Bitget Faces $463M in Withdrawals After $388M Hack Attributed to Lazarus Group
Bitget, a prominent cryptocurrency exchange, reported an alarming $463 million in net outflows following a security breach that resulted in the theft of approximately $388 million from its hot wallets. This incident, which occurred on September 24, marked the largest single-day withdrawal event recorded by DefiLlama in the past four years.
The breach was executed by exploiting a vulnerability in a third-party security product, allowing attackers to inject spoofed transaction data into Bitget's authorization process. Notably, Bitget's private keys remained secure, and its cold storage wallets were unaffected. The attack was characterized by two preliminary test transfers that assessed the exchange's risk controls before the main unauthorized withdrawal took place.
The loss, initially estimated at $351.6 million, was revised to between $387.5 million and $388 million. This amount represents roughly 6.8% of Bitget's total reserves, which stand at approximately $5.7 billion. In response to the breach, Bitget began a phased resumption of withdrawals on September 28, four days after the incident. The exchange maintains a User Protection Fund, which had exceeded $464 million prior to the hack, but has since dropped below $200 million due to the incident.
CEO Gracy Chen indicated that forensic analysis suggests the involvement of North Korean threat actors, specifically the Lazarus Group. Cybersecurity firms Mandiant and SlowMist are currently assisting in the investigation.
Cross-Chain Security Debate Intensified
The stolen funds from Bitget had to be laundered through cross-chain swap services, which have differing approaches to handling such transactions. NEAR Intents, a swap service, successfully blocked over $50 million in attempted transfers linked to the theft. In contrast, THORChain, the largest decentralized swap network, processed approximately $6.3 million in swaps from a wallet associated with the attack and declined to block the involved addresses.
NEAR's screening system, known as SHIELD, was able to freeze about $503,000 mid-transaction, while THORChain maintains a policy of not censoring transactions. This divergence in handling stolen funds highlights the ongoing debate about security and decentralization in the crypto space.
As the industry grapples with these challenges, the response to the Bitget hack may set precedents for future cross-chain security measures and the responsibilities of decentralized platforms in preventing the movement of stolen assets.
FAQ
What was the total amount stolen in the Bitget hack?
Approximately $388 million was stolen from Bitget's hot wallets during the security breach.
How did the hackers execute the breach?
The breach was executed by exploiting a vulnerability in a third-party security product, allowing attackers to inject spoofed transaction data into Bitget's authorization process.
What measures has Bitget taken in response to the hack?
Bitget began a phased resumption of withdrawals on September 28, four days after the incident, and is currently working with cybersecurity firms Mandiant and SlowMist for the investigation.
What impact did the hack have on Bitget's User Protection Fund?
Prior to the hack, the User Protection Fund exceeded $464 million, but it has since dropped below $200 million due to the incident.
What is the significance of the cross-chain security debate highlighted by this incident?
The incident intensified the debate about security and decentralization in the crypto space, as different swap services handled the laundering of stolen funds in varying ways, raising questions about the responsibilities of decentralized platforms.
Comments
Comments are moderated before publish.
No comments yet — be the first.