Bitget Hackers Exploited Vulnerabilities for $388M Heist
- The first malicious activity in Bitget-linked systems was traced back to Aug. 31, indicating intruders were present for at least 25 days before the theft.
- Attackers used an internal employee identity and a custom withdrawal tool to move funds over a period of nearly three hours.
- Suspected North Korean scripts were detected on Sept. 30, routing stolen funds via CoW Protocol and Chainflip.
- The heaviest transfer occurred within the first hour, with $228 million moved across seven chains in just eighteen minutes.
- Bitget’s User Protection Fund, valued at over $464 million, is set to cover the losses incurred from this breach.
The attack on Bitget began with exploiting a zero-day vulnerability in a third-party security product on Aug.31, allowing hackers prolonged access to systems before executing the heist on Sept.24 using forged credentials and withdrawal requests.
This incident highlights vulnerabilities in exchange security protocols and emphasizes the need for robust measures against sophisticated hacking techniques such as those employed by suspected North Korean groups.Source