Loading prices…
🩸BEARISH

Bitget’s 30-Minute Warning Fails to Stop $290M in Transfers

The breach shifts scrutiny from initial access to incident response: Bitget’s own systems flagged unauthorized transfers before the largest losses began.

Bitget detected unauthorized wallet transfers at 18:31 UTC on Sept. 24, about 30 minutes before attackers began moving hundreds of millions of dollars. Hypernative’s reconstruction found that $87.6 million left hot wallets at 19:01, followed by $202.8 million from warm wallets at 19:16. The two bursts took just 24 seconds and accounted for roughly three-quarters of the $387.5 million Bitget said was moved to attacker-controlled addresses.

Why it matters

The timing puts the exchange’s response under scrutiny. Bitget said its security team activated emergency protocols after the alert, but attacker-linked transfers continued until 21:23 UTC, almost three hours after the stated detection time. The key question is why the compromised signing route remained operational after the first warning.

Bitget said an attacker compromised a backend system in its wallet infrastructure, spoofed withdrawal data and tricked its authorization process into approving transfers. The company said private keys were not compromised. Hypernative said the transactions were signed by Bitget’s own wallets and closely resembled ordinary customer withdrawals.

Market impact

The attack began with small test transfers of 0.84 ETH and 93 TRX at 18:31. After about 28 minutes, the attacker moved $34.75 million in USDT, then accelerated the drain across multiple blockchains. Hypernative identified possible safeguards including independently matching signed transfers to approved withdrawals, flagging unusual transaction parameters, setting wallet-tier velocity limits and automatically suspending anomalous signers.

Bitget said it remediated the vulnerability and that no further unauthorized transfers occurred after containment. Mandiant and SlowMist remain involved in the forensic investigation. For exchange operators and customers, the incident highlights the importance of controls that can halt signing automatically when internal systems detect suspicious activity.

Related tokens
$ETH $TRX $USDT

Frequently asked questions

  1. How much moved in Bitget’s two largest transfer bursts?

    Hypernative’s reconstruction found $87.6 million left hot wallets and $202.8 million left warm wallets. The two bursts took 24 seconds.

  2. How long after Bitget’s alert did the first major wave begin?

    Bitget said it detected unauthorized transfers at 18:31 UTC. The first major wave, $87.6 million from hot wallets, began at 19:01.

  3. What did Bitget say the attacker compromised?

    Bitget said the attacker compromised a backend system in its wallet infrastructure, spoofed withdrawal data and tricked its authorization process into approving transfers.

  4. Were Bitget’s private keys compromised?

    Bitget said its private keys were not compromised. It attributed the breach to a compromised backend system and spoofed withdrawal data.

  5. What safeguards did Hypernative identify as potential defenses?

    Hypernative identified independent checks against approved withdrawals, transaction-parameter monitoring, wallet transfer limits, secondary approvals and automatic suspension of anomalous signers.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 44m ago
Open original →