BTC $82,895.03 -0.67%
ETH $2,658.47 +0.09%
BNB $756.39 -2.02%
XRP $1.48 -1.40%
SOL $117.04 -2.61%
TRX $0.3345 +0.34%
DOGE $0.0924 -2.51%
ADA $0.2399 -4.82%
BCH $303.50 -3.79%
LINK $15.05 +6.69%
HYPE $86.33 -4.22%
AAVE $147.47 -2.55%
SUI $1.10 -11.26%
XLM $0.2255 +5.15%
ZEC $1,373.92 -12.47%
AAPL $337.68 -0.73%
AMZN $246.07 -1.13%
GOOGL $342.11 +0.00%
MSFT $507.93 -1.70%
META $716.00 -2.49%
NVDA $228.33 +1.92%
TSLA $357.02 -3.63%
SNDK $1,697.55 -2.31%
INTC $114.11 -4.84%
SPCX $145.74 -2.22%
MU $1,049.63 -1.74%
AMD $604.79 -2.39%
BTC $82,895.03 -0.67%
ETH $2,658.47 +0.09%
BNB $756.39 -2.02%
XRP $1.48 -1.40%
SOL $117.04 -2.61%
TRX $0.3345 +0.34%
DOGE $0.0924 -2.51%
ADA $0.2399 -4.82%
BCH $303.50 -3.79%
LINK $15.05 +6.69%
HYPE $86.33 -4.22%
AAVE $147.47 -2.55%
SUI $1.10 -11.26%
XLM $0.2255 +5.15%
ZEC $1,373.92 -12.47%
AAPL $337.68 -0.73%
AMZN $246.07 -1.13%
GOOGL $342.11 +0.00%
MSFT $507.93 -1.70%
META $716.00 -2.49%
NVDA $228.33 +1.92%
TSLA $357.02 -3.63%
SNDK $1,697.55 -2.31%
INTC $114.11 -4.84%
SPCX $145.74 -2.22%
MU $1,049.63 -1.74%
AMD $604.79 -2.39%

bitget

Bitget was established in 2018 and is a cryptocurrency exchange and Web3 company. As of early 2024, Bitget provides services to over 100 countries and regions worldwide, helping more than 25 million users achieve intelligent trading transformations through leading copy trading and other trading solutions.
All
Article
Flash

first_img NEAR Intents: Frozen $503,000 of stolen funds from Bitget

Cross-chain trading protocol NEAR Intents stated in a post on X that on September 24, Bitget was attacked, resulting in approximately $387.5 million in funds being stolen, most of which were aggregated into Ethereum and converted to ETH. The hacker attempted to transfer over $50 million through NEAR Intents, but ultimately only $166,000 was successfully transferred, while $503,000 was intercepted during the execution process.NEAR Intents indicated that the relevant data comes from on-chain tracking tools, Arkham, internal logs, and risk control layer SHIELD, among other sources. The figures listed are rounded estimates, with an assessment deviation of no more than 10%. SHIELD identified over $50 million in money laundering attempts and has filtered out duplicate flows, of which $166,000 has been successfully transferred, while another $503,000 was frozen midway through execution and remains restricted, pending legal and recovery procedures.NEAR Intents stated: permissionless does not equal neutral, the team refuses to assist in cashing out stolen assets and will forgo the bounty from this incident to allow Bitget to recover funds as much as possible. Bitget previously established a 5% + 5% bounty arrangement. NEAR Intents also mentioned that the protocol will remain permissionless but set boundaries, and will combat money laundering of stolen funds, while suggesting Bitget contact legal and law enforcement channels to handle the frozen funds.

Bitget CEO live-streamed a response to the platform's first security incident in eight years: the attack originated from a vulnerability in a third-party security product, and the losses will be covered by the user protection fund

In today's community live broadcast, Bitget CEO Gracy responded to recent security incidents and the platform's financial status. She candidly stated that this is the first security incident encountered since Bitget was established 8 years ago. After a complete trace, it was found that hackers exploited vulnerabilities in third-party security products to steal internal network access credentials, forged withdrawal commands to the wallet system, and deceived the wallet into executing abnormal transfers that bypassed risk checks. Gracy emphasized that no private keys were leaked, and cold wallets were unaffected; specific technical details will be disclosed in the formally released security report.Gracy pointed out that the verified losses from this incident are within the coverage of the protection fund, and user funds are not affected. The platform's own funds exceed $1.4 billion, which includes approximately $464 million in the user protection fund. The platform will continue to uphold the security commitments made when the protection fund was established in 2022, planning to replenish the fund to the baseline of $300 million within a week."The protection fund is not just a slogan, but an important mechanism that provides tangible security for users in the event of extreme security incidents," Gracy stated. In the face of sudden security challenges, the platform's comprehensive strength and its ability to take responsibility are important criteria for measuring its risk response capability and long-term credibility. Bitget will continue to uphold its long-term commitment to prioritize user interests.

first_img Bitget updates on the security incident progress: the stolen amount is revised to 387.5 million USD, and the withdrawal recovery time will be announced before 12 PM tomorrow

Bitget TradFi Chief Growth Officer Xie Jiayin issued an update on the platform's security incident, stating that the withdrawal time will be announced before noon tomorrow. The security team has identified the hacker's attack path and methods, and has grasped the details of how the attacker bypassed security measures, coming very close to tracing the source of the attack. The incident investigation by third-party security teams Mandiant and SlowMist is still ongoing, with a detailed report pending from the security team.On-chain tracking confirms that approximately $387.5 million has been transferred to the hacker's address, previously estimated at $351.6 million. This revision includes ZEC and TRX, and no other unauthorized transfers have been found. Xie Jiayin stated that the stolen funds at the platform level will be fully covered by the Bitget User Protection Fund, ensuring that user assets are not subject to any losses.Bitget has officially launched a fund recovery bounty program, offering a 5% bounty for voluntarily freezing the attacker’s funds and a 5% bounty for voluntarily recovering funds. The bounty also applies to assistance already provided. The platform has published the attacker's address, a real-time tracking dashboard, and a submission portal, with relevant information also available for submission through Bybit's Lazarus bounty platform.
app_icon
ChainCatcher Building the Web3 world with innovations.