Bitget's $351.6M hack wasn't a private-key theft -- it was a spoofed signing pipeline, and $157M of the stolen XRP can never be frozen.
The news: CEO Gracy Chen revealed the first real technical detail on yesterday's breach -- attackers compromised a backend system that generates wallet-signing data, spoofing transaction/authorization data to trigger legitimate-looking withdrawal approvals. Private keys were never touched; cold wallets stayed secure. Chen said investigators found IP addresses tied to VPN infrastructure previously linked to a North Korean hacking group, calling the connection "very likely" but explicitly not yet confirmed. Some recovery is already underway: chain foundations have frozen hacker-controlled addresses holding centrally-issued tokens like USDT/USDC. But almost 102.9M XRP (~$157M) sits in wallets no one can freeze -- XRPL's freeze tools only apply to issued tokens, not the native asset -- and most stablecoin proceeds on EVM chains have already been converted to ETH, which also can't be blocked. Bitget's full root-cause report is due later today; withdrawals remain frozen, deposits and trading stay open, and the $464M+ User Protection Fund is expected to cover the full loss.
The catch: "very likely" North Korea is Bitget's own read based on IP-pattern matching -- no independent blockchain-forensics firm has published its own attribution yet, so treat that part as suspected, not confirmed.
Our read: the real lesson here isn't the dollar figure, it's that a signing-pipeline compromise beats stronger private-key security entirely -- and XRP's lack of a native freeze mechanism just turned from a decentralization feature into a recovery liability.
Does knowing the keys were never touched change how you think about exchange security, or does the outcome -- $351.6M gone either way -- matter more than the mechanism?
Not financial advice. DYOR.
$XRP #CryptoNews #Bitget #Security
The news: CEO Gracy Chen revealed the first real technical detail on yesterday's breach -- attackers compromised a backend system that generates wallet-signing data, spoofing transaction/authorization data to trigger legitimate-looking withdrawal approvals. Private keys were never touched; cold wallets stayed secure. Chen said investigators found IP addresses tied to VPN infrastructure previously linked to a North Korean hacking group, calling the connection "very likely" but explicitly not yet confirmed. Some recovery is already underway: chain foundations have frozen hacker-controlled addresses holding centrally-issued tokens like USDT/USDC. But almost 102.9M XRP (~$157M) sits in wallets no one can freeze -- XRPL's freeze tools only apply to issued tokens, not the native asset -- and most stablecoin proceeds on EVM chains have already been converted to ETH, which also can't be blocked. Bitget's full root-cause report is due later today; withdrawals remain frozen, deposits and trading stay open, and the $464M+ User Protection Fund is expected to cover the full loss.
The catch: "very likely" North Korea is Bitget's own read based on IP-pattern matching -- no independent blockchain-forensics firm has published its own attribution yet, so treat that part as suspected, not confirmed.
Our read: the real lesson here isn't the dollar figure, it's that a signing-pipeline compromise beats stronger private-key security entirely -- and XRP's lack of a native freeze mechanism just turned from a decentralization feature into a recovery liability.
Does knowing the keys were never touched change how you think about exchange security, or does the outcome -- $351.6M gone either way -- matter more than the mechanism?
Not financial advice. DYOR.
$XRP #CryptoNews #Bitget #Security
