Binance Square
#bitgethotwalletbreachtiedtothirdpartysecurityflaw

bitgethotwalletbreachtiedtothirdpartysecurityflaw

CryptoMahibaloch
·
--
⚠️ Bitget Wallet Incident Explained Unauthorized transfers affected portions of Bitget’s hot and warm wallet infrastructure. Bitget says its cold wallets and private keys were not compromised, while the affected vulnerability has been remediated. $BTC $XRP $ETH #bitgethotwalletbreachtiedtothirdpartysecurityflaw
⚠️ Bitget Wallet Incident Explained
Unauthorized transfers affected portions of Bitget’s hot and warm wallet infrastructure.
Bitget says its cold wallets and private keys were not compromised, while the affected vulnerability has been remediated.
$BTC $XRP $ETH

#bitgethotwalletbreachtiedtothirdpartysecurityflaw
206 Atlas:
Hot wallet breaches are standard operational risks, not fundamental thesis breakers. Price action likely priced this in before the announcement.
·
--
Baissier
#bitgethotwalletbreachtiedtothirdpartysecurityflaw 🚨 Bitget Security Update: $388M Hot Wallet Breach Linked to Third-Party Flaw A major crypto exchange confirmed a security incident, but with a crucial detail: user cold storage remains unaffected. Here is the factual breakdown. 🔹 Incident On Sept 24, 2026, Bitget confirmed a breach of ~$388M from specific operational hot/warm wallets. 🔹 Root Cause**: The exploit did NOT involve compromised private keys. Attackers leveraged a vulnerability in a third-party security product to steal high-level internal credentials. 🔹 Mechanism These credentials allowed forged withdrawal commands, bypassing risk verification to execute on-chain transfers with valid signatures. 🔹 Status Bitget confirms cold wallets are safe. Normal operations have resumed following enhanced security protocols. 📊 Market Impact • Vendor Risk Highlights a critical systemic risk in crypto: third-party software dependencies. Underscores the need for rigorous vendor audits industry-wide. • Market Resilience Confirming cold storage is intact helps contain broader market contagion, despite potential short-term outflows. • Industry Evolution Expect a renewed push for multi-signature operational frameworks and stricter compliance for centralized platforms. 💬 Join the Discussion How should the crypto industry better audit third-party security vendors to prevent indirect breaches? Share your thoughts below! 👇 #CryptoSecurity #Web3Safety #CryptoNews #RiskManagement #Bitget This is for educational purposes only. Not Financial Advice (NFA). Always Do Your Own Research (DYOR). $MARSCOIN $HBAR $ZAMA {future}(ZAMAUSDT) {future}(HBARUSDT) {future}(MARSCOINUSDT)
#bitgethotwalletbreachtiedtothirdpartysecurityflaw 🚨 Bitget Security Update: $388M Hot Wallet Breach Linked to Third-Party Flaw

A major crypto exchange confirmed a security incident, but with a crucial detail: user cold storage remains unaffected. Here is the factual breakdown.

🔹 Incident On Sept 24, 2026, Bitget confirmed a breach of ~$388M from specific operational hot/warm wallets.
🔹 Root Cause**: The exploit did NOT involve compromised private keys. Attackers leveraged a vulnerability in a third-party security product to steal high-level internal credentials.
🔹 Mechanism These credentials allowed forged withdrawal commands, bypassing risk verification to execute on-chain transfers with valid signatures.
🔹 Status Bitget confirms cold wallets are safe. Normal operations have resumed following enhanced security protocols.

📊 Market Impact
• Vendor Risk Highlights a critical systemic risk in crypto: third-party software dependencies. Underscores the need for rigorous vendor audits industry-wide.
• Market Resilience Confirming cold storage is intact helps contain broader market contagion, despite potential short-term outflows.
• Industry Evolution Expect a renewed push for multi-signature operational frameworks and stricter compliance for centralized platforms.

💬 Join the Discussion
How should the crypto industry better audit third-party security vendors to prevent indirect breaches? Share your thoughts below! 👇

#CryptoSecurity #Web3Safety #CryptoNews #RiskManagement #Bitget
This is for educational purposes only. Not Financial Advice (NFA). Always Do Your Own Research (DYOR).
$MARSCOIN $HBAR $ZAMA
·
--
Haussier
#bitgethotwalletbreachtiedtothirdpartysecurityflaw Oh no, Bitget's hot wallet got hit for $388M because a third-party security provider fell asleep on the job! 😱 Will the third party pay it back? The CEO is "not very optimistic," comparing it to past hacks where only 3.5% was frozen. This is a massive wake-up call: even security companies get hacked! 🤦‍♂️ What should traders do? 1️⃣ Move your heavy bags to cold storage immediately. 2️⃣ Diversify across top ecosystems to lower risk. Not financial advice! DYOR! Click trade below to support me!👇 $BNB {future}(BNBUSDT) $NEAR {future}(NEARUSDT) $BTC {future}(BTCUSDT) Use code VINHTOCDO or link: [https://www.binance.com/register?ref=VINHTOCDO](https://www.binance.com/register?ref=VINHTOCDO) #Bitget #CryptoSecurity #Web3 #RiskManagement #VINHTOCDO
#bitgethotwalletbreachtiedtothirdpartysecurityflaw
Oh no, Bitget's hot wallet got hit for $388M because a third-party security provider fell asleep on the job! 😱 Will the third party pay it back? The CEO is "not very optimistic," comparing it to past hacks where only 3.5% was frozen. This is a massive wake-up call: even security companies get hacked! 🤦‍♂️
What should traders do?
1️⃣ Move your heavy bags to cold storage immediately.
2️⃣ Diversify across top ecosystems to lower risk.
Not financial advice! DYOR!
Click trade below to support me!👇
$BNB
$NEAR
$BTC
Use code VINHTOCDO or link: https://www.binance.com/register?ref=VINHTOCDO
#Bitget #CryptoSecurity #Web3 #RiskManagement #VINHTOCDO
Two small test transfers first. Then the big drain. That’s how the Bitget hack started Hot and warm wallets. About $388M. Cold wallets untouched. Customer balances supposedly covered If you still keep size on a CEX, this is why people keep repeating the same warning. Third-party tools sit inside the vault #BitgetHotWalletBreachTiedToThirdPartySecurityFlaw
Two small test transfers first. Then the big drain. That’s how the Bitget hack started

Hot and warm wallets. About $388M. Cold wallets untouched. Customer balances supposedly covered

If you still keep size on a CEX, this is why people keep repeating the same warning. Third-party tools sit inside the vault

#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw
Bitget now says the $388M hack came through a third-party security product Not stolen private keys. Not cold wallets. A vendor flaw that let someone grab internal credentials and send fake withdrawal commands That’s the part people should sit with. Your exchange can be “secure” and still get wrecked by software it bought $BTC withdrawals already restarted. The lesson doesn’t restart with them #BitgetHotWalletBreachTiedToThirdPartySecurityFlaw {future}(BTCUSDT)
Bitget now says the $388M hack came through a third-party security product

Not stolen private keys. Not cold wallets. A vendor flaw that let someone grab internal credentials and send fake withdrawal commands

That’s the part people should sit with. Your exchange can be “secure” and still get wrecked by software it bought

$BTC withdrawals already restarted. The lesson doesn’t restart with them

#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw
Bitget CEO Gracy Chen stated she is "not very optimistic" about fully recovering or freezing the $388 million stolen in the recent security breach, citing historical recovery rates from major exploits like Bybit's 2025 hack. 📊 Incident Breakdown • Total Lost: Revised to approximately $388 million. • Root Cause: A third-party security product vulnerability granting high-level internal credentials. • User Safety: Bitget's $464 million Protection Fund is designated to cover user losses. • Withdrawals: Phased resumption began with Bitcoin on Monday. ⚠️ Recovery Outlook & Challenges • Low Benchmarks: Only ~3.5% of funds were frozen a year after the Bybit hack. • Cross-Chain Hurdles: Decentralized protocols like THORChain declined requests to selectively blacklist attacker addresses. • Mitigation Efforts: • NEAR Intents blocked $50M+ and froze ~$500k. • Tether and Circle blacklisted specific linked wallets. • Bitget launched a bounty program offering 5% for frozen and 5% for recovered funds.#TrumpRejectsAIRulesForVoluntaryAudits #QNTRises287% #BitgetHotWalletBreachTiedToThirdPartySecurityFlaw
Bitget CEO Gracy Chen stated she is "not very optimistic" about fully recovering or freezing the $388 million stolen in the recent security breach, citing historical recovery rates from major exploits like Bybit's 2025 hack.
📊 Incident Breakdown
• Total Lost: Revised to approximately $388 million.
• Root Cause: A third-party security product vulnerability granting high-level internal credentials.
• User Safety: Bitget's $464 million Protection Fund is designated to cover user losses.
• Withdrawals: Phased resumption began with Bitcoin on Monday.
⚠️ Recovery Outlook & Challenges
• Low Benchmarks: Only ~3.5% of funds were frozen a year after the Bybit hack.
• Cross-Chain Hurdles: Decentralized protocols like THORChain declined requests to selectively blacklist attacker addresses.
• Mitigation Efforts:
• NEAR Intents blocked $50M+ and froze ~$500k.
• Tether and Circle blacklisted specific linked wallets.
• Bitget launched a bounty program offering 5% for frozen and 5% for recovered funds.#TrumpRejectsAIRulesForVoluntaryAudits #QNTRises287% #BitgetHotWalletBreachTiedToThirdPartySecurityFlaw
Bitget Hack: The Weak Link Wasn't the Wallet, It Was a "Trusted" Security Tool 🔐 Another major crypto security incident has hit the headlines, and this one carries an important lesson. On September 24, Bitget detected unauthorized transfers from its hot and warm wallets. The estimated loss has since been revised to around $387.5 million. What actually happened? According to Bitget, the attacker exploited a flaw in a third-party security product to obtain high-level internal credentials. Those credentials were then used to send fraudulent withdrawal commands to the wallet system, bypassing risk controls. The key point: private keys were not compromised and cold wallets were unaffected. The attacker didn't break the vault, they got hold of a key through the security guard. 😅 What about user funds? The full loss is reported to be covered by Bitget's $464 million User Protection Fund. Bitget has also launched a recovery bounty program and is working with law enforcement, and withdrawals are being restored in stages. 3 lessons for all of us: 1️⃣ An exchange is only as secure as its weakest link. Vendors and third-party tools are real risks too. 2️⃣ Understand hot vs. cold wallets. Cold storage is exactly why the damage was limited here. 3️⃣ Don't keep everything on one exchange. Long-term holdings are safer in your own wallet. Bitget says it will review how it evaluates and deploys third-party security tools. The real question now is how seriously other exchanges will audit their own vendors. What do you think? Do you still keep funds on exchanges, or are you moving toward self-custody? Tell me in the comments 👇#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw
Bitget Hack: The Weak Link Wasn't the Wallet, It Was a "Trusted" Security Tool 🔐
Another major crypto security incident has hit the headlines, and this one carries an important lesson.
On September 24, Bitget detected unauthorized transfers from its hot and warm wallets. The estimated loss has since been revised to around $387.5 million.
What actually happened?
According to Bitget, the attacker exploited a flaw in a third-party security product to obtain high-level internal credentials. Those credentials were then used to send fraudulent withdrawal commands to the wallet system, bypassing risk controls.
The key point: private keys were not compromised and cold wallets were unaffected. The attacker didn't break the vault, they got hold of a key through the security guard. 😅
What about user funds?
The full loss is reported to be covered by Bitget's $464 million User Protection Fund. Bitget has also launched a recovery bounty program and is working with law enforcement, and withdrawals are being restored in stages.
3 lessons for all of us:
1️⃣ An exchange is only as secure as its weakest link. Vendors and third-party tools are real risks too.
2️⃣ Understand hot vs. cold wallets. Cold storage is exactly why the damage was limited here.
3️⃣ Don't keep everything on one exchange. Long-term holdings are safer in your own wallet.
Bitget says it will review how it evaluates and deploys third-party security tools. The real question now is how seriously other exchanges will audit their own vendors.
What do you think? Do you still keep funds on exchanges, or are you moving toward self-custody? Tell me in the comments 👇#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw
🚨 BREAKING: BITGET HOT WALLET BREACH - $388M HACK! Largest hack of 2026? Bitget confirms hot wallet breach tied to THIRD-PARTY security flaw! 🔴 What happened? - $388,000,000 Stolen from Hot & Warm wallets (Sept 24) - Attacker exploited zero-day vulnerability in third-party security product - Forged withdrawal instructions - bypassed risk controls - Private keys SAFE, Cold wallets UNAFFECTED ✅ ✅ Bitget Recovery Update: - BTC withdrawals resumed Sept 28 - ETH withdrawals Sept 29 - Full recovery by Oct 2 - Protection Fund $464M will cover all losses - 5% bounty for recovery This is why CEX supply chain security matters! Always use cold wallet for long term. Are your funds SAFU? Comment below 👇 #BitgetHotWalletBreachTiedToThirdPartySecurityFlaw #Bitget #Hack #CryptoSecurity #BinanceSquare ⚠️ DISCLAIMER: This content is for educational & news purposes only. Not financial advice. Stay safe, DYOR. $BTC $ETH $BNB {spot}(BNBUSDT) {spot}(ETHUSDT) {spot}(BTCUSDT)
🚨 BREAKING: BITGET HOT WALLET BREACH - $388M HACK!

Largest hack of 2026? Bitget confirms hot wallet breach tied to THIRD-PARTY security flaw!

🔴 What happened?
- $388,000,000 Stolen from Hot & Warm wallets (Sept 24)
- Attacker exploited zero-day vulnerability in third-party security product
- Forged withdrawal instructions - bypassed risk controls
- Private keys SAFE, Cold wallets UNAFFECTED ✅

✅ Bitget Recovery Update:
- BTC withdrawals resumed Sept 28
- ETH withdrawals Sept 29
- Full recovery by Oct 2
- Protection Fund $464M will cover all losses
- 5% bounty for recovery

This is why CEX supply chain security matters! Always use cold wallet for long term.

Are your funds SAFU? Comment below 👇

#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw #Bitget #Hack #CryptoSecurity #BinanceSquare

⚠️ DISCLAIMER: This content is for educational & news purposes only. Not financial advice. Stay safe, DYOR.
$BTC $ETH $BNB

#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw 🚨 $387.5M IN CRYPTO WAS TRANSFERRED TO ATTACKER-CONTROLLED ADDRESSES — AND THE ENTRY POINT WAS A THIRD-PARTY SECURITY FLAW. Bitget says the attacker exploited a vulnerability in a third-party security product, obtained high-level internal credentials and used them to issue fraudulent withdrawal commands. Bitget says its cold wallets and private keys were not compromised, while its Protection Fund is designated to cover the financial impact. Crypto security isn’t just about protecting private keys. Third-party software and internal access can become major attack surfaces too. This incident reinforces why exchange security must cover the entire infrastructure, not just wallets. Short-term fear may increase, but stronger audits, access controls and monitoring could improve industry resilience. Traders should focus on verified updates rather than rumors during active investigations. #Bitget #crypto #Binanace #TrumpRejectsAIRulesForVoluntaryAudits
#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw 🚨 $387.5M IN CRYPTO WAS TRANSFERRED TO ATTACKER-CONTROLLED ADDRESSES — AND THE ENTRY POINT WAS A THIRD-PARTY SECURITY FLAW.
Bitget says the attacker exploited a vulnerability in a third-party security product, obtained high-level internal credentials and used them to issue fraudulent withdrawal commands.
Bitget says its cold wallets and private keys were not compromised, while its Protection Fund is designated to cover the financial impact.

Crypto security isn’t just about protecting private keys. Third-party software and internal access can become major attack surfaces too.

This incident reinforces why exchange security must cover the entire infrastructure, not just wallets. Short-term fear may increase, but stronger audits, access controls and monitoring could improve industry resilience. Traders should focus on verified updates rather than rumors during active investigations.
#Bitget #crypto #Binanace #TrumpRejectsAIRulesForVoluntaryAudits
·
--
Haussier
#bitgethotwalletbreachtiedtothirdpartysecurityflaw 🔍 Market Insight Bitget Breach Linked to Third-Party Security Flaw A recent security incident highlights the critical, often overlooked risks of third-party vendor management in the digital asset ecosystem. 📌 Core News • Incident: Bitget confirmed unauthorized transfers from hot and warm wallets, with on-chain estimates ranging from $351.6M to $387.5M. • Cause: Attackers exploited a vulnerability in a third-party security product within Bitget’s backend to obtain operational credentials and spoof transaction data. Private keys were not compromised. • Response: The exchange paused withdrawals, launched a full investigation, and began phased service resumption. Cold wallets remain fully secure and user funds are protected. 📊 Market Impact • Vendor Scrutiny This underscores the systemic risks of external software dependencies, prompting exchanges to accelerate audits of third-party integrations. • On-Chain Compliance: The swift freezing of stolen funds by major stablecoin issuers demonstrates the growing maturity of real-time monitoring protocols. • Resilience: Historically, isolated exchange breaches have limited market contagion if the platform acts transparently and covers user losses. 💬 Discussion How can centralized exchanges better vet and monitor third-party security integrations to prevent future vulnerabilities? Share your insights below! 👇 #CryptoSecurity #Bitget #MarketUpdate #Web3 #CryptoNews This is for educational purposes only. Not Financial Advice (NFA). Always Do Your Own Research (DYOR). $KSM $STG $ZRO {future}(ZROUSDT) {spot}(STGUSDT) {future}(KSMUSDT)
#bitgethotwalletbreachtiedtothirdpartysecurityflaw 🔍 Market Insight Bitget Breach Linked to Third-Party Security Flaw

A recent security incident highlights the critical, often overlooked risks of third-party vendor management in the digital asset ecosystem.

📌 Core News
• Incident: Bitget confirmed unauthorized transfers from hot and warm wallets, with on-chain estimates ranging from $351.6M to $387.5M.
• Cause: Attackers exploited a vulnerability in a third-party security product within Bitget’s backend to obtain operational credentials and spoof transaction data. Private keys were not compromised.
• Response: The exchange paused withdrawals, launched a full investigation, and began phased service resumption. Cold wallets remain fully secure and user funds are protected.

📊 Market Impact
• Vendor Scrutiny This underscores the systemic risks of external software dependencies, prompting exchanges to accelerate audits of third-party integrations.
• On-Chain Compliance: The swift freezing of stolen funds by major stablecoin issuers demonstrates the growing maturity of real-time monitoring protocols.
• Resilience: Historically, isolated exchange breaches have limited market contagion if the platform acts transparently and covers user losses.

💬 Discussion
How can centralized exchanges better vet and monitor third-party security integrations to prevent future vulnerabilities? Share your insights below! 👇

#CryptoSecurity #Bitget #MarketUpdate #Web3 #CryptoNews

This is for educational purposes only. Not Financial Advice (NFA). Always Do Your Own Research (DYOR).
$KSM $STG $ZRO
🔐 Third-Party Security Risk Comes Into Focus The Bitget investigation points to a vulnerability in an external security product as part of the attack path. The incident shows why exchange security depends not only on internal systems, but also on connected third-party infrastructure. $BTC $ETH $BNB #bitgethotwalletbreachtiedtothirdpartysecurityflaw
🔐 Third-Party Security Risk Comes Into Focus
The Bitget investigation points to a vulnerability in an external security product as part of the attack path.
The incident shows why exchange security depends not only on internal systems, but also on connected third-party infrastructure.
$BTC $ETH $BNB

#bitgethotwalletbreachtiedtothirdpartysecurityflaw
🚨 Bitget Security Incident Bitget says attackers exploited a vulnerability in a third-party security product to obtain internal credentials and send fraudulent withdrawal commands. The affected hot and warm wallets involved an estimated $387.5M in assets. $BTC $ETH $LINK #bitgethotwalletbreachtiedtothirdpartysecurityflaw
🚨 Bitget Security Incident
Bitget says attackers exploited a vulnerability in a third-party security product to obtain internal credentials and send fraudulent withdrawal commands.
The affected hot and warm wallets involved an estimated $387.5M in assets.
$BTC $ETH $LINK

#bitgethotwalletbreachtiedtothirdpartysecurityflaw
Bitget has announced a hot wallet breach, attributing the incident to a security flaw originating from a third-party service. This event highlights the critical importance of robust security measures not only within exchanges but also across their entire supply chain of service providers. The crypto market is highly sensitive to security incidents, and a breach, even if contained and linked to an external factor, can erode user confidence and trigger sell-offs. While Bitget's prompt communication is a positive step, the market will be closely watching their recovery process and any potential impact on trading volumes and asset prices. This incident underscores the ongoing challenge of securing digital assets in an interconnected ecosystem where a single weak link can have significant repercussions. This situation serves as a stark reminder for all crypto participants to remain vigilant about the security practices of the platforms they use. #BitgetHotWalletBreachTiedToThirdPartySecurityFlaw
Bitget has announced a hot wallet breach, attributing the incident to a security flaw originating from a third-party service. This event highlights the critical importance of robust security measures not only within exchanges but also across their entire supply chain of service providers.

The crypto market is highly sensitive to security incidents, and a breach, even if contained and linked to an external factor, can erode user confidence and trigger sell-offs. While Bitget's prompt communication is a positive step, the market will be closely watching their recovery process and any potential impact on trading volumes and asset prices. This incident underscores the ongoing challenge of securing digital assets in an interconnected ecosystem where a single weak link can have significant repercussions.

This situation serves as a stark reminder for all crypto participants to remain vigilant about the security practices of the platforms they use.

#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw
🛡️ Exchange Security Under the Microscope The Bitget incident involved fraudulent withdrawal commands after attackers allegedly gained access through a third-party security flaw. The investigation continues with cybersecurity firms including Mandiant and SlowMist. $LINK $BTC $BNB #bitgethotwalletbreachtiedtothirdpartysecurityflaw
🛡️ Exchange Security Under the Microscope
The Bitget incident involved fraudulent withdrawal commands after attackers allegedly gained access through a third-party security flaw.
The investigation continues with cybersecurity firms including Mandiant and SlowMist.
$LINK $BTC $BNB

#bitgethotwalletbreachtiedtothirdpartysecurityflaw
🌐 A Reminder for Crypto Infrastructure Bitget’s September 24 breach affected certain hot and warm wallets, with the latest estimate at about $388M. The incident highlights how third-party software, internal access and withdrawal controls can all become critical security layers. $BTC $ETH $SOL #bitgethotwalletbreachtiedtothirdpartysecurityflaw
🌐 A Reminder for Crypto Infrastructure
Bitget’s September 24 breach affected certain hot and warm wallets, with the latest estimate at about $388M.
The incident highlights how third-party software, internal access and withdrawal controls can all become critical security layers.
$BTC $ETH $SOL

#bitgethotwalletbreachtiedtothirdpartysecurityflaw
security breach??#bitgethotwalletbreachtiedtothirdpartysecurityflaw What happened An attacker used a flaw in a third-party security product to obtain high-level internal credentials, then sent fraudulent withdrawal commands to Bitget's wallet system on September 24.About $388 million moved across 12 hot or warm wallet addresses, spanning 11 blockchains. Bitget first estimated $351.6M, then revised to about $387.5M after classifying additional Zcash and TRON transfers. It said the revision did not reflect new unauthorized transfers. How it worked The attacker didn't steal private keys. They forged transactions and routed them through the legitimate approval process. The exchange said the fraudulent commands caused the wallet system to execute abnormal transfers that bypassed risk controls. One analysis says the flaw gave access to an internal management system. The attacker reportedly wrote the forged instructions into the wallet backends and then deleted the traces. The stolen funds came from hot and warm wallets. Cold wallets were not affected. The "zero-day" claim Bitget's CEO reportedly described the flaw as a zero-day, meaning attackers exploited it before its maker had a fix. Bit get has not said whether the vendor has released a fix. It has said it patched the vulnerability on its side. The vendor hasn't been publicly named in the sources I found. Attribution CEO Gracey Chen suspects North Korean hackers, citing preliminary IP links. Ahlborn's analysis names Lazarus Group. Bit get says its investigation is still open, so the attacker's identity and the full extent of the compromise remain unconfirmed. Response and user impact Bit get paused withdrawals as a precaution, while trading and deposits continued, and has since restarted Bitcoin withdrawals. The loss is to be covered by its roughly $464 million User Protection Fund, and it offered a 5% bounty for freezing attacker funds and another 5% for recovery .It's coordinating with law enforcement and blockchain security firms to trace the assets. Bit get says it will apply stricter evaluation standards before adopting third-party security products, and add stronger isolation when deploying them.

security breach??

#bitgethotwalletbreachtiedtothirdpartysecurityflaw
What happened
An attacker used a flaw in a third-party security product to obtain high-level internal credentials, then sent fraudulent withdrawal commands to Bitget's wallet system on September 24.About $388 million moved across 12 hot or warm wallet addresses, spanning 11 blockchains. Bitget first estimated $351.6M, then revised to about $387.5M after classifying additional Zcash and TRON transfers. It said the revision did not reflect new unauthorized transfers.
How it worked
The attacker didn't steal private keys. They forged transactions and routed them through the legitimate approval process. The exchange said the fraudulent commands caused the wallet system to execute abnormal transfers that bypassed risk controls. One analysis says the flaw gave access to an internal management system. The attacker reportedly wrote the forged instructions into the wallet backends and then deleted the traces. The stolen funds came from hot and warm wallets. Cold wallets were not affected.
The "zero-day" claim
Bitget's CEO reportedly described the flaw as a zero-day, meaning attackers exploited it before its maker had a fix. Bit get has not said whether the vendor has released a fix. It has said it patched the vulnerability on its side. The vendor hasn't been publicly named in the sources I found.
Attribution
CEO Gracey Chen suspects North Korean hackers, citing preliminary IP links. Ahlborn's analysis names Lazarus Group. Bit get says its investigation is still open, so the attacker's identity and the full extent of the compromise remain unconfirmed.
Response and user impact
Bit get paused withdrawals as a precaution, while trading and deposits continued, and has since restarted Bitcoin withdrawals. The loss is to be covered by its roughly $464 million User Protection Fund, and it offered a 5% bounty for freezing attacker funds and another 5% for recovery .It's coordinating with law enforcement and blockchain security firms to trace the assets. Bit get says it will apply stricter evaluation standards before adopting third-party security products, and add stronger isolation when deploying them.
·
--
Haussier
#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw Bitget’s latest account says the September 24 incident involved unauthorized transfers from part of its hot and warm wallet infrastructure. The investigation indicates that attackers exploited a vulnerability in a third-party security product, obtained internal credentials, and used fraudulent withdrawal commands. Bitget says the underlying vulnerability has since been remediated. The currently reported impact is about $387.5–$388 million. Bitget says its cold wallets were not affected, user account balances remain unaffected, and Mandiant and SlowMist are supporting the ongoing forensic investigation and asset recovery. My takeaway: This incident highlights that exchange security depends not only on wallet architecture but also on the security of third-party systems and access controls. The important questions now are how the external vulnerability was exploited, what additional safeguards are implemented, and how much of the affected assets can be recovered. #Bitget #BitgetSecurity #CryptoSecurity #HotWallet #Web3Security
#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw

Bitget’s latest account says the September 24 incident involved unauthorized transfers from part of its hot and warm wallet infrastructure. The investigation indicates that attackers exploited a vulnerability in a third-party security product, obtained internal credentials, and used fraudulent withdrawal commands. Bitget says the underlying vulnerability has since been remediated.

The currently reported impact is about $387.5–$388 million. Bitget says its cold wallets were not affected, user account balances remain unaffected, and Mandiant and SlowMist are supporting the ongoing forensic investigation and asset recovery.

My takeaway: This incident highlights that exchange security depends not only on wallet architecture but also on the security of third-party systems and access controls. The important questions now are how the external vulnerability was exploited, what additional safeguards are implemented, and how much of the affected assets can be recovered.

#Bitget #BitgetSecurity #CryptoSecurity #HotWallet #Web3Security
Bitget的USDT提现窗口已到|页面仍标Pending不等于延期实锤|ETH在2670附近我先等 我的态度是先核实状态,再谈交易。币安广场的Bitget热钱包安全话题仍在上升,而Bitget原公告把九月三十日08:00 UTC,也就是北京时间今天16:00,列为USDT在Ethereum、BSC、Solana和Tron网络分阶段恢复提现的时间。现在时间窗口已到,Bitget事件汇总页对应USDT一行仍显示Pending;但同一页面标示最后更新时间为00:00 UTC,早于计划恢复时间。因此这只能说明我在公开页面尚未看到明确的完成确认,不能据此断言平台违约、延期或用户仍无法提币。是否真的可提,应看账户内当前网络状态、小额到账结果和后续官方公告。 需要把ETH本币提现与Ethereum网络上的USDT提现分清。Bitget汇总页把ETH及多个EVM网络列为已恢复,但USDT按币种另排在今天;某个网络能转ETH,不自动证明同网络的USDT已经开放。反过来,交易所的提款流程是否打开,也不等于以太坊主网安全出了新故障。两者的风控、托管和运营节点不同。此次事件的已披露攻击链指向第三方安全产品漏洞和伪造提款指令,并非以太坊共识协议被攻破;约3.88亿美元是多链多币的合计受影响规模,不应写成ETH单币损失。 市场价格没有给出明确的事件方向。发稿前币安ETHUSDT约2669.65美元,滚动二十四小时约跌2.09%,低点2656.92、高点2748.60。不能把下跌全归因于这条提款状态,也不能因为官方计划时间到了就断言市场已消化风险。我的观察位是2657附近的日内防线、2685附近的短线收复位,以及2749附近的上方压力。如果后续官方明确确认USDT各网络恢复、实际到账顺畅,并且价格能站稳2685,交易所信任修复才多一层证据;若公告继续缺位、用户实测受限或ETH跌破2657,偏谨慎的判断要进一步收紧。 如果是我自己交易,眼下不参与,方向为空仓观望。只有官方明确确认Ethereum网络USDT提现状态、小额到账有可复核反馈,同时ETH一小时收上2685且回踩2675至2685守住,我才考虑无杠杆现货试多,总资金仓位最多0.4%。目标先看2710减半,再看2740附近平掉余仓;硬止损2648,入场后连续两小时收回2675下方也全部平仓。若事前先跌破2657,或官方披露新增安全风险,直接取消计划。没有达到这些条件就没有成交,更没有已实现收益。 #BitgetHotWalletBreachTiedToThirdPartySecurityFlaw #ETH 以上仅为个人市场观察,不构成投资建议。
Bitget的USDT提现窗口已到|页面仍标Pending不等于延期实锤|ETH在2670附近我先等

我的态度是先核实状态,再谈交易。币安广场的Bitget热钱包安全话题仍在上升,而Bitget原公告把九月三十日08:00 UTC,也就是北京时间今天16:00,列为USDT在Ethereum、BSC、Solana和Tron网络分阶段恢复提现的时间。现在时间窗口已到,Bitget事件汇总页对应USDT一行仍显示Pending;但同一页面标示最后更新时间为00:00 UTC,早于计划恢复时间。因此这只能说明我在公开页面尚未看到明确的完成确认,不能据此断言平台违约、延期或用户仍无法提币。是否真的可提,应看账户内当前网络状态、小额到账结果和后续官方公告。

需要把ETH本币提现与Ethereum网络上的USDT提现分清。Bitget汇总页把ETH及多个EVM网络列为已恢复,但USDT按币种另排在今天;某个网络能转ETH,不自动证明同网络的USDT已经开放。反过来,交易所的提款流程是否打开,也不等于以太坊主网安全出了新故障。两者的风控、托管和运营节点不同。此次事件的已披露攻击链指向第三方安全产品漏洞和伪造提款指令,并非以太坊共识协议被攻破;约3.88亿美元是多链多币的合计受影响规模,不应写成ETH单币损失。

市场价格没有给出明确的事件方向。发稿前币安ETHUSDT约2669.65美元,滚动二十四小时约跌2.09%,低点2656.92、高点2748.60。不能把下跌全归因于这条提款状态,也不能因为官方计划时间到了就断言市场已消化风险。我的观察位是2657附近的日内防线、2685附近的短线收复位,以及2749附近的上方压力。如果后续官方明确确认USDT各网络恢复、实际到账顺畅,并且价格能站稳2685,交易所信任修复才多一层证据;若公告继续缺位、用户实测受限或ETH跌破2657,偏谨慎的判断要进一步收紧。

如果是我自己交易,眼下不参与,方向为空仓观望。只有官方明确确认Ethereum网络USDT提现状态、小额到账有可复核反馈,同时ETH一小时收上2685且回踩2675至2685守住,我才考虑无杠杆现货试多,总资金仓位最多0.4%。目标先看2710减半,再看2740附近平掉余仓;硬止损2648,入场后连续两小时收回2675下方也全部平仓。若事前先跌破2657,或官方披露新增安全风险,直接取消计划。没有达到这些条件就没有成交,更没有已实现收益。

#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw #ETH
以上仅为个人市场观察,不构成投资建议。
Bitget安全话题升温|ZEC在涉事名单不等于全额无法追踪|1394附近我先守纪律 我的态度先摆明:我不因“隐私币涉案”三个字追空ZEC,也不会把交易所追赃承诺写成已经追回。币安广场热榜的#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw与ZEC有关,原因是Bitget官方事件页把ZEC列在受影响资产中,且9月25日公告把Zcash和TRON链上资产纳入修订后的损失估算。平台目前给出的约3.88亿美元是跨多链、多个币种的合计数字;我没有看到可靠的ZEC单币损失拆分、被盗地址完整清单及每笔最终去向。因此“3.88亿美元ZEC被盗”是错的,“全都追回不了”也没有证据。 真正值得讨论的是追踪与冻结的边界。Zcash有公开地址和屏蔽交易,不同路径的链上可见信息不同;但我没有证据表明本案涉及的ZEC已全部进入屏蔽池,更不能假设所有ZEC都能被交易所或发行方直接冻结。Bitget称攻击路径是第三方安全产品漏洞导致内部高权限凭据被盗、伪造提现指令,冷钱包和私钥未受损;这是平台调查口径,后续仍应等独立技术报告。即使部分资产被标记、阻断或冻结,那也与链上资产已经返还受害方不是同一个状态。交易所托管风险、Zcash协议安全、ZEC价格,三者应分开判断。 市场没有给出明确的单一事件定价:发稿前币安ZEC/USDT约1392,滚动24小时跌约2.32%,区间1376至1460。这段价格既受安全话题影响,也可能受今晚美国宏观数据、隐私币自身流动性和基金交易预期影响,不能硬归因。另一个容易误读的数据是ZCSH资金流表:Farside的9月29日一栏仍是横线,自动合计显示0.0,不能据此说机构昨日没有买卖。消息越密集,我越不把空白当事实。 我关注两个验证点:Bitget后续有无披露ZEC单币金额及可核查地址、提现网络的实际可用状态;价格能否重新站稳1410并在回踩中守住。若新资料证实损失远超当前口径、出现持续异常转账,或者ZEC跌破1376后反抽失败,偏中性的判断就被推翻。若只是热榜转述变多、价格一根急拉,而证据没有增加,我仍把它当波动,不当趋势确认。 如果是我自己交易,现在不参与,方向只考虑无杠杆现货多单。完整小时收上1410,回踩1400至1410不破,且目标平台充提状态经小额测试正常,才用总资金最多0.3%试仓;目标1430先减半、1455附近把余仓平掉。硬止损设1375,若入场后连续两小时收回1400下也全部平仓。触发前先破1376,或披露显示事件继续扩大,计划取消;不为抢反弹而扩大仓位。这样做不是断言ZEC一定上涨,而是把未知损失和价格波动都放进纪律里。 #BitgetHotWalletBreachTiedToThirdPartySecurityFlaw #ZEC 以上仅为个人市场观察,不构成投资建议。
Bitget安全话题升温|ZEC在涉事名单不等于全额无法追踪|1394附近我先守纪律

我的态度先摆明:我不因“隐私币涉案”三个字追空ZEC,也不会把交易所追赃承诺写成已经追回。币安广场热榜的#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw与ZEC有关,原因是Bitget官方事件页把ZEC列在受影响资产中,且9月25日公告把Zcash和TRON链上资产纳入修订后的损失估算。平台目前给出的约3.88亿美元是跨多链、多个币种的合计数字;我没有看到可靠的ZEC单币损失拆分、被盗地址完整清单及每笔最终去向。因此“3.88亿美元ZEC被盗”是错的,“全都追回不了”也没有证据。

真正值得讨论的是追踪与冻结的边界。Zcash有公开地址和屏蔽交易,不同路径的链上可见信息不同;但我没有证据表明本案涉及的ZEC已全部进入屏蔽池,更不能假设所有ZEC都能被交易所或发行方直接冻结。Bitget称攻击路径是第三方安全产品漏洞导致内部高权限凭据被盗、伪造提现指令,冷钱包和私钥未受损;这是平台调查口径,后续仍应等独立技术报告。即使部分资产被标记、阻断或冻结,那也与链上资产已经返还受害方不是同一个状态。交易所托管风险、Zcash协议安全、ZEC价格,三者应分开判断。

市场没有给出明确的单一事件定价:发稿前币安ZEC/USDT约1392,滚动24小时跌约2.32%,区间1376至1460。这段价格既受安全话题影响,也可能受今晚美国宏观数据、隐私币自身流动性和基金交易预期影响,不能硬归因。另一个容易误读的数据是ZCSH资金流表:Farside的9月29日一栏仍是横线,自动合计显示0.0,不能据此说机构昨日没有买卖。消息越密集,我越不把空白当事实。

我关注两个验证点:Bitget后续有无披露ZEC单币金额及可核查地址、提现网络的实际可用状态;价格能否重新站稳1410并在回踩中守住。若新资料证实损失远超当前口径、出现持续异常转账,或者ZEC跌破1376后反抽失败,偏中性的判断就被推翻。若只是热榜转述变多、价格一根急拉,而证据没有增加,我仍把它当波动,不当趋势确认。

如果是我自己交易,现在不参与,方向只考虑无杠杆现货多单。完整小时收上1410,回踩1400至1410不破,且目标平台充提状态经小额测试正常,才用总资金最多0.3%试仓;目标1430先减半、1455附近把余仓平掉。硬止损设1375,若入场后连续两小时收回1400下也全部平仓。触发前先破1376,或披露显示事件继续扩大,计划取消;不为抢反弹而扩大仓位。这样做不是断言ZEC一定上涨,而是把未知损失和价格波动都放进纪律里。

#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw #ZEC
以上仅为个人市场观察,不构成投资建议。
Bitget热钱包事件再上热榜|第三方权限漏洞不等于ETH协议失守|2662附近我先等 我的态度:安全新闻先拆清责任边界,再决定是否交易;今天不把“黑客碰到ETH”写成以太坊网络被攻破。币安广场热榜出现#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw,我回看Bitget官方事件时间线:平台称攻击者利用第三方安全产品漏洞取得内网高权限凭据,伪造提现指令绕过风控,涉及热、温钱包;官方称私钥和冷钱包未被攻破。约3.88亿美元是其最新核算的受影响资产规模,不是“以太坊链损失”,也不是已经追回的金额。这个说法仍是交易所调查结论,独立技术报告尚待完整披露,不能当法院或全行业审计定论。 与ETH直接相关的是,官方列出受影响资产和网络包括ETH及多条EVM网络。交易所钱包后端被冒用,与以太坊共识规则被篡改、用户自托管钱包私钥泄漏,是三个不同层级。对交易员更实际的冲击是交易所对手方风险:提现暂停或分批恢复会影响跨平台搬砖、保证金补充和现货价差,资金即使账面可见,也未必能在需要时按原路径转出。官方页面对ETH恢复时间有排期和状态栏,我只把它当安排,不替用户保证此刻任意币种、任意网络都能提走;使用前要以账户实际网络及小额测试为准。 市场反应也要克制解读:写稿时币安ETH/USDT约2662,24小时跌约1.36%,区间2660至2749。跌幅不能全归因于一周前的安全事件,今晚美国宏观数据与整体风险偏好同样会改写价格。我的短线参考位是2660附近的当日低点与2700整数位。若2660失守后反抽无力,说明风险还没被吸收;若重新站上2700但提币实际运行和市场深度没有改善,也不足以证明安全隐患已经消除。若后续独立审计推翻平台攻击路径、出现新的异常转账,或平台恢复计划再度变更,我会立即重估判断。 如果是我自己交易,现在不参与,方向只保留条件式现货多单,不开杠杆。等完整小时站上2700,回踩2688至2700不破,同时目标交易所与接收网络经小额转账核验正常,才用总资金最多0.4%试仓。第一目标2725减半,第二目标2745附近平掉余仓;硬止损放在2660下方,入场后连续两小时收回2688下也全部平仓。若触发前价格先破2660,或新的安全公告与链上异常扩大,原计划作废,宁可错过也不在信息不全时重仓赌反弹。 #BitgetHotWalletBreachTiedToThirdPartySecurityFlaw #ETH 以上仅为个人市场观察,不构成投资建议。
Bitget热钱包事件再上热榜|第三方权限漏洞不等于ETH协议失守|2662附近我先等

我的态度:安全新闻先拆清责任边界,再决定是否交易;今天不把“黑客碰到ETH”写成以太坊网络被攻破。币安广场热榜出现#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw,我回看Bitget官方事件时间线:平台称攻击者利用第三方安全产品漏洞取得内网高权限凭据,伪造提现指令绕过风控,涉及热、温钱包;官方称私钥和冷钱包未被攻破。约3.88亿美元是其最新核算的受影响资产规模,不是“以太坊链损失”,也不是已经追回的金额。这个说法仍是交易所调查结论,独立技术报告尚待完整披露,不能当法院或全行业审计定论。

与ETH直接相关的是,官方列出受影响资产和网络包括ETH及多条EVM网络。交易所钱包后端被冒用,与以太坊共识规则被篡改、用户自托管钱包私钥泄漏,是三个不同层级。对交易员更实际的冲击是交易所对手方风险:提现暂停或分批恢复会影响跨平台搬砖、保证金补充和现货价差,资金即使账面可见,也未必能在需要时按原路径转出。官方页面对ETH恢复时间有排期和状态栏,我只把它当安排,不替用户保证此刻任意币种、任意网络都能提走;使用前要以账户实际网络及小额测试为准。

市场反应也要克制解读:写稿时币安ETH/USDT约2662,24小时跌约1.36%,区间2660至2749。跌幅不能全归因于一周前的安全事件,今晚美国宏观数据与整体风险偏好同样会改写价格。我的短线参考位是2660附近的当日低点与2700整数位。若2660失守后反抽无力,说明风险还没被吸收;若重新站上2700但提币实际运行和市场深度没有改善,也不足以证明安全隐患已经消除。若后续独立审计推翻平台攻击路径、出现新的异常转账,或平台恢复计划再度变更,我会立即重估判断。

如果是我自己交易,现在不参与,方向只保留条件式现货多单,不开杠杆。等完整小时站上2700,回踩2688至2700不破,同时目标交易所与接收网络经小额转账核验正常,才用总资金最多0.4%试仓。第一目标2725减半,第二目标2745附近平掉余仓;硬止损放在2660下方,入场后连续两小时收回2688下也全部平仓。若触发前价格先破2660,或新的安全公告与链上异常扩大,原计划作废,宁可错过也不在信息不全时重仓赌反弹。

#BitgetHotWalletBreachTiedToThirdPartySecurityFlaw #ETH
以上仅为个人市场观察,不构成投资建议。
Connectez-vous pour découvrir plus de contenu
Rejoignez la communauté mondiale des adeptes de cryptomonnaies sur Binance Square
⚡️ Suviez les dernières informations importantes sur les cryptomonnaies.
💬 Jugé digne de confiance par la plus grande plateforme d’échange de cryptomonnaies au monde.
👍 Découvrez les connaissances que partagent les créateurs vérifiés.
Adresse e-mail/Nº de téléphone