Bitget Security Incident — Infrastructure Compromise Without Private Key Leak

Security Alert: Large-Scale Withdrawal via Wallet Infrastructure Breach

The security incident at Bitget involves an unauthorized transfer worth approximately $351.6 million to $387.5 million from hot and warm wallets. While significant, this is classified as a compromise of transaction signing/authorization chains rather than a theft of private keys.

Key Technical Details

  • Nature of Attack: Malicious actors compromised the backend wallet infrastructure (chain of trust), substituting transaction data so that internal authorization processes signed valid transfers unintendedly caused ownsetr [unauthorized].
  • Impacted Assets: ETH, XRP, USDT, USDC, AVAX, BNB, among others.
  • Speed of Drain: The drain lasted roughly 2 hours and 25 minutes; during one peak minute, enough volume moved ($185m) or close would suggest extreme velocity if any single wave was monitored improperly. (Note: High concentration detected).
  • Risk Mitigation: Cold wallets remained unaffected으로 because they were not part of the vulnerable permission layer. Furthermore, the loss is fully covered by moving assets within the context of its User Protection Fund exceeding $464 million.

Comparative Context

  • GoPlus Security notes certain structural similarities betweenthis event and previous market incidents like the Bybit exploit in early 2025, though technical reports are pending for full confirmation.

The bottom line: Bitget remains solvent with all losses covered by protection funds while waiting for final audit/report completion regarding wayways unauthorized signatures bypassed security checks.

! DYOR (Do Your Own Research)