Security· ★★★★★· bearish·

Bitget discloses cause of $388M hack: zero-day in third-party security software

  • —The attack began at 02:31 UTC+8 on Sept 25 with test transfers of 0.84 ETH and 93 TRX below risk thresholds
  • —Attackers then made 17 large transfers worth about $360 million across Ethereum, XRP, ZEC, BSC, Base, Arbitrum, Optimism and Avalanche
  • —Private keys and cold wallets were not compromised and user balances remain unaffected
  • —Bitget offers a 5% bounty for freezing or recovering funds; Mandiant and SlowMist are investigating
Why it matters: The case shows that a third-party software compromise, without key leakage, can bypass exchange risk controls; the market awaits the Mandiant and SlowMist report.
Source: ChainCatcher 链捕手