Bitget Raises Hack Estimate to $387.5 Million, Withdraws Still Suspended for All Users… | Global Crypto Press | Crypto News Today

fiverr
Ledger


Bitget’s hack just got more expensive, and customers are still waiting for a withdrawal update.

The exchange raised its estimate to $387.5 million in a September 25 update, replacing the earlier $351.6 million figure. It attributed the difference to previously uncounted Zcash and TRON transfers. Bitget said the revision reflects better accounting of the original incident, not another attack. That distinction matters when an already substantial loss grows overnight.

The original alarm came at 18:31 UTC on September 24, according to Bitget’s security notice. The company said only part of its hot and warm wallet infrastructure was affected and its cold wallets remained secure. It paused withdrawals while keeping deposits and trading open. Bitget also said account balances remained accurate. Customers therefore face a separation between what their accounts show and their ability to move those assets elsewhere.

The investigation points beyond stolen keys

CEO Gracy Chen has described a compromise of a backend wallet service, according to Cointelegraph. Her account was that attackers forged transfer information and triggered the authorization-signing process. She said the preliminary investigation did not point to leaked private keys. That would put the weakness in the systems instructing transfers, rather than possession of the keys alone. A complete technical explanation is still important before treating that account as the final root-cause finding.

coinbase

Chen also raised the possibility of North Korean involvement, citing IP and VPN patterns resembling those associated with a North Korean group. That is a preliminary attribution by the exchange’s chief executive. It should not be presented as an independently established identity for the attacker. Mandiant and SlowMist are assisting the investigation, Bitget said. For affected customers, identifying the perpetrators and restoring access are separate problems, even when both are being worked on at once.

A coverage promise still needs an operational recovery

Bitget’s original notice said its User Protection Fund held more than $464 million and covered the incident. That was the exchange’s assurance about its own resources. It does not mean the stolen assets have already been returned. The September 25 update says some funds have been frozen and introduces conditional 5% bounties for eligible freezing or recovery work. Freezing funds and returning them to the exchange are different stages of that process.

Bitget says it has fixed the vulnerability and is validating security before restoring withdrawals. It promises an announcement about withdrawal status or timing by September 26 at 04:00 UTC. That is a deadline for information, not a guaranteed reopening time. The next useful evidence is a clear service update followed by withdrawals actually working again. Until then, the larger loss estimate and the coverage pledge should be read alongside the access restrictions customers still face.

—————

Author: Ren Nakamura
Asia Newsroom
Breaking Crypto News



Source link

Coinmama

Be the first to comment

Leave a Reply

Your email address will not be published.


*