Daily
Desk brief
2026-09-25 · 8 high-impact headlines
Market cap
+0.86%
71
Greed
Headlines
- CointelegraphBitget CEO suspects North Korea behind $352M hack, citing IP clues
- Investing.com · Google NewsBitcoin cuts losses, remains muted amid rising oil and yields, hawkish Fed signals - Investing.com
- CryptoBriefingGold prices dip amid Iran tensions, Fed rate hike expectations
- ForkastDarktrace Proved That AI Agent Tools Can Be Hijacked Through Their Own Memory — And the Fix Is Out of Your Hands
- BeInCryptoAs Yields Break Records, Tom Lee Sees an Upside, But Only for the Strongest
- HackerNoon · Google NewsWhat is a DAG-Based Cryptocurrency - and Why It Matters - HackerNoon
- CointelegraphAsia dominates Crypto Adoption Index, Bitget’s $351M hack: Asia Express
- The DefiantPaxos Labs Launches PAXGy, Adding Lending Yield to Tokenized Gold
Flash
- Bitget CEO suspects North Korean hackers behind the attack, says IP clues match VPN characteristics.BlockBeats news, September 25: In a live Q&A regarding the platform security incident, Bitget CEO Gracy Chen stated that preliminary investigations found that some relevant IP addresses match VPN services used by a certain North Korean hacker group, and the attack pattern is also similar to previous actions by North Korean hackers, so the involvement of this group in the attack involving approximately $351.6 million cannot be ruled out. However, the relevant attribution is still in the preliminary investigation stage. Gracy Chen stated that Bitget currently does not believe this incident is an insider job. The attackers directly breached the platform's systems and transferred funds, did not forge user withdrawal requests, and did not obtain the private keys of cold wallets or hot wallets. Investigators are still confirming the specific affected systems and the attackers' method of intrusion.
- SlowMist: Bitget hacker address holds approximately $157 million worth of XRP.BlockBeats news, September 25: SlowMist MistTrack has updated the Bitget hacker wallet addresses, adding 7 new Ripple network addresses marked, with a total balance of approximately 102,926,478 XRP, equivalent to about $157 million. Additionally, it includes 11 EVM addresses and 1 TRON address. Among them, the EVM addresses collectively hold approximately 67,980.25 ETH, 5,896.58 BNB, 495.625 WETH, 218,022.9 USDT, and 99,989.9 USDC; the TRON address holds approximately 20,593,376.5 TRX.
- Bitget CEO: Some stolen funds may be recoverable, withdrawals will only resume after system security is confirmed.BlockBeats news, September 25: Bitget CEO Gracy Chen stated during a livestream regarding the platform's attack incident that some of the affected funds may have a chance of being recovered. Regarding the resumption of withdrawals, Gracy Chen said that Bitget needs to first thoroughly investigate the related issues, and the technical team is currently advancing system repairs and security enhancements. Only after confirming the system's security and ensuring that resuming withdrawals will not lead to further attacks by hackers will the platform reopen the withdrawal function. She stated that once a clear time window for resuming withdrawals is established, users will be informed immediately and an announcement will be issued. At present, no specific time can be promised, because the platform does not wish to make promises it cannot fulfill.
- Bitget CEO Discloses Initial Attack Path: May Involve Third-Party Software Supply Chain AttackBlockBeats news, September 25: Bitget CEO Gracy Chen stated during a livestream regarding the platform attack incident that the security team is currently focused on identifying the root cause and resolving the issue. Based on information available at this stage, the incident bears some resemblance to a supply chain attack: attackers may have compromised a third-party tool frequently used by Bitget, thereby affecting a critical backend system of the wallet service. Gracy Chen said that the compromised service forged transfer information and invoked the signing machine to transfer out funds. This incident is not a private key leak; based on the current investigation, the possibility of an insider job is also relatively low. However, she stated that the final attack path still requires further confirmation by the security team. She added that hacker attacks are usually not of a single type, and a single attack may simultaneously use a combination of two or three out of six to seven types of methods. Citing the previous attack incident on Bybit as an example, she said that incident involved both the signature authorization process and a supply chain attack on the Safe multisig page it used. Common attack methods targeting trading platforms also include private key leaks, smart contract vulnerabilities, insider jobs, and social engineering attacks, among others.
- Bitget CEO: This platform attack was not due to a key leak, no exact time for withdrawal resumption yet.BlockBeats news, September 25: Bitget CEO Gracy Chen stated in a public livestream regarding the platform's attack incident that the platform is currently preparing to resume withdrawals, but there is no exact timeline for restoration yet. Bitget's internal and external technical teams are simultaneously identifying the issue and developing solutions, hoping to restore related services as soon as possible. Gracy Chen said that the attack method in this theft incident differs from security incidents previously occurring on some trading platforms. According to the current investigation, the hackers did not carry out the attack through key leakage, but bypassed some systems and initiated withdrawals through the system. She stated that key leakage is the worst-case scenario, but this incident is not that. Due to the involvement of multiple currencies and blockchain networks in this incident, Bitget is temporarily unable to directly open withdrawals and needs to restore them after confirming that funds are completely safe and formulating a more reliable handling plan. Gracy Chen said that the platform has currently completed comprehensive loss containment, and no further attacks will occur; withdrawals will be reopened once the security issue is handled with greater certainty.
- The Bitget attacker has converted most of the stolen funds on EVM chains into 67,982 ETH, approximately $183 million.BlockBeats news, September 25, according to Lookonchain monitoring, Bitget was hacked, with approximately $351.6 million in assets stolen. The hacker has already converted most of the stolen funds on EVM chains into 67,982 ETH, worth about $183 million.
- Whale 'First Set 10 Big Targets': If BTC falls below $79,000, will gradually close longs; if it quickly surges to around $100,000, plans to short as a hedge.BlockBeats news, September 25: Whale "First Set 10 Big Targets" (@jasonleo) posted an update on Bitcoin trading strategy, stating that at the beginning of this round of BTC's rebound from the $58,000 bottom, he firmly targeted $100,000, but due to a failed attempt to judge the top midway, he missed out on a significant portion of profits. His current long position has an average entry level of approximately $78,000. Regarding subsequent operations, JasonLeo stated that if BTC falls below $79,000 again, he will begin to gradually close long positions; if it quickly rises to $100,000 in the short term, he will consider establishing some defensive short positions in the $98,000 to $105,000 range to hedge against weekly-level correction risks. If BTC stabilizes above $108,000 on the daily chart, the above short position logic will be invalidated. If BTC does not directly surge, but instead engages in sufficient contention in the $80,000 to $100,000 range, he will consider taking defensive operations in the $115,000 to $125,000 range.
- Some Bitget hot wallets experienced abnormal transfers involving approximately $351.6 million, while cold wallets and the vast majority of platform assets were unaffected.BlockBeats news, September 25: Bitget Greater China head Xie Jiayin stated in a post that at 2:31 AM Beijing time on September 25, Bitget's security system detected abnormal transfers from some hot wallets, and the security team immediately activated its emergency response mechanism. The platform's preliminary assessment indicates that the incident involves approximately $351.6 million, and the specific cause is still under investigation. Bitget stated that its cold wallets and the vast majority of the platform's assets remain intact and were not affected by this incident, and that user account balances are accurate and assets are protected. The loss amount is fully covered by the Bitget User Protection Fund, which currently exceeds $464 million. Minutes after the incident occurred, Bitget established an emergency response team. The relevant abnormal transfer addresses have been flagged and reported, and law enforcement agencies and on-chain security firms have been notified to intervene in the investigation. For the sake of fund security, the platform has temporarily suspended withdrawal functions, which will be restored in an orderly manner after security verification is completed; deposit and trading functions remain operational. Bitget said it will subsequently publish updates on the incident on an hourly basis and plans to release a complete incident report within 24 hours, including root cause analysis and corrective measures. Before the investigation conclusions are clear, the platform will not speculate on the specific attack method. Earlier on-chain monitoring showed that approximately $180 million to $183 million in assets were transferred out from multiple addresses tagged as Bitget, involving assets such as ETH, BNB, AVAX, USDT0, USDC, USDT, and XAUT. After the funds were consolidated into one main address, they were then dispersed to at least 6 addresses. Among them, a newly created address used 19.67 million USDT0 from a Bitget hot wallet to buy 7,111 ETH through UniswapX and 1inch Fusion in about 6 minutes, with some execution prices about 5% higher than the spot market. Bitget CEO Gracy Chen has held a public livestream regarding this matter, but as of now, the official side has not yet released a written version of new investigation conclusions.