TGViewer
Daddy Agregator Daddy Agregator @daddyagregator · 6.3K subscribers
Post #104359 266

Forwarded from Crouton Digital | Official

#Bitget #Security #XRP #ETH 💻

Bitget lost $351.6M - and the private keys weren't compromised

September 24, 18:31 UTC: unauthorized transfers out of Bitget. Private keys intact. Attackers hit the critical backend of the wallet infrastructure and routed malicious transactions through it. $351.6M gone.


Per Lookonchain, the breakdown by stolen asset:
⏺️ 102.93M XRP - ~$157.5M (the single largest position)
⏺️ 31,890 ETH - ~$86M
⏺️ USDT, USDC, BNB, AVAX - the remainder

Cold wallets and the decentralized Bitget Wallet were untouched. Withdrawals are suspended; trading and deposits continue. The User Protection Fund stands at $464M - it covers the declared loss.

🟢 Mandiant and SlowMist are running the investigation. Bitget CEO Gracie Chen went live on X with preliminary findings:

"We found IP addresses matching the VPN choice of a certain North Korean group; the pattern is very similar to what the North Korean team has done before."


On-chain researcher Specter linked the stolen XRP to the "AFX EXPLOITER" cluster, which has previously been attributed to TraderTraitor. The connection to Lazarus remains unconfirmed. The FBI formally attributed the $1.5B Bybit hack to North Korean actors in early 2025. Bybit CEO Ben Zhou has already updated LazarusBounty, his cross-chain tracking service built to surface and freeze stolen assets. North Korean involvement remains a working hypothesis - not an official verdict.

🟢 The structural irony: XRP accounts for nearly half the haul - and it cannot be frozen. Ripple has no kill-switch for individual addresses in the XRP Ledger. USDT and USDC issuers have already started locking attack-linked addresses. The largest single piece of the theft stays liquid.

Neither Bybit in February 2025 ($1.5B) nor Bitget today broke cryptography. Both attacks targeted the operational layer around custody - there, a signing-interface compromise; here, a backend authorization breach. Different exchange, same playbook. $464M in the protection fund covers the loss on paper, but the structural question remains: why were $351.6M within reach of one compromised backend system?

➡️Crouton.digital | About us⬅️
More from @daddyagregator
  1. Sep 26, 2026В шаге от того, что бы занести в PreIPO Oura в @Wallet. Напишу чуть мыслей почему стоит за…
  2. Sep 26, 2026💸 Bitget начнёт возвращать вывод средств с 28 сентября после взлома на $388 000 000. Бирж…
  3. Sep 26, 2026Дали доступ к Аркусу неделю назад, удалось сделать нейтрального ботика на Arcus + Nado (за…
  4. Sep 26, 2026🎲 Хакерша девять месяцев имела доступ к системе игорного регулятора Кюрасао и раскрыла до…
  5. Sep 26, 2026🪙 Запустить собственный узел Ethereum стало значительно проще — теперь его можно синхрони…
  6. Sep 25, 2026⚡️50-100$ НА АКК С IPO $OURA? (разбираемся) — Салют, Свидетель! В тг валлете скоро стартуе…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →