FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.8T -1.4%24h Vol $112.4B +63%Fear & Greed 74/100Alts Index 57/100
BTC.D 58.8% -0.1%Stable.D 9.4% +0.2%ETH.D 11.4% 0%Others.D 20.4% -0.1%
QNT$281.27+61.08%•Q$0.0498+37.46%•BTW$1.148+23.58%•BP$1.510+20.63%•GRT$0.0323+16.13%•SEI$0.0830+12.05%•PUMP$0.00491329+11.15%•XDC$0.0336+10.69%•GRASS$0.6307+10.66%•SOON$0.3320+10.21%•
AI$0.2205-17.26%•PONS$0.5186-15.9%•USELESS$0.2567-12.1%•BR$0.9088-11.77%•BCH$308.74-10.12%•SENT$0.0212-9.92%•ZRO$1.517-9.58%•ZEN$7.146-9.58%•AR$4.389-9.51%•ZAMA$0.0804-9.16%•
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      GoPlus: Bitget’s $387.5M Hack Exploited the…

      GoPlus Security says the $387.5 million Bitget hack did not result from stolen private keys but from a compromise of the exchange’s transaction-signing “trust chain,” allowing attackers to make fraudulent transfers appear legitimate to Bitget’s own authorization infrastructure. The finding provides a clearer technical explanation for the September 24 breach, which affected portions of Bitget’s hot and warm wallet infrastructure across multiple blockchains. According to GoPlus, attackers breached a critical wallet backend system, forged transaction data and caused Bitget’s authorized signing process to generate valid cryptographic signatures for transfers the exchange had never intended to approve.In other words, the signing keys continued operating as designed. The information they were being asked to sign had already been compromised. Bitget has separately confirmed that its private keys were not stolen and said it has identified and remediated the underlying vulnerability, although a complete technical post-mortem has not yet been released.

      $387.5M Drained Across Multiple Networks

      Bitget detected unauthorized transfers at 18:31 UTC on September 24 and initially estimated approximately $351.6 million had been affected. Subsequent onchain tracing raised that figure to $387.5 million after investigators incorporated Zcash and TRON transfers omitted from the preliminary calculation. Bitget stressed that the increase represented improved accounting rather than additional theft after the incident. Affected assets included XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX across Ethereum and other EVM networks, XRP Ledger, Zcash and TRON. GoPlus estimates that the main fund-drain window lasted approximately two hours and 25 minutes. The largest wave transferred roughly $185 million in about one minute.That timeline raises a second security question beyond the original intrusion: why automated controls did not halt subsequent transactions after abnormal transfers began. Bitget suspended withdrawals following the incident while keeping deposits and trading operational. The company said cold wallets were unaffected and customer balances remained intact. Its separate self-custodial Bitget Wallet product was also unaffected because it operates on different infrastructure.

      Signing Security Becomes the Bigger Issue

      The distinction between stealing keys and compromising the signing pipeline is significant for exchange security. Cryptocurrency custody systems frequently emphasize protecting private keys through hardware security modules, cold storage and multi-party authorization. Those protections are less effective if an attacker can manipulate the information reaching an otherwise secure signer. A cryptographically valid signature proves that an authorized key approved particular transaction data. It does not, by itself, prove that the underlying transaction was legitimately requested. GoPlus therefore argues that exchanges need independent pre-signing risk controls capable of verifying destinations, amounts and transaction context rather than allowing the signing system to rely on a single upstream source of trusted information.The firm also drew structural parallels with the $1.5 billion Bybit hack in February 2025, although the attack mechanisms were not identical. In both cases, GoPlus argues, attackers targeted trust surrounding the signing process rather than simply extracting private keys. GoPlus has blacklisted addresses associated with the Bitget attacker and distributed the information to ecosystem partners. Bitget, meanwhile, is working with Mandiant and SlowMist on its investigation and has notified law enforcement. It has also launched a recovery bounty program. The exchange says its User Protection Fund held more than $464 million when the incident occurred, exceeding the revised value of affected assets.Questions remain over the attackers’ initial point of entry and exactly which backend component was compromised. Bitget has said those forensic investigations remain underway. The emerging technical lesson, however, extends beyond Bitget: protecting a cryptocurrency exchange requires securing not only the keys that sign transactions, but the entire chain of systems that decides what those keys are told to sign.

      Source: FinanceFeeds
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud