Bitget Reports $388M Theft Linked to Third-Party Security Flaw

Bitget Reports $388M Theft Linked to Third-Party Security Flaw

According to Bitget, the cryptocurrency exchange, the individual responsible for the theft of approximately $388 million accessed the platform via a vulnerability in a third-party security product utilized by the exchange, as stated on Monday.

The attacker took advantage of this flaw to acquire high-level internal credentials, which were then used on September 24 to issue fraudulent withdrawal commands to Bitget’s wallet system.

Typically, exchanges store the majority of customer funds in offline cold wallets, while hot and warm wallets are employed for processing withdrawals. Transfers from these wallets require approval before being finalized. The funds that were stolen originated from Bitget’s hot and warm wallets, with its cold wallets remaining unaffected.

Last week, Bitget disclosed that a critical backend system within its wallet infrastructure had been compromised, allowing the attacker to spoof transaction data and activate the approval process. However, the method of the attacker’s entry had not been revealed.

In a livestream on Monday, Bitget CEO Gracy Chen detailed the attack during an interview with The Block and in comments to Cointelegraph. The vulnerability allowed the attacker to access an internal management system, from which they inserted fraudulent withdrawal commands into backend services related to wallets, where they were processed as legitimate.

On September 24, the attacker initiated two small test transfers at 18:31 UTC, which remained below Bitget’s risk-control threshold and did not trigger any alerts.

Approximately 30 minutes later, larger transfers commenced, and Bitget’s wallet system executed them, circumventing its risk controls.

“Throughout the process, they utilized legitimate credentials. They masked their actions as standard administrative tasks while erasing evidence of their activities,” Chen stated, as reported by U.Today.

Bitget confirmed that no private keys were compromised, a conclusion based on its ongoing investigation.

Chen did not specify the product in her comments on Monday. However, The Block reported that she referred to the flaw as a zero-day, indicating a vulnerability exploited by attackers before a fix was available from the manufacturer.

Bitget has informed the vendor, isolated the compromised systems, revoked and reissued internal credentials, and disabled the affected functionality while addressing the vulnerability, as reported by Crypto Briefing. The exchange has not disclosed whether the vendor has provided a fix.

This account of the incident is based on information from Bitget. Security firms Mandiant and SlowMist are assisting in the investigation, and Bitget anticipates releasing a formal incident report this week.

In response to the attack, Bitget has restricted internal access, implemented independent checks on withdrawals, and enhanced monitoring for unusual activities. The exchange plans to reassess how it evaluates and utilizes third-party security products.

According to Bitget, customer account balances were not impacted. The exchange’s Protection Fund, which is reserved for security incidents like this, will cover the losses.

Bitcoin withdrawals resumed on Monday, with other assets set to follow in stages until October 2. Users are not required to take any action.

Bitget, which previously indicated North Korean hackers as suspects, continues to believe “the same group of individuals” is involved, Chen informed The Block. She refrained from naming the group until the company’s incident report is released.

Last week, TRM Labs, a blockchain analytics firm, reported finding connections between the stolen funds and wallets used to launder previous North Korean thefts. These connections suggested the involvement of the North Korean group TraderTraitor, although TRM had not made a definitive attribution.

Bitget has released the primary addresses that received the stolen funds, along with a live tracking dashboard. The exchange has requested that other exchanges, stablecoin issuers, bridges, custodians, and other infrastructure providers monitor these addresses and report any findings through its recovery portal.

The addresses listed by Bitget on September 25 include:

  • Ethereum and EVM networks: 0x770b10b273fc44fe9197d6bf20f145c2e98463ee
  • XRP: rwNhefsz1UQEusxhCvHip3RANinWi4CTck
  • Zcash: t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG
  • TRON: TBWNguTTgezw9dVorX441C6nDrZ

Source: Original article

Leave a Reply

Your email address will not be published. Required fields are marked *

Back To Top