[Bitget discloses that the hacker forged authorizations after invading the wallet backend; the method appears to follow the Lazarus route]
Bitget CEO Gracy revealed in a live stream that this security incident was not caused by forged withdrawal requests on the user side, nor by any internal employee assistance. Instead, the attacker gained access to the crucial backend infrastructure of the wallet, forged transaction data, and triggered the internal authorization process to transfer assets out. Analysts believe this modus operandi closely matches the attack paths used by the North Korean hacking group Lazarus against exchanges in recent years: it does not directly steal private keys, but rather controls the signing environment or approval workflow to make the system execute tampered transaction instructions. Bitget also emphasized that, while the full method of how the attackers gained access and the technical report have not yet been released, low-probability scenarios involving an insider operation have already been ruled out.
The core impact of this incident lies in highlighting the importance of consistency between the “authorization layer” and the “execution layer” in exchange security. When attackers cannot obtain cold-wallet private keys, they may instead compromise backend logic or the supply chain (such as a third-party multi-signature service provider involved in the Bybit case). By getting the system to “willingly” execute incorrect instructions, this type of attack is more stealthy and destructive. For the market, incidents like this typically raise short-term concerns about the custody security of centralized exchanges (CEXs). This can lead some funds to move toward decentralized exchanges (DEXs) or self-custody wallets, which in turn may affect the on-chain distribution of major assets such as BTC and ETH.
Going forward, it is important to closely watch for the release of Bitget’s official complete technical report to confirm the specific intrusion entry point (internal network or supply chain) and the exact scale and composition of the stolen assets. At the same time, monitor on-chain tracking data related to Lazarus to see whether new large-scale money-laundering routes have emerged. This will be a key signal in determining whether this incident is part of a larger-scale attack network.
$BTC $ETH
Bitget CEO Gracy revealed in a live stream that this security incident was not caused by forged withdrawal requests on the user side, nor by any internal employee assistance. Instead, the attacker gained access to the crucial backend infrastructure of the wallet, forged transaction data, and triggered the internal authorization process to transfer assets out. Analysts believe this modus operandi closely matches the attack paths used by the North Korean hacking group Lazarus against exchanges in recent years: it does not directly steal private keys, but rather controls the signing environment or approval workflow to make the system execute tampered transaction instructions. Bitget also emphasized that, while the full method of how the attackers gained access and the technical report have not yet been released, low-probability scenarios involving an insider operation have already been ruled out.
The core impact of this incident lies in highlighting the importance of consistency between the “authorization layer” and the “execution layer” in exchange security. When attackers cannot obtain cold-wallet private keys, they may instead compromise backend logic or the supply chain (such as a third-party multi-signature service provider involved in the Bybit case). By getting the system to “willingly” execute incorrect instructions, this type of attack is more stealthy and destructive. For the market, incidents like this typically raise short-term concerns about the custody security of centralized exchanges (CEXs). This can lead some funds to move toward decentralized exchanges (DEXs) or self-custody wallets, which in turn may affect the on-chain distribution of major assets such as BTC and ETH.
Going forward, it is important to closely watch for the release of Bitget’s official complete technical report to confirm the specific intrusion entry point (internal network or supply chain) and the exact scale and composition of the stolen assets. At the same time, monitor on-chain tracking data related to Lazarus to see whether new large-scale money-laundering routes have emerged. This will be a key signal in determining whether this incident is part of a larger-scale attack network.
$BTC $ETH