Daily
Desk brief
2026-09-25 · 8 high-impact headlines
Market cap
+0.80%
71
Greed
Headlines
- OdailyBreaking: North Korean hackers strike again, Bitget hot wallet loses over $350 million
- cointelegraph.es · Google NewsLa CFTC actualiza las directrices sobre activos tokenizados y registros en blockchain tras una votación fallida - cointelegraph.es
- Odaily24H Trending Coins and News | Google Set to Release Gemini 4; US 10-Year and 30-Year Treasury Yields Both Hit Highest Since 2007 (September 25)
- mx.advfn.com · Google NewsBTCUSD - CFTC updates guidance on tokenized assets, blockchain records after failed vote - mx.advfn.com
- FXStreet · Google NewsPrevisión del precio de Ethereum: Las ballenas reanudan la acumulación mientras los flujos de los ETF siguen siendo sólidos - FXStreet
- Cryptonews.net · Google NewsLas empresas de materias primas de EE.UU. pueden invertir en activos tokenizados y utilizar registros en blockchain: CFTC - Cryptonews.net
- mx.advfn.com · Google NewsBTCUSD - Bitcoin price steadies, ONDO rallies as US Treasury yields hit 2007 highs - mx.advfn.com
- cointelegraph.es · Google NewsSequans vende los 314 BTC restantes y abandona su tesorería en Bitcoin - cointelegraph.es
Flash
- Specter: Bitget attacker may be North Korean hacker group Lazarus Group, stolen fund path linked to previous AFX hack funds.BlockBeats news, September 25, according to on-chain detective Specter monitoring, by tracking on-chain fund flows, the North Korean hacker group Lazarus Group may be the mastermind behind the Bitget theft incident. This incident is linked to the AFX attack that occurred in July this year, which caused approximately $24 million in losses and was attributed to TraderTraitor, associated with Lazarus Group. After the stolen XRP from Bitget was cross-chained, the relevant fund paths can be directly linked to the stolen funds in the AFX attack.
- The total value of assets stolen from Bitget amounts to approximately $357 million, including about 103 million XRP and 31,890 ETH.BlockBeats news, September 25th, according to Lookonchain monitoring, the total value of assets stolen in the Bitget attack amounted to approximately $356.86 million. Among them, 102,926,478 XRP ($157.48 million) and 31,890 ETH ($85.75 million) were the main portions of the stolen assets. The remaining stolen assets include 34,751,168 USDT ($34.75 million), 21,056,725 USDC ($21.06 million), 19,668,852 USD₮0 ($19.67 million), 3,000 XAUt ($12.82 million), 12,719 BNB ($9.88 million), 821,012 AVAX ($8.38 million), and 20,593,377 TRX ($7.07 million).
- Bitget CEO suspects North Korean hackers behind the attack, says IP clues match VPN characteristics.BlockBeats news, September 25: In a live Q&A regarding the platform security incident, Bitget CEO Gracy Chen stated that preliminary investigations found that some relevant IP addresses match VPN services used by a certain North Korean hacker group, and the attack pattern is also similar to previous actions by North Korean hackers, so the involvement of this group in the attack involving approximately $351.6 million cannot be ruled out. However, the relevant attribution is still in the preliminary investigation stage. Gracy Chen stated that Bitget currently does not believe this incident is an insider job. The attackers directly breached the platform's systems and transferred funds, did not forge user withdrawal requests, and did not obtain the private keys of cold wallets or hot wallets. Investigators are still confirming the specific affected systems and the attackers' method of intrusion.
- SlowMist: Bitget hacker address holds approximately $157 million worth of XRP.BlockBeats news, September 25: SlowMist MistTrack has updated the Bitget hacker wallet addresses, adding 7 new Ripple network addresses marked, with a total balance of approximately 102,926,478 XRP, equivalent to about $157 million. Additionally, it includes 11 EVM addresses and 1 TRON address. Among them, the EVM addresses collectively hold approximately 67,980.25 ETH, 5,896.58 BNB, 495.625 WETH, 218,022.9 USDT, and 99,989.9 USDC; the TRON address holds approximately 20,593,376.5 TRX.
- Bitget CEO: Some stolen funds may be recoverable, withdrawals will only resume after system security is confirmed.BlockBeats news, September 25: Bitget CEO Gracy Chen stated during a livestream regarding the platform's attack incident that some of the affected funds may have a chance of being recovered. Regarding the resumption of withdrawals, Gracy Chen said that Bitget needs to first thoroughly investigate the related issues, and the technical team is currently advancing system repairs and security enhancements. Only after confirming the system's security and ensuring that resuming withdrawals will not lead to further attacks by hackers will the platform reopen the withdrawal function. She stated that once a clear time window for resuming withdrawals is established, users will be informed immediately and an announcement will be issued. At present, no specific time can be promised, because the platform does not wish to make promises it cannot fulfill.
- Bitget CEO Discloses Initial Attack Path: May Involve Third-Party Software Supply Chain AttackBlockBeats news, September 25: Bitget CEO Gracy Chen stated during a livestream regarding the platform attack incident that the security team is currently focused on identifying the root cause and resolving the issue. Based on information available at this stage, the incident bears some resemblance to a supply chain attack: attackers may have compromised a third-party tool frequently used by Bitget, thereby affecting a critical backend system of the wallet service. Gracy Chen said that the compromised service forged transfer information and invoked the signing machine to transfer out funds. This incident is not a private key leak; based on the current investigation, the possibility of an insider job is also relatively low. However, she stated that the final attack path still requires further confirmation by the security team. She added that hacker attacks are usually not of a single type, and a single attack may simultaneously use a combination of two or three out of six to seven types of methods. Citing the previous attack incident on Bybit as an example, she said that incident involved both the signature authorization process and a supply chain attack on the Safe multisig page it used. Common attack methods targeting trading platforms also include private key leaks, smart contract vulnerabilities, insider jobs, and social engineering attacks, among others.
- Bitget CEO: This platform attack was not due to a key leak, no exact time for withdrawal resumption yet.BlockBeats news, September 25: Bitget CEO Gracy Chen stated in a public livestream regarding the platform's attack incident that the platform is currently preparing to resume withdrawals, but there is no exact timeline for restoration yet. Bitget's internal and external technical teams are simultaneously identifying the issue and developing solutions, hoping to restore related services as soon as possible. Gracy Chen said that the attack method in this theft incident differs from security incidents previously occurring on some trading platforms. According to the current investigation, the hackers did not carry out the attack through key leakage, but bypassed some systems and initiated withdrawals through the system. She stated that key leakage is the worst-case scenario, but this incident is not that. Due to the involvement of multiple currencies and blockchain networks in this incident, Bitget is temporarily unable to directly open withdrawals and needs to restore them after confirming that funds are completely safe and formulating a more reliable handling plan. Gracy Chen said that the platform has currently completed comprehensive loss containment, and no further attacks will occur; withdrawals will be reopened once the security issue is handled with greater certainty.
- The Bitget attacker has converted most of the stolen funds on EVM chains into 67,982 ETH, approximately $183 million.BlockBeats news, September 25, according to Lookonchain monitoring, Bitget was hacked, with approximately $351.6 million in assets stolen. The hacker has already converted most of the stolen funds on EVM chains into 67,982 ETH, worth about $183 million.