GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

$470 Million in Seized Crypto Assets Moved, US Government-Linked Wallets Involve 4,695 BTC, WBTC, and USDT

Odaily News: According to Bitcoin News monitoring, Arkham reports that US government-linked wallets transferred approximately 4,695 BTC, along with WBTC and USDT, through a series of transactions today, involving total assets worth approximately $470 million. On-chain analyst @TimechainIndex independently flagged the same batch of approximately 4,695 BTC, distributed across 4 transactions. The assets are related to seizures tied to the Bitfinex hack and FTX/Alameda, with some assets already sent to Coinbase Prime deposit addresses. This transfer follows the US government's additional transfer to Coinbase Prime yesterday.

ZachXBT Goes Undercover in Lazarus Group-Linked Money Laundering Ring: Invested Nearly $3.5 Million in OTC Trades with Counterparty Using the Alias Jimmy Green

Odaily News: On-chain detective ZachXBT posted on X that he once posed as a client to infiltrate a criminal group suspected of laundering money for the North Korea-backed hacker organization Lazarus Group, and assisted in freezing funds related to the 2025 Bybit attack.ZachXBT stated that after Bybit suffered a $1.5 billion attack in February 2025, he discovered that more than 15 accounts in public Telegram and Discord groups were seeking help processing transactions related to the stolen funds. He subsequently contacted one of the Telegram users using the alias "Jimmy Green" and built trust through multiple transactions. According to his disclosure, on March 6, 2025, he transferred $3.497 million in USDC to an Ethereum address for a USDC-to-TRON-chain USDT exchange transaction with the counterparty. The source of gas funds for that address can be traced back to the Bybit attack funds and was publicly flagged as a Bybit attack blacklisted address.ZachXBT said that in subsequent communications, the counterparty revealed that their team had been involved in processing the stolen Bybit funds and disclosed in advance that the funds would be moved across chains including Solana. By matching transaction timing, amounts, and on-chain data, he identified a wallet cluster involving more than $12 million in Bybit attack funds, with fund paths spanning multiple networks including BTC→ETH→SOL→TRON. Approximately 442,000 USDT was frozen by Tether, and the group also attempted to launder money through Uniswap liquidity pools and low-liquidity tokens. Additionally, the counterparty disclosed having helped other clients process approximately $3 million in fraudulent proceeds, and ZachXBT traced the related funds to wallets associated with the sanctioned Huione Guarantee.ZachXBT revealed that in this investigation, he initially invested $3.497 million and bore a loss risk of approximately 5% per transaction. The intelligence ultimately obtained was provided to relevant investigative agencies and law enforcement authorities at the earliest opportunity. Since 2022, he has assisted in freezing over $75 million in funds related to North Korea-linked incidents.

Drift Foundation: DFX is not pegged to 1 USDT; the current recovery pool covers only approximately 1% of claims.

The Drift Foundation has outlined the compensation plan following the protocol hack: users will receive 1 DFX token for every 1 USDT lost, with redemption amounts depending on the recovery pool balance that currently covers only about 1% of total claims; Tether has committed to providing up to $127.5 million USDT to support protocol restart and user compensation, with funds matched against Velocity's net protocol revenue rather than disbursed as a lump sum; the claims deadline is January 1, 2028, allowing users to choose to hold DFX or trade it on secondary markets such as Raydium, with the only official link being dfx.drift.trade.

Drift Hack Victims Begin Redemptions, $3.11M Recovery Pool Pays Out Only About 1 Cent per Dollar

victims of the Drift hack, a perpetual contract exchange on Solana, began filing claims on October 1. The recovery pool's initial funding stands at approximately $3.11 million against nearly $295.4 million in verified losses. Victims can redeem USDT through DFX tokens, with each $1 of loss converting to roughly 1.04 cents at launch, meaning a $1,000 loss corresponds to about $10.40.The total supply of DFX is fixed at 299,500,810.998 tokens, with each token corresponding to $1 of verified loss from the April incident, and no additional tokens will be minted. Holders can choose to burn DFX to redeem USDT, sell on secondary markets such as Raydium, or continue holding their claims. Completed redemptions are irreversible, and unclaimed tokens will expire after the claims window closes on January 1, 2028.Future funding for the recovery pool includes a portion of daily net protocol revenue from Velocity, the rebranded exchange rebuilt by Drift, up to $127.5 million in USDT committed by Tether, $20 million in USDT committed by strategic partners, and recovered stolen assets. On the first Friday after claims opened, approximately 216,480 DFX tokens were redeemed for about 2,250 USDT, with Velocity's first revenue transfer amounting to 31 USDT; approximately 13,025.9 ETH is spread across 4 Ethereum wallets, another approximately 2,309.4 ETH passed through Tornado Cash, and about $9.2 million in assets have been frozen at other addresses. (Bitcoin.com News)

Approximately $295 million in user assets stolen, Drift Foundation launches DFX claims and redemption

Odaily News — According to monitoring by Drift Foundation, DFX claims and redemption are now live. Users with verified losses from the April 1 incident can claim 1 DFX per 1 USDT lost. Each DFX corresponds to a claim on the Recovery Pool, which currently holds approximately 3.11 million USDT. The funding sources include a portion of Velocity's daily protocol net revenue, up to 127.5 million USDT in matching funds from Tether, up to 20 million USDT from strategic partners, and assets recovered subsequently.DFX can be redeemed for USDT at a redemption amount calculated as "Recovery Pool balance ÷ DFX outstanding supply." Redeemed DFX will be burned, and transactions are irreversible. The claims window will close on January 1, 2028, at 00:00 UTC, at which point unclaimed DFX will be burned.Yesterday, Drift Foundation released an update on fund recovery efforts related to the April 1 security incident, in which approximately $295 million in user assets were stolen. The Foundation has engaged Mandiant, zeroShadow, and SEAL 911 to conduct investigations and trace funds, with Mandiant identifying the attacker as North Korean threat group UNC6862.

NEAR Co-Founder: NEAR Intents and near.com Restored; Attack Impact Limited to USDT on BSC

Illia Polosukhin stated that the attack involving approximately $3.8 million only affected USDT on BSC. NEAR Intents and near.com are now back online, and affected users will receive full compensation.

$900,000 Bitcoin Theft Case: US Seeks Forfeiture of 110,300 USDT

Odaily News: The U.S. Attorney's Office for the District of Massachusetts filed a civil forfeiture lawsuit on September 28, seeking the forfeiture of 110,300 USDT seized from a Binance account. The case involves phishing text messages impersonating Coinbase, which led to the theft of 33.7 bitcoins, worth approximately $900,000 at the time, from a beneficiary and their family trust held in the same Coinbase account.Investigators said that between June 5 and June 15, 2023, 11.2 of the stolen bitcoins were traced to the Binance account and were quickly converted into Monero. When the FBI requested the account be frozen, it held approximately 758.55 Monero; Binance transferred 110,300 USDT to a government-controlled wallet on August 3, 2026. (Bitcoin.com News)

$388 Million in Crypto Assets Stolen, Bitget CEO Says Full Recovery Unlikely

Odaily News — Gracy Chen, CEO of cryptocurrency exchange Bitget, said the company is not optimistic about recovering the $388 million in crypto assets lost in last week's security incident. Citing the Bybit hack in 2025 as a reference, she noted that approximately one year after that incident, only about 3.5% of the stolen funds had been frozen, and that this does not equate to a completed recovery.Bitget has set up a bounty program offering 5% rewards for frozen funds and recovered funds respectively. The NEAR Intents team said it has intercepted over $50 million in assets related to the attack and frozen approximately $500,000. Tether and Circle have blacklisted the relevant wallets, freezing $318,000 worth of USDT and USDC.Gracy Chen stated that preliminary investigations indicate the attack may match VPN addresses used by North Korea-linked groups, but Bitget has not yet fully ruled out the possibility of an insider job. Bitget has resumed withdrawals in phases, starting with Bitcoin transactions on Monday and continuing with ETH transactions on Tuesday. (Cointelegraph)

MEXC Users Suffer Account Takeover, API Backdoor Leads to $340,000 in Stolen Assets

According to a post by user @shuangfei8, their MEXC account was compromised on September 25 when attackers used forged identification documents to complete a security reset and breach the account within 10 minutes. Although MEXC subsequently froze the account and assisted in its recovery, it failed to revoke the API key created by the attacker during the period of unauthorized control. At 04:12 on September 27, merely 27 minutes after the 24-hour withdrawal restriction was lifted, the attacker exploited this residual API to bypass Google verification and email verification, draining 322,110 USDT and 9,133,999 ONE (totaling approximately $340,000) from the account across six separate transactions. The user has submitted a formal compensation claim to MEXC and attempted to report the incident to the police, demanding that the platform preserve logs, provide a written response regarding the security vulnerability, and return the stolen assets. Furthermore, multiple MEXC users have recently reported receiving suspicious emails resembling a "request to reset security settings," prompting users to immediately navigate to 【API Management】 to check for any unknown API keys.

Slow Mist's Cosine Talks About THORChain: Decentralization Is Not Just a Slogan, and "Decentralized, No Right to Interfere" Should Not Be Used to Respond to Industry Security Incidents

Slow Mist's Cosine posted on X platform, stating that the Bitget hack incident has spread widely, involves a huge amount of funds, and the related funds were quickly linked to North Korean hackers. Institutions such as Circle and Tether promptly assisted in freezing the related funds, with Circle freezing the USDC held by the hackers.Regarding THORChain, Cosine pointed out that when THORChain itself previously suffered a hack, it also quickly intervened in its so-called "decentralized" platform; but this time, when facing a major industry security incident, it responded on the grounds of being "decentralized and having no right to interfere," likened itself to Bitcoin and Ethereum, and continued to earn fees from the hackers' large cross-chain transactions.He stated that decentralization should not just be a slogan. After major security incidents occur, the key is to distinguish which issues need to be solved jointly by the industry. He also believes that platforms such as THORChain should not be easily mentioned in the same breath as Bitcoin and Ethereum, as there are clear differences in the degree of decentralization and mechanisms among different systems.

AMLBot: Some of Bitget's Stolen Funds Reportedly Begin Mixing Through Wasabi CoinJoin

According to AMLBot monitoring, some of the stolen funds from the Bitget hack have reportedly begun being mixed through Wasabi CoinJoin. The related funds originally came from a TRON wallet on Bitget. The attacker swapped TRX for USDT, then bridged via USDT0 to Ethereum and exchanged it for approximately 145 ETH, which was subsequently swapped through THORChain into approximately 4.59 BTC. These BTC were then split and pre-processed before entering CoinJoin.

Bitget Asset Recovery Bounty Program Launched: 5% Reward Each for Freezing and Recovering Attacker Funds

Bitget CEO Gracy Chen thanked Circle and Tether for their swift action. The Bitget Asset Recovery Bounty Program has now been launched, offering a 5% reward respectively to participants who assist in freezing the attacker's funds and recovering the assets, and calls on exchanges, security researchers, and on-chain investigators to participate.

Bitget hacker suspected of receiving $1.23 million ETH transfer

Odaily news: According to Lookonchain monitoring, about 11 hours ago, an address withdrew 257.6 ETH, worth $692,000, and 545,000 USDT from Binance, then swapped 545,000 USDT for 200.2 ETH. About 1 hour ago, the address transferred all 457.9 ETH, worth $1.23 million, into the Bitget hacker wallet.

Xie Jiaxin: The method of theft in this security incident differs from last year's Bybit incident, so different withdrawal recovery arrangements are being adopted

Odaily reports: Xie Jiaxin posted on X stating that this Bitget security incident involved multiple non-EVM chains and 10 tokens, and due to the different method of asset theft, different approaches to handling and restoring withdrawals were taken compared to last year's Bybit security incident in order to thoroughly eliminate potential risks.Additionally, Xie Jiaxin stated that he and Bitget CEO Gracy Chen will host a community livestream 30 minutes before withdrawals resume on Monday to discuss this security incident and answer community questions.Bitget announced on X that it will restore withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate normally, and users do not need to take any action in advance.

Bitget: Withdrawals to Resume in Phases, Bitcoin Network Withdrawals Opening on September 28

Odaily News: Bitget posted on X platform that the vulnerability involved in the September 24 security incident has been identified and fixed. The team is conducting additional verification and security checks on the withdrawal infrastructure, with Mandiant and SlowMist continuing to assist with the investigation. The temporary suspension of withdrawals is a security measure and is unrelated to the availability of user assets; user account balances have not been affected, and the Bitget Protection Fund will cover the financial impact of this platform-wide incident.Bitget plans to resume withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on the Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on the Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate, and users do not need to take any action in advance.

Bitget Stolen Funds Tracking: Circle Has Frozen Nearly 100,000 USDC on Linked Addresses; 218,000 USDT Remains Transferable

According to on-chain detective SomaXBT, Circle has frozen 99,989.91 USDC in an address associated with the Bitget hacker, while approximately 218,000 USDT at the same address remains unfrozen. According to prior on-chain tracking, this address shares a multi-hop fund connection with Bitget's initial stolen funds address. The transferred USDC and USDT remained inactive for over 2.5 hours. The community had previously publicly called on Circle and Tether to freeze the relevant assets. Circle has now taken the lead in executing the action, and SomaXBT subsequently urged Tether to follow suit.

Bitget Security Incident Response Contest: Circle Quickly Freezes 100,000 USDC in Address Linked to a Hacker, Tether Yet to Take Corresponding Action

on-chain analyst tanuki42 disclosed that address 0xe07 holds 100,000 USDC and 218,000 USDT originating from the initial address of the stolen Bitget funds. These funds had been dormant for over 2.5 hours before the analyst publicly called on Circle and Tether to freeze the assets. At around 5 PM, crypto researcher SomaXBT posted that Circle had frozen the USDC assets and called on Tether to follow suit. As of press time, Tether has yet to respond.

Bitget Security Incident 12-Hour Progress Report: Cold Wallets Secure, No Commitment to Withdrawal Recovery Timelines That Cannot Be Fulfilled

Bitget CEO Gracy Chen posted a 12-hour progress report on the security incident on X, including:1. Affected assets include ETH, XRP (largest single-chain loss), BNB, AVAX, USDT, USDC, and other tokens. Affected chains include: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. All on-chain cold wallets have been confirmed secure and unaffected.2. All foundations of the affected chains have been contacted, and some foundations have confirmed the freezing of the hacker's wallet addresses.3. Based on IP behavioral characteristics and on-chain analysis, the attack methodology is highly consistent with known patterns of North Korean hacker groups. Relevant authorities have been notified, and full cooperation is being provided for a global investigation.4. Bitget Wallet (decentralized wallet) operates completely independently from Bitget exchange infrastructure, and this incident has no impact on it. Bitget Wallet assets are completely safe.5. Transparent disclosure regarding the platform's financial status: In addition to over $464 million in protection funds (all held in publicly verifiable wallet addresses), Bitget's own assets exceed $1 billion. User funds are covered at a 1:1 ratio, and all data can be verified on-chain.6. Regarding withdrawal recovery timing: The goal is to achieve full recovery as soon as possible. Once a specific time window is confirmed, an announcement will be made immediately. No commitment will be made to timelines that cannot be fulfilled.

Latest Data: Top 3 Stolen Assets from Bitget Are XRP, ETH, and USDT, with XRP Losses Exceeding $157 Million

Odaily News: According to LookonChain monitoring, the breakdown of assets stolen from Bitget is as follows:102.93 million XRP (approximately $157.48 million);31,890 ETH (valued at $85.75 million);34.75 million USDT (approximately $34.75 million);21.05 million USDC ($21.05 million);19.67 million USD₮0 ($19.67 million);3,000 XAUt (equivalent to $12.82 million);12,719 BNB (valued at $9.88 million);821,012 AVAX (valued at $8.38 million);20.59 million $TRX (approximately $7.07 million).

Stolen assets at Bitget involve 9 types of tokens, with XRP valued at up to $157 million.

According to Lookonchain data, the assets stolen in the Bitget incident comprise 9 different token categories, totaling approximately $356.9 million in value. Of these, approximately 102.93 million XRP (worth around $157.48 million) represents the highest-valued category, alongside 31,890 ETH (approximately $85.75 million). The remaining stolen assets include approximately 34.75 million USDT ($34.75 million), 21.06 million USDC ($21.06 million), 19.67 million USD₮0 ($19.67 million), 3,000 XAUt ($12.82 million), 12,719 BNB ($9.88 million), 821,000 AVAX ($8.38 million), and 20.59 million TRX ($7.07 million).