šŸ”¤ UPD: The $352M Bitget Hack Started Almost a Month Earlier

CRYPTO ROAST, @roasted_crypto

Open in Telegram
#1981Text

šŸ”¤ UPD: The $352M Bitget Hack Started Almost a Month Earlier 🟠Remember the $351.6M Bitget hack? SlowMist’s investigation suggests the actual operation didn’t begin on September 24. The first traces of malicious activity reportedly appeared as early as August 31. 🟠According to SlowMist, the attacker exploited a zero-day vulnerability in a third-party security service, gaining access to its database. Malicious activity was later identified on two additional nodes — suggesting the attackers were already establishing their foothold weeks before the money moved. 🟠Then on September 25, the attacker reportedly compromised another third-party security service using an employee account and began uploading malicious files. The attackers had also prepared a tool specifically designed for Bitget’s internal systems. 🟠That tool could allegedly forge risk-control parameters, automatically generate withdrawal requests and execute them. Once the theft began, assets were withdrawn across multiple blockchains for almost three hours. 🟠SlowMist is still investigating exactly how the attackers moved between the compromised systems. But the timeline makes one thing clear: this wasn’t a quick wallet exploit. It appears to have been a multi-stage operation prepared weeks in advance. 🟠Meanwhile, Bitget is gradually restoring withdrawals. USDT withdrawals are now available on Ethereum, BSC, Solana and Tron, while BTC and ETH withdrawals had already been reopened. šŸ‘‰ The $352M disappeared in hours. The attack behind it may have been running for almost a month.

Open in Telegram
Views1,589āˆ’66%vs avg
Forwards4
Reactions61
Comments—

Reactions

  • šŸ‘28
  • ā¤19
  • 🄰13
  • šŸ”„1

More from CRYPTO ROAST

  1. 01

    šŸ”¤ UPD: Trezor Data Leak Is Much Bigger Than We Thought 🟠Remember the ShipMonk breach that exposed the personal information of roughly 14,000 Trezor customers? Turns out that was only part of the story. 🟠Trezor now says data belonging to another 67,000 U.S. customers was also exposed. The leaked records reportedly include names, emails, phone numbers, shipping addresses, and order numbers from purchases made between 2019 and 2021. 🟠The ugly part is that this data apparently shouldn’t have existed anymore. Trezor says logistics partner ShipMonk repeatedly provided written confirmation that the old customer data had been deleted — yet it remained stored in its systems. 🟠No private keys or seed phrases were compromised, so this isn’t a hardware-wallet hack. But combining a person’s name, phone number, home address, and proof that they purchased a hardware wallet creates an extremely valuable targeting database. 🟠Trezor is warning users about increased risks of targeted phishing, scam calls, impersonation attacks, and even physical security threats. A scammer doesn’t have to guess whether you own crypto anymore — the leaked order history already tells them. 🟠This is why privacy matters just as much as wallet security. Your seed can remain perfectly safe while leaked personal data gives attackers everything they need to start working on you instead. šŸ‘‰ They didn’t steal the keys. They leaked a map of who might be holding them.

    Text
    Views7.83K
    Forwards1
    Reactions415
    Comments—
  2. 02
    Views7.29K
    Forwards1
    Reactions404
    Comments—
  3. 03
    Views7.16K
    Forwards1
    Reactions421
    Comments—
  4. 04

    šŸ”¤ UPD: $115M COLDCARD Hacker Starts Moving the Bitcoin 🟠Remember the COLDCARD seed-generation flaw that allowed attackers to reconstruct weak private keys and drain thousands of wallets? The stolen funds are finally starting to move. 🟠According to Galaxy Digital’s Alex Thorn, the third-wave attacker moved stolen $BTC on-chain for the first time, swapping part of it into $ETH through THORChain — likely the beginning of the laundering and cash-out phase. 🟠The scale is now estimated at 1,789.28 BTC worth roughly $114.7M, stolen from 8,865 addresses across the full series of attacks. Until now, funds from all three waves had reportedly remained sitting in the attackers’ original wallets. 🟠The hacker is apparently having some trouble. Several THORChain swaps were reportedly refunded, but attempts to move the Bitcoin continue. Around 90% of the third-wave funds still haven’t moved. 🟠Thorn says the BTC routed through THORChain has already been traced to new Ethereum addresses, with the information shared with authorities and crypto companies. Moving across chains may complicate tracking — but it also creates an entirely new trail for investigators to follow. 🟠The exploit phase is basically over. Now comes the harder part for the attacker: turning $115M of publicly traceable stolen Bitcoin into spendable money without touching infrastructure willing to freeze it. šŸ‘‰ Stealing crypto is one problem. Laundering nine figures on a public blockchain is another.

    Text
    Views7.05K
    Forwards2
    Reactions396
    Comments—
  5. 05
    Views6.86K
    Forwards1
    Reactions352
    Comments—

All posts of CRYPTO ROAST