This is the first hacker transfer in the official review, purely a test, small amount 0.84 ETH
TX here
https://etherscan.io/tx/0xc19560f5fe5308c9ec8aa5721d7acb9a713cbf6166e2a8e34b6ecd5327c37be6
Unchained records: About 30 minutes after the successful test, the same address successively received:
Approximately $34.75 million USDT
Approximately $12.85 million USDC
3000 XAUT (tokenized gold, approximately $12.8 million)
Arbitrum · Stablecoin transfer out 19,668,851 USDT0 (approximately $19.67 million)
https://arbiscan.io/tx/0xd032320ad8a3cddc61ec0db5e6e26a6dcf813243a77b7edc5a65451ade0b84e3
Then within about 6 minutes, this money was swapped on Arbitrum via UniswapX + 1inch Fusion into approximately 7111 ETH (maximum premium about 5%). This is the transaction that was discovered and made public by community user @dcfgod, indicating that Bitget seems to have a problem.
ETH mainnet transfer out 7,130.86 ETH (approximately $19 million)
https://etherscan.io/tx/0x67a7ac52e0de05aa3e9a3901cbd6315d3317c8ec191e175067d49c709b48930c
03:05:11 ETH Mainnet · Hacker splitting wallets themselves
03:16:23 ETH Mainnet 13,965.93 ETH (approx. $37.5 million)
https://etherscan.io/tx/0x8469803a082c4d106c642874509ffb8b7a730cd52934ccd44af0c479d8f60bfa
04:09 Hacker continues to withdraw ETH from Bitget, approximately 2,400 ETH, plus $8.2 million USDC on the AVAX chain
Xie Jiayin, Head of Bitget Greater China, stated in a post in the early hours that at 2:31 AM Beijing time on September 25, Bitget's security system detected abnormal transfers from some hot wallets, and the security team immediately activated its emergency response mechanism. The platform's preliminary assessment indicates that the incident involves approximately $351.6 million, and the specific cause is still under investigation.
Bitget stated that its cold wallets and the vast majority of platform assets remain intact and were not affected by this incident. User account balances are accurate and assets are protected. The losses from this incident are fully covered by the Bitget User Protection Fund, which currently exceeds $464 million.
Minutes after the incident occurred, Bitget established an emergency response team. The relevant abnormal transfer addresses have been flagged and reported, and law enforcement agencies and on-chain security firms have been notified to intervene in the investigation. For fund security reasons, the platform has temporarily suspended withdrawal functions, which will be restored in an orderly manner after security verification is completed; deposit and trading functions remain operational.
Bitget stated that it will release updates on an hourly basis and plans to publish a complete incident report within 24 hours, including root cause analysis and remediation measures. Before the investigation conclusions are clear, the platform will not speculate on the specific attack method.
Previous on-chain monitoring showed that approximately $180 million to $183 million in assets were transferred out from multiple Bitget-labeled addresses, involving assets such as ETH, BNB, AVAX, USDT0, USDC, USDT, and XAUT. The funds were consolidated into one primary address and then dispersed to at least 6 addresses. Among them, a newly created address used 19.67 million USDT0 from a Bitget hot wallet to purchase 7,111 ETH through UniswapX and 1inch Fusion within approximately 6 minutes, with some trades executed at prices approximately 5% higher than the spot market.
Bitget CEO Gracy Chen stated during a public livestream regarding the platform attack that the platform is currently preparing to resume withdrawals, but there is no exact timeline yet. Bitget's internal and external technical teams are simultaneously identifying the issue and developing solutions, hoping to restore related services as soon as possible.
Gracy Chen stated that the attack method in this incident differs from security incidents previously experienced by some trading platforms. According to the current investigation, the hacker did not carry out the attack through key leakage, but instead bypassed certain systems and initiated withdrawals through the system. She stated that key leakage would be the worst-case scenario, but this incident is not that.
Due to the involvement of multiple cryptocurrencies and blockchain networks in this incident, Bitget is temporarily unable to directly open withdrawals and needs to resume them after confirming that funds are completely safe and developing a more reliable handling plan. Gracy Chen stated that the platform has now completed comprehensive loss containment, and no further attacks will occur; withdrawals will be reopened once the security issue is handled with greater certainty.
Bitget CEO Gracy Chen stated during a livestream regarding the platform attack that the security team is currently focused on identifying the root cause and resolving the issue. Based on information available at this stage, this incident bears some resemblance to a supply chain attack: the attacker may have compromised a third-party tool frequently used by Bitget, thereby affecting an important backend system of the wallet service.
Gracy Chen stated that the compromised service forged transfer information and called the signing machine to transfer out funds. This incident is not a private key leakage; based on the current investigation, the possibility of an insider job is also relatively low. However, she stated that the final attack path still requires further confirmation by the security team.
She added that hacker attacks are usually not of a single type, and a single attack may simultaneously use a combination of two or three out of six to seven categories of methods. She cited the previous Bybit attack as an example, stating that the incident involved both the signature authorization process and a supply chain attack on the Safe multisig page it used. Common attack methods targeting trading platforms also include private key leakage, smart contract vulnerabilities, insider jobs, and social engineering attacks.
Bitget CEO Gracy Chen stated during a livestream regarding the platform attack that some affected funds may have a chance of being recovered. Regarding the resumption of withdrawals, Gracy Chen stated that Bitget needs to first thoroughly investigate the related issues, and the technical team is currently advancing system repairs and security hardening. Only after confirming system security and ensuring that resuming withdrawals will not lead to further attacks by hackers will the platform reopen the withdrawal function.
She stated that once a clear time window for resuming withdrawals is established, users will be informed immediately and an announcement will be made. Currently, no specific timeline can be promised, as the platform does not wish to make commitments it cannot fulfill.
SlowMist MistTrack has updated the Bitget hacker wallet addresses, adding 7 newly flagged Ripple network addresses with a combined balance of approximately 102,926,478 XRP, worth about $157 million.
Additionally, the list includes 11 EVM addresses and 1 TRON address. Among them, the EVM addresses collectively hold approximately 67,980.25 ETH, 5,896.58 BNB, 495.625 WETH, 218,022.9 USDT, and 99,989.9 USDC; the TRON address holds approximately 20,593,376.5 TRX.
Bitget CEO Gracy Chen stated during a live Q&A session on the platform's security incident that preliminary investigations found some related IP addresses matching VPN services used by a North Korean hacker group, and the attack pattern is similar to previous operations by North Korean hackers. Therefore, the involvement of this group in the attack involving approximately $351.6 million cannot be ruled out. However, the attribution remains in the preliminary investigation stage.
Gracy Chen stated that Bitget currently does not believe this incident involved an insider. The attackers directly breached the platform's systems and transferred funds, without forging user withdrawal requests or obtaining the private keys of cold or hot wallets. Investigators are still confirming the specific affected systems and the attackers' method of intrusion.
According to on-chain detective Specter, by tracking on-chain fund flows, the North Korean hacker group Lazarus Group may be the mastermind behind the Bitget theft. This incident is linked to the AFX attack that occurred in July this year, which caused approximately $24 million in losses and was attributed to TraderTraitor, associated with Lazarus Group.
The stolen XRP from Bitget, after being cross-chained, can be directly linked to the stolen funds from the AFX attack through the relevant fund paths.
Welcome to join the official BlockBeats community:
Telegram Subscription Group: https://t.me/theblockbeats
Telegram Discussion Group: https://t.me/BlockBeats_App
Official Twitter Account: https://twitter.com/BlockBeatsAsia