BTC $83,418.35 -1.40%
ETH $2,679.79 -0.27%
BNB $762.79 -1.96%
XRP $1.49 -1.98%
SOL $118.29 -3.74%
TRX $0.3358 +0.66%
DOGE $0.0936 -3.62%
ADA $0.2450 -4.17%
BCH $307.95 -7.95%
LINK $15.26 +8.99%
HYPE $87.21 -4.76%
AAVE $146.91 -4.87%
SUI $1.14 -9.20%
XLM $0.2271 +4.66%
ZEC $1,451.15 -9.43%
AAPL $338.53 -0.48%
AMZN $246.35 -1.47%
GOOGL $342.54 -0.44%
MSFT $510.33 -1.43%
META $716.71 -4.47%
NVDA $229.27 +1.76%
TSLA $357.80 -4.22%
SNDK $1,713.64 -4.01%
INTC $116.02 -7.57%
SPCX $146.00 -2.23%
MU $1,054.30 -3.88%
AMD $609.36 -4.19%
BTC $83,418.35 -1.40%
ETH $2,679.79 -0.27%
BNB $762.79 -1.96%
XRP $1.49 -1.98%
SOL $118.29 -3.74%
TRX $0.3358 +0.66%
DOGE $0.0936 -3.62%
ADA $0.2450 -4.17%
BCH $307.95 -7.95%
LINK $15.26 +8.99%
HYPE $87.21 -4.76%
AAVE $146.91 -4.87%
SUI $1.14 -9.20%
XLM $0.2271 +4.66%
ZEC $1,451.15 -9.43%
AAPL $338.53 -0.48%
AMZN $246.35 -1.47%
GOOGL $342.54 -0.44%
MSFT $510.33 -1.43%
META $716.71 -4.47%
NVDA $229.27 +1.76%
TSLA $357.80 -4.22%
SNDK $1,713.64 -4.01%
INTC $116.02 -7.57%
SPCX $146.00 -2.23%
MU $1,054.30 -3.88%
AMD $609.36 -4.19%

vulnerability

All
Article
Flash

Bitget CEO live-streamed a response to the platform's first security incident in eight years: the attack originated from a vulnerability in a third-party security product, and the losses will be covered by the user protection fund

In today's community live broadcast, Bitget CEO Gracy responded to recent security incidents and the platform's financial status. She candidly stated that this is the first security incident encountered since Bitget was established 8 years ago. After a complete trace, it was found that hackers exploited vulnerabilities in third-party security products to steal internal network access credentials, forged withdrawal commands to the wallet system, and deceived the wallet into executing abnormal transfers that bypassed risk checks. Gracy emphasized that no private keys were leaked, and cold wallets were unaffected; specific technical details will be disclosed in the formally released security report.Gracy pointed out that the verified losses from this incident are within the coverage of the protection fund, and user funds are not affected. The platform's own funds exceed $1.4 billion, which includes approximately $464 million in the user protection fund. The platform will continue to uphold the security commitments made when the protection fund was established in 2022, planning to replenish the fund to the baseline of $300 million within a week."The protection fund is not just a slogan, but an important mechanism that provides tangible security for users in the event of extreme security incidents," Gracy stated. In the face of sudden security challenges, the platform's comprehensive strength and its ability to take responsibility are important criteria for measuring its risk response capability and long-term credibility. Bitget will continue to uphold its long-term commitment to prioritize user interests.

Magic Eden: Current open orders are not affected by this vulnerability; users in the EVM market from February to October 2024 need to revoke related contract authorizations

Magic Eden announced that the vulnerability occurred in the NFT trading protocol Payment Processor V2 maintained by Limit Break. Magic Eden adopted this protocol for EVM network transaction settlements in 2024 but stopped using V2 in October 2024 and will completely shut down the EVM market in the first quarter of 2026. Therefore, NFTs currently listed on Magic Eden are not affected by this vulnerability.NFTs listed through its EVM market between February and October 2024 may be affected, while listings after October 2024 are generally not impacted. The platform is contacting the protocol owner and maintainer Limit Break to explore other risk mitigation measures, including pausing protocol transfers, and will continue to investigate the actual scope of the impact.Magic Eden reminds users who have listed or traded NFTs on its EVM market to revoke relevant contract authorizations on the Ethereum, Polygon, and Base networks. Users can filter the address through revoke.cash and revoke all authorizations marked as "approved for all" for NFTs. Magic Eden emphasizes that revoking authorization cannot recover assets that have already been transferred.Yuga Labs' Vice President of Blockchain Quit stated today that at 9 AM Eastern Time, attackers exploited the Payment Processor V2 vulnerability to steal a large number of NFTs. After contacting the LimitBreak team, the latter quickly paused the similarly affected Payment Processor V3. However, V2 could not be paused, and V3 on ApeChain is also temporarily unable to be paused. Therefore, the team implemented a white-hat operation, successfully transferring and protecting 23,155 NFTs valued at over 5.7 million dollars.
app_icon
ChainCatcher Building the Web3 world with innovations.