GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

AMLBot: Some of Bitget's Stolen Funds Reportedly Begin Mixing Through Wasabi CoinJoin

According to AMLBot monitoring, some of the stolen funds from the Bitget hack have reportedly begun being mixed through Wasabi CoinJoin. The related funds originally came from a TRON wallet on Bitget. The attacker swapped TRX for USDT, then bridged via USDT0 to Ethereum and exchanged it for approximately 145 ETH, which was subsequently swapped through THORChain into approximately 4.59 BTC. These BTC were then split and pre-processed before entering CoinJoin.

Xie Jiaxin: The method of theft in this security incident differs from last year's Bybit incident, so different withdrawal recovery arrangements are being adopted

Odaily reports: Xie Jiaxin posted on X stating that this Bitget security incident involved multiple non-EVM chains and 10 tokens, and due to the different method of asset theft, different approaches to handling and restoring withdrawals were taken compared to last year's Bybit security incident in order to thoroughly eliminate potential risks.Additionally, Xie Jiaxin stated that he and Bitget CEO Gracy Chen will host a community livestream 30 minutes before withdrawals resume on Monday to discuss this security incident and answer community questions.Bitget announced on X that it will restore withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate normally, and users do not need to take any action in advance.

Bitget: Withdrawals to Resume in Phases, Bitcoin Network Withdrawals Opening on September 28

Odaily News: Bitget posted on X platform that the vulnerability involved in the September 24 security incident has been identified and fixed. The team is conducting additional verification and security checks on the withdrawal infrastructure, with Mandiant and SlowMist continuing to assist with the investigation. The temporary suspension of withdrawals is a security measure and is unrelated to the availability of user assets; user account balances have not been affected, and the Bitget Protection Fund will cover the financial impact of this platform-wide incident.Bitget plans to resume withdrawals in phases: Bitcoin network withdrawals will resume on September 28 at 8:00 (UTC); ETH withdrawals on the Ethereum, BSC, Arbitrum, Base, and Optimism networks will resume on September 29 at 8:00 (UTC); USDT withdrawals on the Ethereum, BSC, Solana, and Tron networks will resume on September 30 at 8:00 (UTC); other tokens, fiat, and P2P withdrawals will resume on October 2 at 8:00 (UTC). Trading and deposit services continue to operate, and users do not need to take any action in advance.

Xie Jiayin: Attack paths and methods have been precisely identified, and the stolen funds will be fully covered by the user protection fund.

Xie Jiayin, Head of Greater China at Bitget, announced the latest updates on the security incident, stating that the security team has accurately identified the hackers' attack vectors and methodologies, and obtained details on how the attackers bypassed security protocols. Tracing the attack back to its source is now highly imminent. Third-party security firms Mandiant and SlowMist are continuing their incident investigation and will release a detailed report subsequently. On-chain tracking confirms that approximately $387.5 million in assets were transferred to attacker addresses, an upward revision from the previously estimated $351.6 million. This adjustment simply incorporates ZEC and TRX into the total and does not indicate any new assets were stolen. No other unauthorized transfers have been detected. Bitget stated that all stolen funds at the platform level will be fully covered by the User Protection Fund, ensuring user assets remain unaffected. Bitget has also officially launched its Fund Recovery Bounty Program. Individuals or entities that voluntarily freeze or proactively retrieve attacker funds will be eligible for a 5% bounty, with prior assistance remaining eligible. The platform has published the attacker's addresses, a real-time fund tracking dashboard, and an information submission portal, and pledged to announce withdrawal times by 12:00 PM on September 26.

Latest Data: Top 3 Stolen Assets from Bitget Are XRP, ETH, and USDT, with XRP Losses Exceeding $157 Million

Odaily News: According to LookonChain monitoring, the breakdown of assets stolen from Bitget is as follows:102.93 million XRP (approximately $157.48 million);31,890 ETH (valued at $85.75 million);34.75 million USDT (approximately $34.75 million);21.05 million USDC ($21.05 million);19.67 million USD₮0 ($19.67 million);3,000 XAUt (equivalent to $12.82 million);12,719 BNB (valued at $9.88 million);821,012 AVAX (valued at $8.38 million);20.59 million $TRX (approximately $7.07 million).

Stolen assets at Bitget involve 9 types of tokens, with XRP valued at up to $157 million.

According to Lookonchain data, the assets stolen in the Bitget incident comprise 9 different token categories, totaling approximately $356.9 million in value. Of these, approximately 102.93 million XRP (worth around $157.48 million) represents the highest-valued category, alongside 31,890 ETH (approximately $85.75 million). The remaining stolen assets include approximately 34.75 million USDT ($34.75 million), 21.06 million USDC ($21.06 million), 19.67 million USD₮0 ($19.67 million), 3,000 XAUt ($12.82 million), 12,719 BNB ($9.88 million), 821,000 AVAX ($8.38 million), and 20.59 million TRX ($7.07 million).

Duelbits Hot Wallet Suspected Private Key Leak, Approximately $4.2 Million in Assets Stolen and Transferred

According to Scam Sniffer (@realScamSniffer), Duelbits' hot wallets on Ethereum, BSC, and Tron are suspected of having leaked private keys, with approximately $4.2 million in assets flowing to newly created addresses. The transferred assets include 836 ETH, 1.62 million USDT, 97,000 USDC, 209 BNB, and 192,000 TRX, with most of them already converted to ETH. The hacker's EVM address is 0xa77e24fe29d16e051e487ef4ea7b056cb05aef76.

Chainflip Hit by Attack, 736,442 USDT Stolen, Recovery Expected Around Monday

Odaily reports: Cross-chain protocol Chainflip has disclosed that an attack targeting Tron USDT occurred yesterday. It has been confirmed that 736,442.17 USDT was stolen through 6 unauthorized payments, while another 115,654.41 USDT in user swaps remained in the vault due to failed payments. All other funds were unaffected.Chainflip stated that the attacker exploited a vulnerability in the Tron transaction memo mechanism by attaching custom memos to transactions already signed by validators, causing the system to identify the same deposit as separate swaps and issue refunds again, ultimately resulting in duplicate payments. The attacker carried out 8 operations over approximately 90 minutes, gradually increasing the amounts. Chainflip said it has completed a fix and has flagged the stolen funds to relevant authorities in an attempt to recover them. The protocol is expected to resume operations as early as Monday and will be responsible for compensating affected users for their losses.

Hackers Steal Crypto Wallet Data Using Google Docs and Fake Claude AI Pages

According to security firm Huntress, hackers are distributing credential-stealing malware to cryptocurrency users through forged Google Docs files, malicious files hosted on GitHub, and cloned Claude.ai pages. Attackers impersonate senior CoinDesk employees on the social platform X, luring victims into opening Google Docs documents containing malicious code under the guise of an online meeting invitation, which then prompts users to manually install the malicious software. Mac users face threats from Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are served fake Google API Connector updates that, once installed, deploy NetSupport RAT and counterfeit Ledger hardware wallet applications. Additionally, hackers have placed fraudulent ads on search engines like Bing to lure users to cloned Claude.ai pages where they execute malicious commands; the associated malware, MacSync and SectopRAT, can steal cookies, saved passwords, mnemonic phrases, and payment card information. Security firm Socket also concurrently identified 16 malicious extensions targeting Chrome and Edge, capable of draining EVM, Solana, and Tron wallet assets.

Analyst: Address poisoning attacks on Tron have resulted in 15 victims losing $9.4 million over the past 4 weeks

Odaily News: On-chain analyst Specter has disclosed that a series of address poisoning attacks on the Tron network over the past 4 weeks have caused 15 victims to lose approximately $9.4 million in total. Among them, two victims each had $2.5 million stolen, while another lost $2 million. After succeeding, the attackers quickly converted all stolen assets into the stablecoin USDD and transferred them to a collection address, where all funds currently remain. Specter calls on wallet service providers in the Tron ecosystem to implement interception measures as soon as possible and reminds users to carefully verify addresses when making transfers.

A hacker in Zhejiang Province was sentenced to four years and four months in prison for illegally controlling over 150 servers and concealing illicit proceeds in cryptocurrency.

Zhou, a hacker from Quzhou City, Zhejiang Province, was sentenced by a court to four years and four months’ imprisonment and fined for the crime of illegally controlling computer information systems. Zhou exploited security vulnerabilities in websites to illegally control over 150 government and enterprise servers, causing links on websites belonging to 157 organizations to redirect to overseas pornographic websites. He also profited by reselling control rights. According to disclosures by the investigating authorities, Zhou settled his illicit proceeds using virtual currencies such as USDT and TRX, dispersing and concealing them across multiple cryptocurrency wallets. Authorities subsequently seized assets valued at over RMB 42 million through a cryptocurrency tracing system. Additionally, Zhou voluntarily surrendered over RMB 28 million in illicit gains.

A hacker organization has made over $14 million through token scams and X account hijackings

on-chain analyst Specter stated that the hijacking incidents of investor Keith Gill, Matt Furie, and WinRAR accounts on the X platform are all linked to the same hacker organization. This organization has accumulated over $14 million in profits by hijacking accounts to promote tokens and conducting cross-chain money laundering, with funds flowing through five chains: Solana, BNB Chain, Ethereum, Tron, and Hyperliquid.Specter claims the organization may also be connected to a $2.45 million wstETH phishing attack in 2024. The investigation found that hackers used compromised accounts to issue Pepe imitation tokens, incorporating a built-in 2% automatic fee mechanism to generate profits; related fund flows are associated with the bnbshare.fun platform and multiple Solana, Tron, and Ethereum addresses. Analysis also showed that several tokens (including USOR, VDOR, DROID, WCOR, UGOR) were used to inflate market caps before being dumped to zero.

Wasabi Protocol attacker has deposited all stolen funds into Tornado Cash

According to monitoring by on-chain analyst Specter, the Wasabi Protocol attacker has deposited all stolen funds into Tornado Cash, moving approximately $5.9 million into Tornado Cash. Additionally, North Korean hacking groups have also used Tornado Cash to launder stolen funds from KelpDAO and LayerZero. Their process involved first cross-chaining the assets to Bitcoin, then routing them through Wasabi Mixer, extracting and cross-chaining back to Ethereum, depositing into Tornado Cash, subsequently withdrawing to new wallets and dispersing across multiple addresses. The new wallets then deployed tokens, used the stolen funds to buy in, removed liquidity from the deployment wallet, cross-chained to Tron (USDT), held for several hours or days, and finally sent to OTC-related wallets.

Researcher cracks 15-bit ECC key, earns 1 Bitcoin reward

According to Odaily, independent researcher Giancarlo Lelli was awarded the Q-Day Prize and 1 Bitcoin by quantum security startup Project Eleven for successfully cracking the encryption keys protecting Bitcoin. Giancarlo Lelli utilized publicly available quantum hardware and a variant of Shor's algorithm to crack a 15-bit encryption key among 32,767 possibilities. The difficulty of this quantum attack is 512 times greater than the 6-bit key record set in September 2025. Project Eleven CEO Alex Pruden stated that the resource requirements for such attacks continue to decline, with approximately 6.9 million Bitcoins currently held in vulnerable static addresses, including 1 million Bitcoins owned by Satoshi Nakamoto. The Bitcoin network has proposed BIP-360 to introduce quantum-resistant address types, while platforms such as Ethereum, Ripple, and Tron have also begun releasing plans for transitioning to post-quantum defenses.

Russian exchange Grinex suspends operations after ~$15 million attack

According to The Block, Grinex—a Russia-linked cryptocurrency exchange—suspended withdrawals and trading on Thursday after suffering a hack reportedly worth approximately $15 million. Blockchain analytics firm Elliptic stated that the stolen funds consisted of USDT, which were subsequently moved across the Tron and Ethereum networks and swapped for TRX and ETH to reduce the risk of being frozen by Tether. Grinex said its wallet infrastructure was hit by a “large-scale cyberattack,” resulting in losses exceeding 1 billion rubles—approximately $13.1 million. Reports indicate Grinex is widely regarded as one of the successor platforms to sanctioned exchange Garantex, which U.S. authorities targeted last year for facilitating hundreds of millions of dollars in illicit fund flows.

Aethir Prevents Cross-Chain Bridge Vulnerability Attack and Promises Compensation

Decentralized GPU cloud computing infrastructure platform Aethir confirmed that its Ethereum-related bridge contract was attacked. The team promptly disconnected the affected contract and, in collaboration with major exchanges, blacklisted the hacker’s wallet, limiting losses to under $90,000. Earlier, blockchain security firm PeckShield estimated losses at $400,000. The attacker exploited Aethir’s cross-chain smart contract, AethirOFTAdapter, to transfer stolen funds from BNB Chain to Tron. Aethir stated that its Ethereum mainnet ATH token supply remains unaffected. It plans to release a detailed compensation plan and incident analysis next week and will collaborate with exchanges including Binance, Upbit, and Bithumb to freeze funds. Web3 security platform ZeroShadow is assisting with the investigation. In 2025, Aethir achieved $127.8 million in revenue and deployed over 440,000 GPU containers globally.