The Evolving Bitget Hack: Losses Revised Upwards to $388 Million

The financial impact of the security breach targeting cryptocurrency exchange Bitget has been reassessed, with estimated losses rising from an initial $351.6 million to approximately $387.5 million. This revision includes transfers identified on the Zcash and TRON blockchains. The illicit withdrawals were executed on Thursday.

Inside the Attack: "Tricking" the System into Compliance

Bitget CEO Gracy Chen provided technical insight into the exploit. Rather than stealing private keys, the attackers employed a more sophisticated method.

  • Backend Compromise: Hackers first infiltrated critical backend systems within Bitget's wallet infrastructure.
  • Data Forgery and Process Trigger: They fabricated transaction data internally and successfully triggered the platform's own authorization process.
  • Self-Signed Transactions: Crucially, the withdrawal instructions were ultimately signed and approved by Bitget's own systems, making the transactions appear legitimate.

Chen noted that this method of "tricking the system into authorizing itself" aligns with patterns associated with North Korea-linked hacker groups and resembles the path used in a previous $1.5 billion exploit against Bybit.

Tracking the Funds and Recovery Efforts

Blockchain analytics from Nansen show the stolen 40,000 ETH was split evenly into four newly created addresses. As of Friday evening ET, eight addresses linked to the attack collectively hold about 68,300 ETH (roughly $184 million), which has not been moved further.

Bitget has initiated several countermeasures:

  • A portion of the stolen assets has been frozen.
  • The exchange announced a 5% bounty on any funds recovered through external assistance.
  • Bitget stated its user protection fund, valued at over $464 million, will fully cover user losses from the incident.

Response and Next Steps

The technical team at Bitget confirmed the specific vulnerability has been identified and patched. An update on the status of withdrawals, which were paused Thursday, is expected before midnight ET. Security firms Mandiant and SlowMist are assisting with the ongoing investigation.