BTC $84,008.86 +1.36%
ETH $2,711.04 +2.22%
BNB $763.62 +0.30%
XRP $1.50 +0.85%
SOL $119.22 +0.61%
TRX $0.3353 +0.35%
DOGE $0.0949 +1.74%
ADA $0.2502 +1.43%
BCH $312.07 +0.98%
LINK $15.33 +10.27%
HYPE $88.19 -1.84%
AAVE $166.61 +12.49%
SUI $1.15 -0.31%
XLM $0.2291 +7.04%
ZEC $1,417.94 -9.06%
AAPL $336.48 -1.27%
AMZN $247.12 -0.34%
GOOGL $342.36 +0.46%
MSFT $508.56 -1.12%
META $720.30 -1.32%
NVDA $230.78 +2.90%
TSLA $358.86 -2.93%
SNDK $1,733.18 +1.09%
INTC $116.54 -2.14%
SPCX $146.97 -1.67%
MU $1,071.49 +1.31%
AMD $613.96 -0.04%
BTC $84,008.86 +1.36%
ETH $2,711.04 +2.22%
BNB $763.62 +0.30%
XRP $1.50 +0.85%
SOL $119.22 +0.61%
TRX $0.3353 +0.35%
DOGE $0.0949 +1.74%
ADA $0.2502 +1.43%
BCH $312.07 +0.98%
LINK $15.33 +10.27%
HYPE $88.19 -1.84%
AAVE $166.61 +12.49%
SUI $1.15 -0.31%
XLM $0.2291 +7.04%
ZEC $1,417.94 -9.06%
AAPL $336.48 -1.27%
AMZN $247.12 -0.34%
GOOGL $342.36 +0.46%
MSFT $508.56 -1.12%
META $720.30 -1.32%
NVDA $230.78 +2.90%
TSLA $358.86 -2.93%
SNDK $1,733.18 +1.09%
INTC $116.54 -2.14%
SPCX $146.97 -1.67%
MU $1,071.49 +1.31%
AMD $613.96 -0.04%

stolen

All
Article
Flash

first_img NEAR Intents: Frozen $503,000 of stolen funds from Bitget

Cross-chain trading protocol NEAR Intents stated in a post on X that on September 24, Bitget was attacked, resulting in approximately $387.5 million in funds being stolen, most of which were aggregated into Ethereum and converted to ETH. The hacker attempted to transfer over $50 million through NEAR Intents, but ultimately only $166,000 was successfully transferred, while $503,000 was intercepted during the execution process.NEAR Intents indicated that the relevant data comes from on-chain tracking tools, Arkham, internal logs, and risk control layer SHIELD, among other sources. The figures listed are rounded estimates, with an assessment deviation of no more than 10%. SHIELD identified over $50 million in money laundering attempts and has filtered out duplicate flows, of which $166,000 has been successfully transferred, while another $503,000 was frozen midway through execution and remains restricted, pending legal and recovery procedures.NEAR Intents stated: permissionless does not equal neutral, the team refuses to assist in cashing out stolen assets and will forgo the bounty from this incident to allow Bitget to recover funds as much as possible. Bitget previously established a 5% + 5% bounty arrangement. NEAR Intents also mentioned that the protocol will remain permissionless but set boundaries, and will combat money laundering of stolen funds, while suggesting Bitget contact legal and law enforcement channels to handle the frozen funds.

first_img Bitget updates on the security incident progress: the stolen amount is revised to 387.5 million USD, and the withdrawal recovery time will be announced before 12 PM tomorrow

Bitget TradFi Chief Growth Officer Xie Jiayin issued an update on the platform's security incident, stating that the withdrawal time will be announced before noon tomorrow. The security team has identified the hacker's attack path and methods, and has grasped the details of how the attacker bypassed security measures, coming very close to tracing the source of the attack. The incident investigation by third-party security teams Mandiant and SlowMist is still ongoing, with a detailed report pending from the security team.On-chain tracking confirms that approximately $387.5 million has been transferred to the hacker's address, previously estimated at $351.6 million. This revision includes ZEC and TRX, and no other unauthorized transfers have been found. Xie Jiayin stated that the stolen funds at the platform level will be fully covered by the Bitget User Protection Fund, ensuring that user assets are not subject to any losses.Bitget has officially launched a fund recovery bounty program, offering a 5% bounty for voluntarily freezing the attacker’s funds and a 5% bounty for voluntarily recovering funds. The bounty also applies to assistance already provided. The platform has published the attacker's address, a real-time tracking dashboard, and a submission portal, with relevant information also available for submission through Bybit's Lazarus bounty platform.

first_img Cryptography technology provider Haruko was attacked, affecting 15 clients, with a small amount of funds stolen

According to CoinDesk, the crypto technology provider Haruko was targeted in a cyber attack earlier this week, affecting 15 clients. The attack exposed clients' read-only exchange API details and trading data. According to insiders, some hedge fund clients with weaker security protections may have had a small amount of funds stolen.Adam Carlile, co-founder and Chief Technology Officer of Haruko, stated in an email sent to clients that this was a targeted attack initiated by an organization, and the affected clients were all non-whitelisted clients. The attackers exploited a vulnerability in one of Haruko's processes to extract user access tokens, thereby obtaining data such as read-only exchange API information stored in process memory; clients' login credentials were not compromised. Haruko has fixed the vulnerability and refreshed the server-side keys, and plans to release a complete technical review report.Based in London, Haruko provides portfolio, risk management, and trading data infrastructure for institutional digital asset companies. The platform connects centralized exchanges, custodians, blockchains, and DeFi protocols, currently serving over 80 clients globally and integrating with more than 100 centralized trading platforms, 30 blockchains, and 250 on-chain protocols. Its listed clients include Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, among others, with GSR stating that it was not affected by this incident.
app_icon
ChainCatcher Building the Web3 world with innovations.