News linked to both this project and an event.
MistTrack (@MistTrack_io) disclosed that, following the transfer of nearly $1.2 billion in stolen funds from last year's $1.46 billion Bybit hack via THORChain, Bitget has recently suffered another major security breach, with stolen funds suspected of again flowing through THORChain. In response, the official THORChain team stated that its protocol is a decentralized, permissionless network, just like Bitcoin, Ethereum, and BNB Chain.
Odaily News: Today, THORChain officially posted on X platform stating, "We have noticed the recent Bitget hack and are deeply saddened by it. We can imagine this is a difficult time for everyone in the industry. (However,) THORChain is as decentralized and permissionless as Bitcoin, Ethereum, and BNB Chain. When dealing with known stolen funds, what responsibility should Bitcoin, Ethereum, and BNB Chain bear?" Subsequently, it called out OKX CEO Star and Bitget CEO Gracy.However, crypto community members in the comments pointed out that when THORChain previously suffered an attack, it once suspended services for 39 days, and they are deeply ashamed of the differentiated treatment between the two situations.
Odaily News: OKX Star posted on X in response to THORChain, stating that he does not believe THORChain's TSS + validator model represents true decentralization. THORChain's validators collectively control the underlying assets in the TSS vault, and funds can be moved once the signature threshold is reached. Therefore, from a custody perspective, it cannot be compared to the underlying consensus mechanisms of Bitcoin and Ethereum, but instead acts as an intermediary between users and native chains. "TSS distributes control among multiple participants, but decentralizing an intermediary does not eliminate the intermediary itself."Previously, discussions arose after some stolen Bitget funds were transferred through THORChain. THORChain responded that it is decentralized and permissionless, just like Bitcoin, Ethereum, and BNB Chain, and stated that if stolen funds were known to flow through Bitcoin, Ethereum, or BNB Chain, what responsibility should those networks bear?
According to AMLBot monitoring, some of the stolen funds from the Bitget hack have reportedly begun being mixed through Wasabi CoinJoin. The related funds originally came from a TRON wallet on Bitget. The attacker swapped TRX for USDT, then bridged via USDT0 to Ethereum and exchanged it for approximately 145 ETH, which was subsequently swapped through THORChain into approximately 4.59 BTC. These BTC were then split and pre-processed before entering CoinJoin.
OKX founder Star posted on X platform regarding the Bitget hack incident, stating that THORChain is a "very unique" part of the crypto industry. After Bitget was attacked, both the OKX exchange and OKX Wallet immediately took action and stood ready to assist in identifying and tracing the flow of stolen funds, and to block the transfer of stolen funds where possible. Star stated that resilience is an important quality that every crypto company should possess; when security incidents occur, the industry needs to respond quickly, share information, and cooperate to protect users and prevent similar attacks from happening again. He emphasized: "Security is not a competition, but a shared responsibility."
Bitget was hacked, resulting in the theft of approximately $83 million worth of XRP. Ripple officially stated that due to technical architecture limitations, it is unable to freeze funds in external accounts.
Odaily News: According to monitoring by the Bitget CEO, the attacker's addresses have been publicly listed and are being continuously tracked. Bitget has formally demanded that THORChain refuse to provide services to these addresses. Decentralization is a design principle and should not serve as a protective shield that facilitates the handling of known stolen funds.
Bitget CEO Gracy Chen thanked Circle and Tether for their swift action. The Bitget Asset Recovery Bounty Program has now been launched, offering a 5% reward respectively to participants who assist in freezing the attacker's funds and recovering the assets, and calls on exchanges, security researchers, and on-chain investigators to participate.
Odaily news: According to Lookonchain monitoring, about 11 hours ago, an address withdrew 257.6 ETH, worth $692,000, and 545,000 USDT from Binance, then swapped 545,000 USDT for 200.2 ETH. About 1 hour ago, the address transferred all 457.9 ETH, worth $1.23 million, into the Bitget hacker wallet.
Odaily reports: Xie Jiaxin posted on X stating that this Bitget security incident involved multiple non-EVM chains and 10 tokens, and due to the different method of asset theft, different approaches to handling and restoring withdrawals were taken compared to last year's Bybit security incident in order to thoroughly eliminate potential risks.Additionally, Xie Jiaxin stated that he and Bitget CEO Gracy Chen will host a community livestream 30 minutes before withdrawals resume on Monday to discuss this security incident and answer community questions.Bitget announced on X that it will restore withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate normally, and users do not need to take any action in advance.
Odaily News: Bitget posted on X platform that the vulnerability involved in the September 24 security incident has been identified and fixed. The team is conducting additional verification and security checks on the withdrawal infrastructure, with Mandiant and SlowMist continuing to assist with the investigation. The temporary suspension of withdrawals is a security measure and is unrelated to the availability of user assets; user account balances have not been affected, and the Bitget Protection Fund will cover the financial impact of this platform-wide incident.Bitget plans to resume withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on the Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on the Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate, and users do not need to take any action in advance.
DOG 创始人 Leonidas在 X 平台发文喊话 Bitget CEO 称,Bitget 在遭遇黑客攻击数小时后、用户提现仍处于暂停状态时发布 DOG 下架公告,叠加黑客事件引发的信任担忧,导致 DOG在 Bitget 出现严重价格脱锚,并直接影响持有或交易 DOG 的用户。
Bitget updated its security incident report, adjusting the damaged asset amount from $352 million to approximately $388 million. The exchange stated that the situation is now under control and will continue to suspend withdrawals.
Xie Jiayin, Head of Greater China at Bitget, announced the latest updates on the security incident, stating that the security team has accurately identified the hackers' attack vectors and methodologies, and obtained details on how the attackers bypassed security protocols. Tracing the attack back to its source is now highly imminent. Third-party security firms Mandiant and SlowMist are continuing their incident investigation and will release a detailed report subsequently. On-chain tracking confirms that approximately $387.5 million in assets were transferred to attacker addresses, an upward revision from the previously estimated $351.6 million. This adjustment simply incorporates ZEC and TRX into the total and does not indicate any new assets were stolen. No other unauthorized transfers have been detected. Bitget stated that all stolen funds at the platform level will be fully covered by the User Protection Fund, ensuring user assets remain unaffected. Bitget has also officially launched its Fund Recovery Bounty Program. Individuals or entities that voluntarily freeze or proactively retrieve attacker funds will be eligible for a 5% bounty, with prior assistance remaining eligible. The platform has published the attacker's addresses, a real-time fund tracking dashboard, and an information submission portal, and pledged to announce withdrawal times by 12:00 PM on September 26.
Bitget is working to resume withdrawals and has stated it will announce the specific withdrawal restoration plan by 12:00 Beijing Time on September 26.
Bitget CEO Gray Chen posted on X platform that following the security incident, on-chain tracking confirmed the attacker's address received a total of $387.5 million in assets, revised upward from the previously disclosed $351.6 million.Gray Chen stated that the revised amount incorporates Zcash and TRON assets that were not fully accounted for previously, and does not represent newly stolen funds. No unauthorized transfers have occurred since the incident, and the situation remains under control. Bitget has launched a Recovery Bounty Program, offering a 5% bounty to each party that voluntarily assists in freezing the attacker's funds or recovering the funds. The exchange has also launched a real-time tracking dashboard, an information submission portal, and an attacker address API, while supporting reports submitted through Bybit's Lazarus Bounty platform. Bitget is currently making full preparations to resume withdrawals, with a specific withdrawal plan to be announced before 4:00 AM (UTC) on September 26.
According to on-chain detective SomaXBT, Circle has frozen 99,989.91 USDC in an address associated with the Bitget hacker, while approximately 218,000 USDT at the same address remains unfrozen. According to prior on-chain tracking, this address shares a multi-hop fund connection with Bitget's initial stolen funds address. The transferred USDC and USDT remained inactive for over 2.5 hours. The community had previously publicly called on Circle and Tether to freeze the relevant assets. Circle has now taken the lead in executing the action, and SomaXBT subsequently urged Tether to follow suit.
on-chain analyst tanuki42 disclosed that address 0xe07 holds 100,000 USDC and 218,000 USDT originating from the initial address of the stolen Bitget funds. These funds had been dormant for over 2.5 hours before the analyst publicly called on Circle and Tether to freeze the assets. At around 5 PM, crypto researcher SomaXBT posted that Circle had frozen the USDC assets and called on Tether to follow suit. As of press time, Tether has yet to respond.
Binance CEO Richard Teng stated that following Bitget's recent security incident, the Binance security team has been closely collaborating with the Bitget team since the breach was identified. The teams are currently sharing threat intelligence, tracking relevant funds, and assisting in asset recovery. Richard Teng emphasized that the industry will collectively tackle attackers in response to such security incidents, with ongoing operations continuing to advance.
Bitget CEO Gracy Chen 发布安全事件最新进展称,平台正与独立第三方安全团队 Mandiant 和慢雾合作,对此次事件展开全面调查。 Gracy Chen 表示,目前用户账户余额保持完整,此次平台层面安全事件造成的影响将由 Bitget 用户保护基金覆盖;Bitget Wallet 采用自托管模式,其基础设施与 Bitget Exchange 相互独立,因此未受到此次事件影响。 目前 Bitget Exchange 的充值、交易及奖励等功能继续运行,但提币仍暂时暂停,平台正在进行额外安全核查,确认安全后将恢复。Bitget 官方公告也显示,提币服务目前仍处于暂停状态,充值和交易正常运行。 Bitget 表示,后续调查进展及安全事件相关信息将通过官方渠道持续公布。