom withdrawal tool

Odaily News — SlowMist security team has disclosed preliminary investigation findings on the September 25 theft of assets from Bitget's hot wallet. The investigation found that the attack involved certain third-party security products and wallet application hosts, with a zero-day vulnerability present in one of the third-party products. The attacker also gained unauthorized access to a third-party product management platform by impersonating an internal employee.SlowMist stated that the team has obtained the custom withdrawal tool used by the attacker to interact with the wallet system's withdrawal logic. On-chain attack activity began at 2:31 on September 25, lasted approximately 2 hours and 52 minutes, and involved multiple blockchains. The attacker subsequently attempted to tamper with withdrawal records and trigger additional BTC withdrawals. The team is still investigating how the attacker moved laterally between the affected systems.

North Korean hackers swap stolen Bitget funds cross-chain into BTC, involving CoW Protocol and Chainflip

Odaily News — According to monitoring by SlowMist's Yu Xian, MistTrack_io's TrackAgent discovered that North Korean hackers used automated scripts to create orders on CoW Protocol and set the receiving address to pre-prepared Chainflip Deposit-related contract addresses. After the orders were filled, the relevant assets could complete cross-chain operations on Chainflip and be swapped into BTC. The operation involves stolen Bitget funds.

$388 Million in Crypto Assets Stolen, Bitget CEO Says Full Recovery Unlikely

Odaily News — Gracy Chen, CEO of cryptocurrency exchange Bitget, said the company is not optimistic about recovering the $388 million in crypto assets lost in last week's security incident. Citing the Bybit hack in 2025 as a reference, she noted that approximately one year after that incident, only about 3.5% of the stolen funds had been frozen, and that this does not equate to a completed recovery.Bitget has set up a bounty program offering 5% rewards for frozen funds and recovered funds respectively. The NEAR Intents team said it has intercepted over $50 million in assets related to the attack and frozen approximately $500,000. Tether and Circle have blacklisted the relevant wallets, freezing $318,000 worth of USDT and USDC.Gracy Chen stated that preliminary investigations indicate the attack may match VPN addresses used by North Korea-linked groups, but Bitget has not yet fully ruled out the possibility of an insider job. Bitget has resumed withdrawals in phases, starting with Bitcoin transactions on Monday and continuing with ETH transactions on Tuesday. (Cointelegraph)

Bitget Suffers $350 Million Security Breach, CEO: Funds Fully Secured

Bitget confirmed a hack of approximately $351.6 million, with CEO Gracy Chen stating that attackers stole funds by forging transfer requests, and that user assets are fully covered by a protective fund of over $464 million.

SlowMist's Cos: Chainflip bridge blocks North Korean hacker money laundering, but AML/KYT speed lags behind

Odaily report: According to monitoring by SlowMist's Cos, the Chainflip bridge is attempting to block North Korean hacker money laundering, but the response speed of AML/KYT lags behind the speed of money laundering. Money laundering groups use automation to split funds into large numbers of small amounts, transferring them across chains through various bridges; if funds are intercepted or returned by risk controls, they immediately try the next money laundering path, ultimately converting to BTC and continuing to obfuscate the source of funds through CoinJoin. This money laundering operation is still continuously evolving.

Bitget Attackers Attempted to Transfer Stolen Funds via Cross-Chain Protocol Chainflip But Were Rejected

MistTrack monitoring indicates that a Bitget attacker recently attempted to transfer stolen funds through the cross-chain liquidity network Chainflip, but the deposit was rejected by the relevant broker (Broker). The platform did not freeze the funds, but instead executed a return to the originating address. MistTrack stated it will continue to track the subsequent flow of the stolen funds.

Bitget Suffers $387.5 Million Exploit, NEAR Intents Freezes $503,000 in Stolen Funds

Odaily News: According to monitoring by Bitget CEO, Bitget was hacked on September 24, with approximately $387.5 million in funds stolen, a large portion of which was transferred across chains and primarily consolidated on Ethereum. A report released by NEAR Intents shows that its risk intelligence layer SHIELD detected over $50 million in suspected money laundering transfer attempts; of this, $166,000 in funds went through, while $503,000 was frozen during execution. The frozen funds remain restricted pending subsequent legal and recovery proceedings.

Bitget Launches the "Companion Plan": V1 to V7 Users Can Receive a 30-Day Tier Protection Trial Pass

According to the official announcement, Bitget has launched the "Companion Program," offering trading rewards, asset rewards, and exclusive benefits across different user segments, designed to reward those who have consistently provided trust and support throughout the recent security incident.

ZachXBT: Gang Suspected of Assisting North Korean Hackers with Money Laundering is Transferring Stolen Bitget Funds and Publicly Seeking Technical Support

On-chain investigator ZachXBT disclosed that illicit actors assisting a suspected North Korean hacker group with money laundering are currently publicly seeking order processing support on the Discord public servers and Telegram channels of relevant service platforms. The laundered funds originate from the $387 million security breach previously suffered by Bitget.

First such security incident in 8 years of operations, Bitget publishes attacker addresses and tracing data

Odaily News: According to Bitget monitoring, Mandiant and SlowMist are continuing to support the investigation and on-chain tracing of this incident. Bitget has published the identified attacker addresses and related tracing data to support industry collaboration and asset recovery efforts.Bitget expects to complete its internal security report this week and will release further updates once the investigation findings are verified. Bitget stated that the September 24 incident was the first such security event in its 8 years of exchange operations.

Stealing $351.6 Million: Bitget Hacker Swaps ETH for BTC via THORChain

Odaily reports, according to Lookonchain monitoring, the Bitget hacker (0xf7bC...96C3) swapped ETH for BTC via THORChain, having stolen $351.6 million.

Bitget Hacked, THORchain Refuses to Cooperate

Bitget announces that approximately $387.5 million has been stolen; the CEO's request for THORchain to compromise addresses was denied; Vitalik Buterin states that Ethereum is evolving into a "cryptographic world computer".

Bitget Hacked, Loses $351 Million and Suspends Withdrawals

Cryptocurrency exchange Bitget has been hacked, losing approximately $351 million. Bitget CEO Gracy Chen stated that the platform's protection fund will cover the losses, and the exchange has temporarily suspended withdrawals. (Bitcoin.com News)

THORChain Earns Nearly $10 Million in Fees in 10 Days, Accused of Funneling Most of Bybit's Stolen Funds

Odaily News: According to on-chain analyst Yu Jin, over 90% of the funds swapped cross-chain through THORChain are illicit or grey-market funds. Yu Jin stated that most of the funds stolen from Bybit last year were transferred through THORChain, which collected nearly $10 million in fees within 10 days. Recently, some of the funds stolen from Bitget have also been transferred through THORChain, generating $1 million in fee revenue.

Slow Mist's Cosine Talks About THORChain: Decentralization Is Not Just a Slogan, and "Decentralized, No Right to Interfere" Should Not Be Used to Respond to Industry Security Incidents

Slow Mist's Cosine posted on X platform, stating that the Bitget hack incident has spread widely, involves a huge amount of funds, and the related funds were quickly linked to North Korean hackers. Institutions such as Circle and Tether promptly assisted in freezing the related funds, with Circle freezing the USDC held by the hackers.Regarding THORChain, Cosine pointed out that when THORChain itself previously suffered a hack, it also quickly intervened in its so-called "decentralized" platform; but this time, when facing a major industry security incident, it responded on the grounds of being "decentralized and having no right to interfere," likened itself to Bitcoin and Ethereum, and continued to earn fees from the hackers' large cross-chain transactions.He stated that decentralization should not just be a slogan. After major security incidents occur, the key is to distinguish which issues need to be solved jointly by the industry. He also believes that platforms such as THORChain should not be easily mentioned in the same breath as Bitcoin and Ethereum, as there are clear differences in the degree of decentralization and mechanisms among different systems.