
Bitget discloses cause of $388M hack: zero-day in third-party security software
- —The attack began at 02:31 UTC+8 on Sept 25 with test transfers of 0.84 ETH and 93 TRX below risk thresholds
- —Attackers then made 17 large transfers worth about $360 million across Ethereum, XRP, ZEC, BSC, Base, Arbitrum, Optimism and Avalanche
- —Private keys and cold wallets were not compromised and user balances remain unaffected
- —Bitget offers a 5% bounty for freezing or recovering funds; Mandiant and SlowMist are investigating
Why it matters: The case shows that a third-party software compromise, without key leakage, can bypass exchange risk controls; the market awaits the Mandiant and SlowMist report.
Source: ChainCatcher 链捕手
More on this
Security · yesterdayBitget says hack was its first security breach in 8 years, traced to third-party software
DeFi · Sep 17Vitalik Buterin: AI will make it possible to prove software security in full
Security · Sep 18Vitalik Buterin: AI hacking threat overstated, formal verification will strengthen security