Good morning everyone!
$351.6M walked out of Bitget yesterday in about an hour. The line that got my attention wasn't the number, it was this one: the attacker never got the private keys.
They compromised a backend system instead. The keys sat exactly where they were supposed to be, and the hot wallets moved anyway, because the thing that tells them what to sign had been taken over. Cold storage held. Gracy Chen confirmed both!
I study cybersecurity, and this is the shape of every big one now. February 2025, Bybit, $1.4B: the attackers spoofed a signing screen on a routine transfer. Both went around the keys instead of through them. The industry spent a decade hardening custody and the attackers moved one layer up, to the part that decides what gets authorised.
Then I went looking at what actually left, and that's the part I haven't seen anyone say. The protection fund is 5,500 BTC. The hole isn't Bitcoin. Lookonchain has XRP alone at about $157M, and the attacker has already swapped the EVM side into 67,982 ETH. Around $75M of it was stablecoins, and those can be frozen by their issuers. Native XRP and ETH can't!
So the coverage everyone is quoting is Bitcoin standing behind a liability denominated in something else, and the net after freezes hasn't been published yet.
One forensic detail I found "funny", is that the attacker paid up to 5% over market for that ETH. Seems that he cared more about speed more than price.
JUST IN: 馃毃 Bitget says ~$351.6M in assets was stolen from the exchange's hot and warm wallets and has suspended withdrawals.