Bitget Hack Exposes Security Weakness in Transaction-Signing Process
The recent $387.5 million hack of Bitget did not involve stolen private keys but rather an exploitation of the exchange's transaction-signing 'trust chain', according to security firm GoPlus.
This means that attackers were able to make fraudulent transfers appear legitimate by manipulating information before it reached Bitget's signing system, which continued to operate as designed.
The hack occurred on September 24 and affected multiple blockchains, including Ethereum and other EVM networks, XRP Ledger, Zcash, and TRON. Affected assets included XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, and TRX.
GoPlus estimates that the main fund-drain window lasted approximately two hours and 25 minutes, with the largest wave transferring roughly $185 million in about one minute. This raises a second security question: why automated controls did not halt subsequent transactions after abnormal transfers began.