History was happening right in front of us. while people were catching me up on what I'd missed over the past two weeks, one of the biggest thefts of the year was underway. Yeah, I'm still talking about
@bitget getting cleaned out for $387.5m
CT is still talking about how Bitget will cover the losses. researchers are digging through blockchains hoping for a bounty, and
@zachxbt is already naming the middlemen laundering the stolen cash. (btw, I hope he actually gets paid for his work this time)
I'm obsessed with wallets, so I went digging into how this attack was even possible and what the team did when they spotted it.
Mandiant and slowMist lay out the attack vector in their reports. Links if you want to read them:
img.bgstatic.com/multiLang/e…
github.com/slowmist/Knowledg…
But after reading them, I've got more questionss about the team's response than anything else...
Three times in Bitget timeline. september 24, all utc:
19:05: Risk controls spot a discrepancy and block withdrawal requests.
20:40: The team starts moving funds to cold wallets.
21:44: They shut down withdrawals, including the transaction signing service.
2 hours and 39 minutes between blocking requests and shutting down signing. Were you guys asleep or what?
And the thief didn't just leave some signed transactions behind and walk away. After 21:22, he was still looking through logs, checking request statuses, still trying to steal BTC.
So requests were already being blocked. And the hacker was still in there, working inside the infrastructure.
Take the usdc transfers. at 20:41, 2.6m usdc gets moved out of the hot wallet address on ethereum:
etherscan.io/tx/0xb9f716952b…
On Avalanche, that same address has 8.6m USDc left after a series of transfers around 20:40. at 20:55, 8.2M of it goes to the attacker:
snowtrace.io/tx/0x4d2d95dadf…
Why the hell was that money still there? Did you forget about it? Couldn't move it in time?
I don't like kicking people when they're down. But for an exchange this size, this looks negligent. You're already blocking requests, you're moving funds, and the hacker is still working inside your infrastructure. Why were millions in usdc still sitting in that wallet for him to take later?
Okay, a third-party vulnerability explains how he got in. But how far he could get into your systems and how fast you could cut him off, that's on you.
I don't know what the team had figured out minute by minute during the hack. But being ready for shit like this should've been part of your product from day one.
My feed is full of people talking about money leaving Bitget. Looks like net outflows hit roughly half a billion dollars in the first 24 hours after they started bringing withdrawals back. And I get it. nobody wants a security crew that's already there but holds back the homeowner while the thieves carry their stuff out.
I'm a fan of decentralization. This just made me more sure of it. I want to control my own money and take responsibility for my own decisions. And if you take on the job of holding other people's funds, you're responsible for keeping them safe. (Protecting them, not paying them back.)
$352m? If that number checks out,
@bitget just made it into the biggest fuckups we’ve talked about here today This post was supposed to be satire…
but seriously, this is awful. Really hope the team gets it sorted fast
They have a Protection Fund, so I’m less worried about user funds.
Bearish for the market. a reminder for users to be careful with their keys. and for those of us building, warm and hot wallets need more layers of protection