On September 24, cryptocurrency exchange Bitget faced a significant security breach, resulting in the loss of approximately $387.5 million. The attackers exploited Bitget’s backend wallet infrastructure, primarily targeting hot and warm wallets, while the cold wallets and standalone Bitget Wallet service remained secure. This incident highlights vulnerabilities in transaction preparation and authorization systems, even when private keys are not compromised.
Attack Details and Initial Response
The breach was identified at 18:31 UTC when unauthorized transactions were detected. Bitget quickly enacted emergency protocols, halting withdrawals. According to CEO Gracy Chen, the attackers manipulated a crucial backend component, spoofing transaction details to trigger fraudulent approvals. Initially, losses were estimated at $351.6 million but were later amended to reflect additional asset movements, including Zcash and TRON.
The stolen cryptocurrencies spanned multiple assets, with XRP being the most affected. An estimated 102.93 million XRP, valued at around $157.5 million, and 31,890 ETH, worth about $85.75 million, were among the stolen assets. The complexity of tracing these assets increased as they were converted and distributed across networks.
Investigation and Unintended Revelations
Blockchain investigator ZachXBT uncovered significant operational security lapses among individuals allegedly laundering the stolen funds for suspected North Korean hackers. These actors, identified using aliases like “jack” and “HELP ME,” sought technical support in public forums when their transactions stalled, inadvertently exposing their activities.
Further investigations revealed connections between these actors and intermediary wallets linked to the Bitget theft. Notably, one alias, “lolo/Marin,” was associated with laundering funds from a previous $292 million Kelp DAO exploit. Transaction maps demonstrated the flow of proceeds through various cryptocurrency platforms, complicating recovery efforts.
Ongoing Efforts and Future Outlook
Bitget has attributed the breach to a DPRK-linked group, based on observed IP and on-chain signatures, although no official confirmation has been made by external authorities. The investigation is ongoing, with cybersecurity firms Mandiant and SlowMist providing support. Law enforcement has been notified, and efforts to trace and freeze the stolen assets continue.
As part of their recovery plan, Bitget has started reinstating withdrawals in a phased manner, beginning with Bitcoin and followed by Ethereum, USDT, and other currencies. The exchange has addressed the vulnerability exploited in the breach and assures that no further unauthorized transactions can occur. Despite the breach, customer balances remain unaffected due to Bitget’s protection fund.
As the situation develops, Bitget’s response and the broader implications for cybersecurity in the cryptocurrency sector remain under close scrutiny. The incident underscores the importance of robust security measures and the challenges of safeguarding digital assets against increasingly sophisticated cyber threats.
