환율 -
|
USDT(업비트) -
|
BTC.D -
|
총시총 -
|
접속 0

Bitget traces $387.5 million hack to third-party security product, fund to cover losses

Bitget traces $387.5 million hack to third-party security product, fund to cover losses

Bitget traced the Sept. 24 hack to a vulnerability in a third-party vendor's security product.

Its user protection fund will cover the full $387.5 million loss, leaving user balances unchanged.

Withdrawals reopen in phases: BTC (Sept. 28), ETH (Sept. 29), USDT (Sept. 30) and the rest (Oct. 2).

광고

Bitget said a vulnerability in a third-party security product it used allowed attackers to steal about $387.5 million in crypto on Sept. 24, and that its user protection fund will cover the entire loss. "It's also, in my opinion, the trickiest part," Chief Executive Gracy Chen told The Block, referring to how the attacker erased traces of fraudulent withdrawal commands. Withdrawals, frozen since the attack, have been reopening asset by asset since bitcoin came back on Sept. 28.

Main attack began 27 minutes after test transfers

  1. The attacker first sent 0.184 ETH from an Ethereum hot wallet (an internet-connected wallet used for withdrawals) and 193 TRX from a Tron hot wallet. Chen disclosed the transfers in the interview with The Block; both fell below risk-control thresholds and triggered no alert.
  2. Seventeen large transfers followed across eight blockchains: Ethereum, XRP Ledger, Zcash, BNB Chain, Base, Arbitrum, Optimism and Avalanche. Bitget's ledger reconciliation system caught the discrepancy at 19:05, seven minutes after the first large transfer, and halted all withdrawals. Bitget initially put the loss at $351.6 million.
  3. Bitget revised the figure to $387.5 million after adding Zcash (ZEC) and Tron (TRX) assets. It said the change reflected a more complete accounting, not additional theft, and offered a 5% bounty on funds frozen or recovered.
  4. Bitget asked the decentralized swap protocol THORChain to block the hacker's trades. THORChain effectively refused, saying it is a decentralized network anyone can use, like Bitcoin and Ethereum. Bitget published its phased withdrawal schedule the same day.
  5. Bitget disclosed the cause. The attacker exploited a vulnerability in a third-party security product to obtain high-privilege internal credentials, then injected fraudulent withdrawal commands into the wallet system to bypass risk controls. Bitget said private keys and cold wallets (offline storage) were not compromised. It reopened bitcoin withdrawals the same day, processing 4,098 BTC by 6 p.m. KST.
  6. Ether withdrawals reopened. According to Bitget's official account, about 9,674 ETH came in and about 9,023 ETH went out in the first hour through 09:00 UTC, a net inflow of about 651 ETH. "We actually saw a net inflow," Chen wrote.
광고

Withdrawal restart schedule

Sept. 28Bitcoin (BTC) on the Bitcoin and BSC networks
Sept. 29Ether (ETH) on the Ethereum, BSC, Arbitrum, Base and Optimism networks
Sept. 30Tether (USDT) on the Ethereum, BSC, Solana and Tron networks
Oct. 2All remaining tokens, fiat and P2P

Each restart takes effect at 08:00 UTC (5 p.m. KST). Bitget said it has found and fixed the vulnerability and that deposits and trading continue normally. User account balances are unchanged, and the protection fund will absorb 100% of the loss, it said. The fund stood at about $465 million on Sept. 25, according to The Block. Bitget said it will top the depleted fund back up to more than $300 million with its own capital within a week. Chen told The Block the company held more than $1.4 billion in its own reserves as of an Aug. 31 audit and that a formal incident report would be released this week.

Where hacker funds were stopped, and where they slipped through

According to Chen, cross-chain trading service NEAR Intents flagged more than $50 million in attempted laundering flows, froze $503,000 mid-execution and waived its own share of the bounty. Circle and Tether also froze about $318,000 in stablecoins held in one of the hacker's wallets. Funds did escape through THORChain, however: CoinDesk counted about 2,390 ETH (about $6.3 million) swapped into 75.2 BTC on THORChain by wallets linked to the hacker.

At a Sept. 25 town hall, Chen said IP addresses, behavior patterns and on-chain traces tied the attack to a North Korea-linked hacking group. In the interview with The Block, however, she held off on naming a specific group until the formal incident report.

광고

An unregistered offshore exchange for South Korean users

Bitget has not registered as a virtual asset service provider with South Korea's Financial Intelligence Unit (FIU), making it an unregistered offshore exchange for local users. At 9:16 a.m. KST on Sept. 25, Korean exchange Upbit posted a notice urging caution over digital asset withdrawals to Bitget. Upbit said it had confirmed signs of asset theft stemming from a security problem at Bitget, asked users to be careful when withdrawing to Bitget, and said it could restrict withdrawals to Bitget as an investor protection measure depending on the situation.

Bitget's own token, BGB, is not listed on the Korean won markets of local exchanges Upbit or Bithumb (according to both exchanges' public APIs checked at 11:36 p.m. KST on Sept. 29). On Bitget's spot market, BGB fell from around $2.06 on the day of the hack to as low as $1.88, a drop of about 9%, then traded between $1.96 and $2.08 through Sept. 28. It was around $1.99 at 11:36 p.m. KST on Sept. 29.

BGB details →
This article summarizes public announcements and documents. It is not investment advice; investment decisions and their consequences are your own.