North Korea accused of plundering Bitget for $387 million in year’s biggest crypto attack
Hackers exploited Bitget’s wallet backend, using a flaw that made fraudulent withdrawals look legitimate.
On Thursday night, the cryptocurrency exchange Bitget fell victim to a massive security breach, resulting in the theft of over $387 million. According to Bitget CEO Gracy Chen, the attackers allegedly exploited a backend system responsible for processing wallet transactions, making fraudulent withdrawals appear legitimate. The perpetrators did not steal private keys but instead manipulated Bitget's internal approval system to authorize the transfers.
The exchange has since patched the vulnerability and is pausing withdrawals while investigating the security incident. Bitget's native token, BGB, experienced a nearly 7% drop in value to $1.93 before recovering slightly to $1.97. The unauthorized transfers were limited to the exchange's hot and warm wallets, which are company-controlled pools of crypto used for processing customer trades and withdrawals.
Bitget Wallet, a self-custodial product where users control their own cryptocurrency, remained unaffected. The breach is the largest cryptocurrency hack of the year so far, coming on the heels of several other security incidents in the crypto sector over the past three months.
Written by urgent.news from Fortune's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.