$388 Million Bitget Exploit: Attacker Tested Risk Controls Before Drain
The Bitget exchange has been hit by a massive $388 million exploit, and according to CEO Gracy Chen, the attacker tested risk controls with two small transfers half an hour before draining the exchange.
The first unauthorized transfers happened at 6:31 p.m. UTC on Sept. 24, including 0.184 ETH from an Ethereum hot wallet and 193 TRX from a Tron hot wallet, both of which sat below the exchange's risk-control threshold and triggered no system alerts.
About 30 minutes later, the attacker began making larger transfers, totaling about $361 million in cryptocurrency across multiple chains, including Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism, and Avalanche.
Bitget's reconciliation system detected a significant discrepancy within seven minutes of the first large transfer, at 7:05 p.m., and its risk system blocked platform-wide user-initiated withdrawals. However, the attacker had already gained access to an internal management system by exploiting a zero-day vulnerability in a third-party security product.