UNICORN⚡️🦄
UNICORN⚡️🦄|9月 25, 2026 07:17
General Kim of North Korea treated the cryptocurrency exchange as an ATM, and $350 million was stolen from Bitget Compared to before, Bybit's Safe multi signature front-end was tampered with, and the signer thought they were signing a normal transaction Bitget was not breached by a single wallet or currency this time, but by the exploitation of the backend authorization process itself, involving dozens of assets and several chains What is the current status Withdrawals are still suspended, recharges and transactions are normal Its CEO Gracy Chen said that recovery would take several hours to several days, not weeks, but refused to give a specific time. The original statement was that she did not promise a time window that could not be guaranteed Suspend coverage of all 4930 Bitget currency networks. BGB is now 1.98, down 2.5% timeline On September 24th at 18:31 UTC (Beijing 25th at 2:31 am), the first abnormal transfer was made, mainly in ETH Half an hour later, an XRP hot wallet began to make large transfers, which was the largest transaction The attacker concentrated the transfer until 19:16 UTC 21:30 UTC, Chen made an announcement At 21:41 UTC, there are still funds going out, which is 10 minutes later than the announcement Bitget later identified 52 meaningful transfers, of which 19 were confirmed to have been made by attackers, corresponding to approximately $351 million How did the money go out The biggest single loss comes from an XRP hot wallet Ranked by chain, XRP and Ethereum suffer the greatest losses, while also involving Arbitrarum, Optimism, Base, BNB Chain, Avalanche XRP 102.93 million pieces (157 million) ETH 31, 890 pieces (85.75 million) USDT 34.75 million USDC 21.05 million USDT0 19.67 million XAUt 3000 pieces (12.82 million) BNB 9.88 million AVAX 8.38 million TRX 7.07 million Ethereum and Arbitrarum alone have 133.4 million legs Convert all stablecoins to ETH using Uniswap X and 1-inch Fusion, with a 5% premium accepted, just for the sake of speed USDT and USDC can be frozen by the issuer, while ETH cannot official statement Chen wrote on X that the attacker invaded a critical backend system in the wallet infrastructure, used it to forge transaction data, triggered the authorization process, and transferred money out Private key leakage has been ruled out, no forged user withdrawal requests have been made, and losses have been controlled The cold wallet is fine, it only affects some hot wallets and warm wallets. Full coverage of $464 million user protection fund, in addition to $1 billion of self owned funds and 1:1 reserve of user assets In the live broadcast, she added a sentence that preliminarily judged it to be a supply chain attack, and the one that was breached was a third-party tool used by Bitget in daily life An independent third-party security team has been commissioned to enter the site, and withdrawals will only resume after all vulnerabilities have been identified and fixed Additionally, there is a possibility of recovering some of the funds The real culprit's line On chain detective Specter traced the stolen XRP to an Ethereum address that received 68808 USDT. The wallet used for the transfer had previously been transferred ETH to an address labeled AFX EXPLOITER AFX is a protocol on Arbitrum, which was attacked by a bridge on July 22 and took $24.15 million. Its own review named Trader Raitor, which is a subgroup under Lazarus Earlier, LayerZero grouped the KelpDAO bridge attack in April under the same group Chen said 'very likely to be North Korea', but did not name it She also emphasized that this time is different from the Bybit incident in 2025 Bybit is a Safe multi signature front-end that has been tampered with, and the signer thought they were signing a normal transaction Bitget was not breached by a single wallet or currency this time, but by the exploitation of the backend authorization process itself, involving dozens of assets and several chains So I dare not resume withdrawals first, fearing that the same pipeline will be used a second time Bybit's Ben Zhou publicly responded, the team is on standby at any time, and is updating http://(LazarusBounty. com) to help Bitget chase funds Where to place a question mark 351.6 million is Bitget's own number At the beginning, the on chain tracker only saw 183 million, and the difference was mainly due to the XRP leg. The tracker focused on Ethereum and couldn't see the XRP Ledger No one has verified what is inside the 464 million yuan protection fund. The Chinese announcement reads' over 400 million ', which does not match the English one of 464 million Analysis suggests that the transaction involves three hot wallets and one cold wallet, which contradicts the official statement that 'all cold wallets are secure' The attribution of North Korea is much stronger in the evidence chain than simple IP matching, but law enforcement and security companies have not yet released formal technical reports This year, ZachXBT has repeatedly accused Bitget of condoning market makers to manipulate supply, but Bitget denies it Industry Location DeFiLlama listed this as the largest theft of 2026, surpassing Liquid Network's 320 million in September and Drift's 295 million in April From 2026 to present, a total of approximately 2.2 billion US dollars have been stolen Next, let's look at three things: When will withdrawals resume The 24-hour report (which was supposed to be sent before 05:30 Beijing time on September 26th) clearly states whether the entrance has been identified, whether the third-party tool has been named, and whether the 67982 ETH exchanged has been deposited into Tornado Cash
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads