RC RANDOM CHAOS

Bitget Hack: $388M Stolen via Third-Party Security Flaw

· via The Hacker News

Original source

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The Hacker News →

A cryptocurrency exchange, Bitget, suffered a $388 million theft due to a vulnerability in a third-party security product. The attacker exploited the flaw to obtain high-level internal credentials and sent fraudulent withdrawal commands to Bitget’s wallet system on September 24. The stolen funds were from Bitget’s hot and warm wallets, while its cold wallets remained unaffected. The attack involved inserting fraudulent withdrawal commands into wallet-related backend services, bypassing risk controls. Bitget has taken steps to secure its systems, including isolating affected systems, revoking and reissuing internal credentials, and increasing monitoring for unusual activity. The exchange suspects North Korean hackers and has published the main addresses receiving the stolen funds, asking other exchanges and infrastructure providers to monitor these addresses.

Read the full article

Continue reading at The Hacker News →

This is an AI-generated summary. Read the original for the full story.