Chainalysis tied the $387 million Bitget hack to North Korea-linked hackers, saying it pushed their 2026 crypto theft past $1 billion. Its AI cut more than 20 hours of tracing to minutes, while the bill falls on a Bitget user fund the exchange puts above $464 million.
Perspective Coverage
3 publishers
- Builder
- Builder 32%
- Operator
- Operator 41%
- Investor
- Investor 27%
Reality
- Evidence70
- Adoption25
- Hype gap+35
- Incentives60
- Confidence65
Two Safe multisigs lost up to $310K after an attacker impersonated a Safe to get past FlashLoopAdapter, an Aave leverage add-on the owners had enabled. Aave and Safe's core code held, so the loss fell on owners who let a module move funds without signatures.
Perspective Coverage
3 publishers
- Builder
- Builder 38%
- Operator
- Operator 37%
- Investor
- Investor 25%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+12
- Incentives35
- Confidence72
Scammers ran a working copy of Dunamu's unlaunched GIWA network on its reserved chain ID 9134 and drained 766.25 ETH from users. The ID got through an exchange's listing checks, so a matching network ID is now weak evidence that a chain is the real one.
Perspective Coverage
3 publishers
- Builder
- Builder 38%
- Operator
- Operator 40%
- Investor
- Investor 22%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+12
- Incentives60
- Confidence70
Bitget CEO Gracy Chen doubts much of the $387.5 million stolen via a backend tied to a third-party security vendor will come back. So far about 0.2% of the loss has been frozen, so the exchange itself is paying for an outsourced security flaw.
Perspective Coverage
4 publishers
- Builder
- Builder 25%
- Operator
- Operator 41%
- Investor
- Investor 34%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence70
Bitget says attackers may have used a flaw in a third-party security product to get internal credentials and forge $388 million of withdrawals. The account puts vendor software that can reach a withdrawal system inside an exchange's counterparty risk, alongside its own wallet controls.
Publishers:bitget.com · cointelegraph.com Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence50
Bitget says attackers stole $387.5 million after exploiting zero-days in two third-party security appliances. Investigators say the appliances' privileged access led the attacker to its production wallet server.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence60
Bitget customers pulled about $463 million in the first 24 hours after withdrawals reopened, more than the $388 million hackers stole on September 24. The protection fund covers the theft with about $76 million to spare, so the withdrawals now test whether the $5.7 billion left in reserves matches what Bitget owes customers.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+12
- Incentives58
- Confidence58
Bitget lost $387.5 million after attackers inside its wallet backend falsified transaction data that its own authorization process then approved. Its CEO says the private keys stayed safe, so the failure sat in the step between approval and signature.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence60
Bitget said a flaw in a third-party security product gave an attacker the internal credentials used to take about $388 million on September 24. With the product unnamed and no fix confirmed, other companies running it cannot yet check their own exposure.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence45
Bitget CEO Gracy Chen said the exchange's $387.5 million breach ran through a vulnerability in a third-party security product that gave attackers internal credentials to sign off fraudulent withdrawals. The loss was about 83% of its $464 million Protection Fund.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives70
- Confidence60
Bitget says suspected North Korean attackers took $351.6 million from its hot and warm wallets by spoofing the transaction data that triggers its signing process. Its $464 million user protection fund, held in bitcoin, covers the loss.
Perspective Coverage
10 publishers
- Builder
- Builder 27%
- Operator
- Operator 42%
- Investor
- Investor 31%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence60
Bitget CEO Gracy Chen publicly asked THORChain to refuse service to the wallets that took $387.5 million, after Circle and Tether stopped nearly $318,000. Much of the rest now depends on a no-KYC swap protocol that has declined to block stolen funds in earlier hacks, including its own.
Perspective Coverage
3 publishers
- Builder
- Builder 38%
- Operator
- Operator 40%
- Investor
- Investor 22%
Reality
- Evidence57
- Adoption44
- Hype gap+12
- Incentives68
- Confidence55
Bitget now puts its September breach at $387.5 million, and AMLBot estimates $343 million of it sat untouched in 13 attacker wallets on Sept. 25. The phased withdrawals due from Sept. 28 are the better guide to whether customer money is safe.
Perspective Coverage
15 publishers
- Builder
- Builder 25%
- Operator
- Operator 43%
- Investor
- Investor 32%
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence62
Bitget says attackers took over a wallet backend system and fed its authorization process spoofed data, moving out $387.5 million without stolen keys. For teams running payouts, the data an approver trusts now belongs on the same review list as the keys.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 40%
- Investor
- Investor 37%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+18
- Incentives62
- Confidence60
Bitget says attackers took over a wallet backend, faked transaction data and got the exchange's own authorization process to move $351.6 million out. No key was reported stolen, so the failure is in where the approvers got their facts.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence50
SlowMist says its evidence for the iPhone Safari attack on crypto wallet keys covers iOS 18.4 to 18.6.2 and that it has confirmed no theft victim. The firm calls this week's iOS 13 to 26.5 warnings preliminary and still tells iPhone users to install security updates.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+45
- Incentives
- Insufficient
- Confidence50
Blockchain security firm SlowMist says an active exploit chain walks from a Safari page to kernel access and the iOS Keychain on everything from iOS 13 to 26.5, while Apple's patches, by the same account, reach 26.3.
Reality
- Evidence30
- Adoption22
- Hype gap+38
- Incentives66
- Confidence34
Roughly $2 million left Fetch.ai and NuNet on a valid signature, with the token contracts themselves unbroken. The split between the FET drained and the NTX minted decides how much of it the attacker can collect.
Reality
- Evidence64
- Adoption58
- Hype gap+24
- Incentives60
- Confidence58
Four security firms classified the $3.5 million Nostra Finance loss as oracle price manipulation. The remedies the write-up lists are listing-policy parameters: a borrow cap below free float, an isolation flag, a deviation bound.
Reality
- Evidence52
- Adoption42
- Hype gap+15
- Incentives55
- Confidence45
A BridgeV2 flaw let an attacker mint about 2^62 unbacked syBTC, of which 4.39 WBTC got sold before Blockaid flagged it. Symbiosis has halted BTC routing and recovered 15 BTC into a multisig wallet.
Reality
- Evidence58
- Adoption62
- Hype gap+38
- Incentives66
- Confidence61