#BitgetCEOConfirms$388MStolenInHack

The crypto space has experienced one of its largest security breaches of the year. Bitget CEO Gracy Chen confirmed that an estimated $387.5 million was drained following an exploit targeting critical backend systems.

Here is a comprehensive breakdown of what happened, current mitigation steps, and what traders need to do next:

1. How the Breach Occurred

System Compromise: Attackers compromised a third-party security product and critical backend wallet infrastructure.

Spoofed Approvals: The hackers forged transaction data, effectively tricking Bitget's own authorization systems into validating the unauthorized outbound transfers.

Affected Chains: Losses spanned multiple blockchains, including Ethereum (ETH), XRP Ledger, TRON, Zcash, BNB Chain, and Avalanche.

Suspected Attribution: Early investigations link the exploit mechanics to sophisticated state-sponsored threat groups, such as North Korea's Lazarus/TraderTraitor network.

2. Current Status & Protection Measures

User Protection Fund: Bitget has clarified that its $400M+ Protection Fund is fully equipped to cover the affected assets, ensuring user balances remain backed.

Staggered Withdrawal Resumption: Suspended services are gradually coming back online after rigorous security audits. Bitcoin network withdrawals have begun reopening, with Ethereum and USDT expected to follow shortly.

Forensic Investigation: Leading Web3 security teams, including Mandiant and SlowMist, are working alongside law enforcement to trace and freeze stolen funds on-chain.

3. Key Action Plan for Crypto Holders

Verify Token Approvals: Use tools like Revoke.cash to review and revoke unnecessary smart contract permissions on your personal EVM wallets.

Beware of Phishing Scams: Major exchange incidents trigger influxes of fake support accounts offering "refunds" or "withdrawal assistance." Rely exclusively on official Bitget channels.

Upgrade Account Security: Ensure 2FA (hardware keys like YubiKey or authenticator apps) is enabled on all exchange accounts and avoid using SMS