Prefer Koin Bülteni on Google Add as source

Inside Bitget’s $388 Million Attack: Two Small Transfers Evaded Alarms

Bitget CEO Gracy Chen said two small transfers made before the $388 million attack did not trigger security alerts, and that the attacker used compromised executive access to make the system accept fraudulent withdrawal commands.

In an interview with The Block, Chen described how the September 24 attack began and when the exchange intervened. The initial attempts did not generate system alerts because they fell below the risk controls’ threshold. Larger transfers then began across eight blockchain networks.

Large transfers began half an hour after the small test transactions

According to the timeline shared by the CEO, at 21:31 on September 24 (Turkey time), the attacker sent 0.184 ETH from an Ethereum hot wallet and 193 TRX from a Tron hot wallet. About half an hour after these two small transactions, much larger amounts began leaving the exchange.

Between 21:58 and 23:09 (Turkey time), approximately $361 million was moved in 17 transactions through Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism, and Avalanche. These transactions accounted for most of the $388 million attack.

Bitget’s reconciliation system, which compares records with balances, detected a significant discrepancy seven minutes after the first large transfer, at 22:05 (Turkey time). The platform then blocked user-initiated withdrawals across the board. The attacker had already gained access to the internal management system.

Fraudulent withdrawal commands were accepted as valid transactions

According to Chen, the attacker exploited a previously unknown vulnerability in a third-party security product to obtain valid administrator login credentials. With this access, the attacker was able to insert fraudulent withdrawal commands directly into the wallet infrastructure, and the system accepted them as legitimate transactions.

The attacker’s deletion of traces left by the commands also made it harder to investigate the incident. Bitget is conducting its investigation with Mandiant and SlowMist and expects to publish its official incident report this week. Chen said the suspicions point to the same group but did not name it before the report is released.

The exchange said that private keys and cold wallets were not compromised.

Loss to be covered by protection fund

Chen said that, as of September 25, the $465 million user protection fund would cover the loss. The plan is to replenish the fund to at least $300 million within a week after the payout, using a transfer from the company’s reserves. In an audit dated August 31, the company’s reserves stood at more than $1.4 billion.

Bitcoin withdrawals reopened on Monday, September 28, and more than 3,000 BTC in withdrawals were processed in the first hour. Ethereum withdrawals are scheduled to reopen on September 29.

Tüm gelişmelerden ve paylaşımlardan haberdar olmak için Telegram kanalımıza katılın!