Bitget Hackers' $700K Loss Highlights Need for Automated Cross-Chain Checks
A recent script error has left hackers involved in the $387.5 million Bitget hack with a significant loss of around $700,000. The error occurred when automated transfers sent USDC and ETH to Chainflip deposit channels on the wrong blockchain networks. One receiving address has been blacklisted by Circle, which may lock the USDC permanently.
The two transfers, made seconds apart, mixed up Ethereum and Arbitrum in opposite directions. The stuck ETH on Arbitrum lacks a sweep contract, leaving technical solutions as the only possible retrieval route. AMLBot reported that the errors highlight the urgent need for automated cross-chain checks to prevent future fund misrouting.
Chainflip is a decentralized cross-chain swap protocol that exchanges native assets across multiple blockchain networks. To start a swap, a user opens a deposit channel, a temporary address assigned to one asset on one specific blockchain. Funds sent to that address on any other chain are not recognized by the protocol.
The pattern of the mistakes fits earlier observations from MistTrack, which reported that operators were placing automated CoW Protocol orders with pre-set Chainflip deposit addresses as recipients to move Bitget proceeds toward Bitcoin. The script error that led to the loss is likely due to a configuration error in which the two networks were swapped.