Bitget traces 351.6 million dollars in unauthorized wallet transfers
Bitget chief executive Gracy Chen said about 351.6 million dollars moved in 19 unauthorized transfers from hot and warm wallets, CNBC reported, and The Hacker News says the firm suspects North Korean hackers. Cold wallets stayed secure. Chen said a user protection fund of more than 464 million dollars covers the loss. Earlier chain estimates of about 183 million dollars missed some affected chains.
Economics & Markets··Evening
19 transfers left the hot wallets
Bitget chief executive Gracy Chen said investigators tied a breach to about 351.6 million dollars of unauthorized transfers, in 19 movements out of hot and warm wallets, CNBC reported. The Hacker News, citing Bitget, says the exchange's security systems identified unauthorized transfers on 24 September involving a limited number of hot wallets, and that suspected North Korean threat actors stole 351.6 million dollars from hot and warm wallets.[1], [2]
Cold wallets and the protection fund
CNBC says cold wallets stayed secure and that Chen said the loss is covered by a user protection fund of more than 464 million dollars. Earlier on-chain estimates of about 183 million dollars missed some of the affected chains, the company told CNBC. The Hacker News says Bitget's cold wallets and the overwhelming majority of platform assets remain secure, and that customer account balances remain accurate while deposits and trading continue.[1], [2]
The firm points at North Korean patterns
CNBC says Chen treated internet-protocol addresses linked to VPN services previously used by a North Korean hacking group as a suspicion, not a completed attribution. She said the attacker entered a backend wallet system, spoofed transfer information and started the signing process, and that a private-key compromise has been ruled out. The Hacker News quotes Chen that, based on IP behaviour and on-chain analysis, the method is highly consistent with known patterns of North Korean hacker organisations, and that the attacker compromised a critical backend system, spoofed transaction data and started the authorization process. The specific intrusion method remains under investigation, The Hacker News reports. The Hacker News says withdrawals are paused during the security review while deposits and trading continue. Chen named ETH, XRP, BNB, AVAX, USDT and USDC among the affected assets. Bitget called in Mandiant and SlowMist. Cold wallets are not on that list.[1], [2]