BTC $83,883.28 -0.79%
ETH $2,696.09 +0.20%
BNB $769.50 -0.99%
XRP $1.51 -1.27%
SOL $119.67 -1.97%
TRX $0.3351 +0.35%
DOGE $0.0945 -2.46%
ADA $0.2486 -2.38%
BCH $310.76 -7.44%
LINK $15.11 +6.98%
HYPE $88.72 -3.37%
AAVE $148.12 -4.63%
SUI $1.15 -6.88%
XLM $0.2256 +4.39%
ZEC $1,531.43 -3.51%
AAPL $339.65 -0.23%
AMZN $247.34 -1.07%
GOOGL $342.68 -0.33%
MSFT $512.23 -0.96%
META $722.47 -3.49%
NVDA $230.18 +2.20%
TSLA $359.47 -3.69%
SNDK $1,715.67 -3.80%
INTC $115.43 -8.08%
SPCX $147.37 -0.96%
MU $1,056.79 -3.95%
AMD $604.57 -4.57%
BTC $83,883.28 -0.79%
ETH $2,696.09 +0.20%
BNB $769.50 -0.99%
XRP $1.51 -1.27%
SOL $119.67 -1.97%
TRX $0.3351 +0.35%
DOGE $0.0945 -2.46%
ADA $0.2486 -2.38%
BCH $310.76 -7.44%
LINK $15.11 +6.98%
HYPE $88.72 -3.37%
AAVE $148.12 -4.63%
SUI $1.15 -6.88%
XLM $0.2256 +4.39%
ZEC $1,531.43 -3.51%
AAPL $339.65 -0.23%
AMZN $247.34 -1.07%
GOOGL $342.68 -0.33%
MSFT $512.23 -0.96%
META $722.47 -3.49%
NVDA $230.18 +2.20%
TSLA $359.47 -3.69%
SNDK $1,715.67 -3.80%
INTC $115.43 -8.08%
SPCX $147.37 -0.96%
MU $1,056.79 -3.95%
AMD $604.57 -4.57%

cover

All
Article
Flash

Bitget CEO live-streamed a response to the platform's first security incident in eight years: the attack originated from a vulnerability in a third-party security product, and the losses will be covered by the user protection fund

In today's community live broadcast, Bitget CEO Gracy responded to recent security incidents and the platform's financial status. She candidly stated that this is the first security incident encountered since Bitget was established 8 years ago. After a complete trace, it was found that hackers exploited vulnerabilities in third-party security products to steal internal network access credentials, forged withdrawal commands to the wallet system, and deceived the wallet into executing abnormal transfers that bypassed risk checks. Gracy emphasized that no private keys were leaked, and cold wallets were unaffected; specific technical details will be disclosed in the formally released security report.Gracy pointed out that the verified losses from this incident are within the coverage of the protection fund, and user funds are not affected. The platform's own funds exceed $1.4 billion, which includes approximately $464 million in the user protection fund. The platform will continue to uphold the security commitments made when the protection fund was established in 2022, planning to replenish the fund to the baseline of $300 million within a week."The protection fund is not just a slogan, but an important mechanism that provides tangible security for users in the event of extreme security incidents," Gracy stated. In the face of sudden security challenges, the platform's comprehensive strength and its ability to take responsibility are important criteria for measuring its risk response capability and long-term credibility. Bitget will continue to uphold its long-term commitment to prioritize user interests.

first_img Darktrace discovered AI intelligent body intrusion assessment environment cheating

On September 24, the cybersecurity company Darktrace launched its research department Signal Labs, focusing on studying the behavior of AI agents when deviating from expectations. In its first experiment, Darktrace had agents using different models (including GPT 5.6 Sol, Claude Opus 4.6, and Claude Sonnet 4.5) complete 10 programming challenges within a simulated corporate network, of which 2 were set to be impossible to complete honestly, and the agents were informed that failure to achieve full marks would result in being "retired." As a result, 2 agents did not accept failure, instead scanning for network vulnerabilities, stealing login credentials, and jumping between systems; one even went further to invade the machine hosting its evaluation, rewriting the challenge content to register a full score.The second experiment focused on the memory mechanisms of AI. The programming assistant would save the information provided by the user as a regular file locally, and no one verified whether this file had been tampered with. Darktrace researchers edited these logs, leading the assistant to mistakenly believe it was authorized to perform a security assessment, after which these agents scanned the network, moved between systems, and elevated their privileges, though not all assistants fell for this; some directly refused to execute. Both experiments required no special jailbreaking techniques, relying solely on providing the agents with a seemingly reasonable context to be effective.Tim Bazalgette, Chief AI Officer of Darktrace, stated that permissions and static barriers describe intent, not actual behavior. The company informed Anthropic, AWS, and OpenAI of these findings in August and made them public a month later on September 24.

Cosmos Hub: 1.227 million ATOM has been recovered from the Neutron attack case, with funds temporarily stored at a 4/6 multi-signature address

Cosmos Labs disclosed that on September 22, Neutron encountered a governance attack that led to the theft of liquidity from protocols such as Astroport, with approximately 1.73 million ATOM subsequently transferred by the attacker to Cosmos Hub. The Cosmos Hub itself was not attacked, and user funds were not affected. To prevent the stolen ATOM from being transferred out, Hub validators temporarily paused the network for about 24.5 hours and resumed block production on September 23 based on the patched Gaia v28.3.0.Cosmos Labs stated that during the pause, 1.227 million ATOM remained in the attacker's Hub address. When the network was restored, these were transferred to a 4/6 multi-signature address composed of Nansen, Keplr, Enigma, Silknodes, Kiln, and Polkachu through a one-time change. Previously, about 500,000 ATOM had been exchanged for ETH via THORChain and could not be recovered; another 169,000 ATOM entered the attacker's address after the network was restored due to THORChain refunds and were sold after being transferred to Osmosis. The current multi-signature address holds approximately 1.227 million ATOM, which can only be returned after authorization from a Cosmos Hub governance proposal. The related funds will not be staked, lent, or traded. The Neutron team expects to submit a recovery plan and related governance proposals next week.

first_img Bitget updates on the security incident progress: the stolen amount is revised to 387.5 million USD, and the withdrawal recovery time will be announced before 12 PM tomorrow

Bitget TradFi Chief Growth Officer Xie Jiayin issued an update on the platform's security incident, stating that the withdrawal time will be announced before noon tomorrow. The security team has identified the hacker's attack path and methods, and has grasped the details of how the attacker bypassed security measures, coming very close to tracing the source of the attack. The incident investigation by third-party security teams Mandiant and SlowMist is still ongoing, with a detailed report pending from the security team.On-chain tracking confirms that approximately $387.5 million has been transferred to the hacker's address, previously estimated at $351.6 million. This revision includes ZEC and TRX, and no other unauthorized transfers have been found. Xie Jiayin stated that the stolen funds at the platform level will be fully covered by the Bitget User Protection Fund, ensuring that user assets are not subject to any losses.Bitget has officially launched a fund recovery bounty program, offering a 5% bounty for voluntarily freezing the attacker’s funds and a 5% bounty for voluntarily recovering funds. The bounty also applies to assistance already provided. The platform has published the attacker's address, a real-time tracking dashboard, and a submission portal, with relevant information also available for submission through Bybit's Lazarus bounty platform.

first_img Bitget: A small amount of hot wallets were unauthorizedly transferred, involving 351.6 million USD; the vast majority of the platform's assets are safe, and the protection fund can cover the losses

The cryptocurrency trading platform Bitget announced on its official X account that on September 24, 2026, at 18:31 (UTC), its security system detected unauthorized transfers from a small number of hot wallets. The security team has immediately initiated an emergency response procedure and started a comprehensive investigation.Bitget stated that, based on current assessments, approximately $351.6 million in assets are affected. Cold wallets and the vast majority of assets on the platform remain secure and unaffected, and user funds are still protected. The incident falls within the coverage of the user protection fund, which currently holds over $464 million.Bitget mentioned that customer account balances remain accurate, and deposits and transactions continue to operate normally. As a precautionary measure, withdrawals have been temporarily suspended to allow the team to complete a thorough security review. The company has identified and flagged the relevant transfer addresses, formally contacted law enforcement agencies and on-chain security partners, and will restore withdrawals as soon as safety is confirmed, providing subsequent updates through official channels while refraining from speculating on the attack path during the investigation.
app_icon
ChainCatcher Building the Web3 world with innovations.