Bitget Loses $352M in Hack via Spoofed Transfers, Not Private Keys
What happened: Crypto exchange Bitget confirmed a $351.
What happened: Crypto exchange Bitget confirmed a $351.6 million loss after attackers compromised a backend wallet system and spoofed transaction data to authorize unauthorized transfers. CEO Gracy Chen stated that private keys were not stolen; instead, the breach exploited internal authorization processes. Bitget's User Protection Fund, valued at over $464 million, covers the loss, but withdrawals remain suspended pending review. Preliminary investigations suggest North Korean-linked hackers may be responsible, though attribution is not yet conclusive.
Why it matters: The scale and method of the attack highlight evolving risks for centralized exchanges, particularly around internal controls and supply-chain vulnerabilities. Bitget's rapid communication and assurance of user fund safety contrast with the operational impact of suspended withdrawals. The incident underscores the need for robust backend security and transparency in breach response, as well as the persistent threat from state-linked hacking groups.
Source: CoinDesk