Tag: Bitget hack

  • 18 Altcoins Face Massive Token Unlocks This Week: Day-by-Day, Hour-by-Hour Schedule

    18 Altcoins Face Massive Token Unlocks This Week: Day-by-Day, Hour-by-Hour Schedule

    Key Highlights

    • A packed schedule of token unlocks spans September 28 through October 4, 2026, with DoubleZero (2Z) releasing 46.78% of its market value—the largest proportional unlock of the week.
    • Major unlocks from Bitway (BTW) and Ethena (ENA) each exceed $25 million in absolute value, while Bitcoin gained approximately 3.90% last week despite macro headwinds and a $300 million-plus Bitget exchange hack.
    • All unlock times are listed in UTC+3 (Turkish time) as compiled by Bitcoinsistemi.com, covering 18 projects ranging from AI-focused Gensyn to infrastructure plays like EigenCloud and Lagrange.

    Crypto Market Digests Macro Pressure While Token Unlock Calendar Looms Large

    The cryptocurrency sector navigated a volatile seven-day period marked by conflicting signals: rising expectations for a near-term Federal Reserve interest rate hike and a significant security breach at Bitget, a major centralized exchange, which suffered losses exceeding $300 million. Despite these bearish catalysts, Bitcoin defied gravity, appreciating roughly 3.90% over the week. As traders assess the damage from the Bitget exploit and parse central bank rhetoric, the coming days present a fresh technical challenge—a dense cluster of token unlocks across nearly twenty altcoin projects that could inject substantial selling pressure into already fragile order books.

    Weekly Unlock Schedule: High-Profile Releases Dominate Early October

    Data aggregated by Bitcoinsistemi.com outlines a daily cadence of vesting events beginning Monday, September 28, and running through Saturday, October 4. All timestamps reference UTC+3 (Turkish time). The week opens with dual unlocks for Sign ($2.11 million, 13.02% of market cap) and corn (CORN) ($1.59 million, 11.69%) at 03:00. Tuesday, September 29, accelerates activity with four projects: Falcon Finance (FF) releases $32.34 million (10.58%) at 03:00, followed by Anoma (XAN) at $2.60 million (8.10%), Midnight (NIGHT) at $2.54 million (8.59%), and Gensyn (AI) at $1.93 million (6.88%) at 09:00.

    Mid-Week Sees Infrastructure and Gaming Tokens Unlock

    Wednesday, September 30, brings BSquared Network (B2) ($1.70 million, 4.92%) and GUNZ (GUN) ($1.02 million, 9.44%) at 03:00. Thursday, October 1, features a quartet of unlocks at 03:00: Kite (KITE) ($15.95 million, 4.35%), Audiera (BEAT) ($1.13 million, 3.24%), Swarm Network (TRUTH) ($1.42 million, 5.03%), and a late-morning release for EigenCloud (EIGEN) at 11:00 AM totaling $9.95 million (3.97%).

    Friday Concentrates Largest Absolute and Proportional Unlocks

    Friday, October 2, represents the peak of the schedule. DoubleZero (2Z) leads with a staggering $113.27 million unlock—representing 46.78% of its market capitalization—at 03:00. Simultaneously, Quack AI (Q) releases $7.67 million (5.38%). At 09:00, Bitway (BTW) unlocks $105.67 million (3.62% of its $2.91 billion valuation), followed two hours later by Ethereum (ENA)—listed in the source as Ethereum with ticker ENA, widely recognized as the Ethena protocol’s governance token—releasing $25.33 million (0.93% of its $2.71 billion market cap). The week concludes with Impossible Cloud Network (ICNT) at $1.53 million (6.03%) on October 3 and Lagrange (LA) at $2.14 million (15.04%) on October 4, both at 03:00.

    Why This Matters: Liquidity Events Test Market Depth Amid Macro Uncertainty

    The convergence of these unlocks arrives at a precarious moment. The Bitget hack—one of the largest exchange exploits in recent memory—has shaken custody confidence, while hawkish Fed signals threaten to drain global risk appetite. Large proportional unlocks, particularly DoubleZero’s near-47% supply expansion, historically correlate with short-term price depreciation as early investors and team allocations hit circulating supply. Conversely, Bitcoin’s resilience last week suggests bids may absorb incremental sell pressure if macro narratives stabilize. Market participants should monitor on-chain exchange inflows for unlocked tokens and watch Bitcoin’s correlation with equities as a barometer for broader risk sentiment heading into the final quarter of 2026.

    Frequently Asked Questions

    Which token unlock represents the largest proportional supply increase this week?
    DoubleZero (2Z) unlocks 46.78% of its market capitalization ($113.27 million) on October 2 at 03:00 UTC+3, the highest percentage release on the schedule.
    What were the two main macro catalysts affecting crypto markets last week?
    The increased probability of a Federal Reserve interest rate hike and a hacking attack on the Bitget exchange resulting in losses exceeding $300 million dominated headlines.
    How did Bitcoin perform during the turbulent week prior to these unlocks?
    Despite negative macro catalysts, Bitcoin’s price rose approximately 3.90% over the last week.
  • Bitget Hacker Moves $83 Million in Stolen XRP That Ripple Cannot Freeze

    Bitget Hacker Moves $83 Million in Stolen XRP That Ripple Cannot Freeze

    Key Highlights

    • Circle and Tether froze approximately $320,000 in USDC and USDT stablecoins linked to the Bitget exchange hack, leveraging built-in blacklist controls.
    • The attacker moved roughly 54 million XRP from the original five holding wallets overnight, reducing the balance from 70 million to 49 million tokens in eight hours.
    • XRP traded near $1.54 on Saturday, down 4% in 24 hours but retaining a 9% weekly gain, with the stolen haul valued at approximately $160 million.

    Stablecoin Issuers Intervene to Block Illicit Funds

    Circle and Tether, the operators behind the leading dollar-pegged stablecoins USDC and USDT, have taken swift action to mitigate the fallout from the massive Bitget crypto exchange breach. The companies froze roughly $320,000 worth of stablecoins associated with the hacker’s wallet addresses. Both tokens possess programmable controls that allow the issuers to blacklist specific addresses, effectively preventing the frozen assets from being transferred or redeemed. This intervention highlights the centralized enforcement layer that exists within major fiat-backed stablecoins, a feature often cited by regulators and critics alike.

    Attacker Accelerates XRP Distribution Across Wallets

    On-chain data shows the perpetrator significantly sped up the movement of stolen XRP tokens during the early hours of Saturday. At 04:32 UTC, approximately 70 million XRP remained in the original five accounts identified as the initial holding points for the stolen funds. Roughly eight hours later, that aggregate balance had dropped to 49 million, indicating a rapid dispersal strategy. The transfers reveal the attacker distributing the assets across a growing number of wallets, a common tactic to obfuscate the trail and complicate recovery efforts.

    Transaction Patterns Suggest Automated Scripting

    Analysis of the transfer flows shows certain payments replicating routes previously used by the first wallet. In one notable instance, an attempted transfer of about 521,000 XRP failed because the sending account lacked sufficient funds. Approximately one hour later, a second wallet executed an identical transfer of 521,000 XRP to the same intended recipient. This pattern suggests the use of automated scripts or predetermined routing logic rather than purely manual intervention, with the attacker managing multiple wallets in parallel to drain the holdings.

    Market Absorbs Supply Overhang Amid Price Resilience

    Despite the significant movement of stolen funds, XRP markets displayed relative stability on Saturday. The token traded around $1.54, representing a 4% decline over the preceding 24 hours but maintaining a weekly gain of approximately 9%, according to data from CoinGecko. At the prevailing price, the original XRP haul—estimated at roughly 100 million tokens based on the 54 million moved and 49 million remaining—was worth approximately $160 million. That figure equates to roughly 4% of XRP’s reported $4.4 billion in daily trading volume, suggesting the market possesses sufficient liquidity to absorb potential sell pressure, though actual price impact will depend on the depth of buy orders at the time of execution.

    Why This Matters

    The Bitget hack and subsequent fund movements underscore several critical dynamics in the crypto ecosystem. First, the ability of Circle and Tether to freeze assets demonstrates the “off-switch” capability inherent in centralized stablecoins, providing a rapid response mechanism for illicit flows that does not exist for native blockchain assets like XRP. Second, the speed and sophistication of the XRP laundering—evidenced by automated multi-wallet distribution and retry logic—illustrates the operational maturity of modern cybercriminal groups targeting exchanges. Finally, the market’s muted price reaction reflects XRP’s deep liquidity and the market’s growing desensitization to large-scale exchange breaches, though the ultimate impact hinges on whether the attacker opts for rapid liquidation via decentralized exchanges or slower over-the-counter channels.

    Frequently Asked Questions

    How much XRP was stolen in the Bitget hack?

    Based on on-chain analysis, the original haul held in five primary wallets totaled approximately 119 million XRP (70 million remaining at 04:32 UTC plus 49 million moved subsequently). At Saturday’s price of $1.54, the total value was roughly $160 million.

    Can Circle and Tether freeze XRP tokens?

    No. Circle and Tether can only freeze assets issued on their respective contracts—USDC and USDT. XRP is a native asset on the XRP Ledger and does not have a centralized freeze function. The $320,000 freeze applied only to stablecoin balances held in the hacker’s wallets.

    Will the stolen XRP dump crash the price?

    The stolen amount represents about 4% of XRP’s reported daily trading volume ($4.4 billion). While a sudden market sale could cause short-term slippage, the depth of the order books across major exchanges suggests the market could absorb the supply without a catastrophic price collapse, especially if distributed over time or via OTC desks.

  • Circle and Tether Freeze Hacker Wallet After Massive Bitget Crypto Heist

    Circle and Tether Freeze Hacker Wallet After Massive Bitget Crypto Heist

    Key Highlights

    • Circle and Tether froze approximately $318,000 in stablecoins (218,023 USDT and 99,990 USDC) held in a wallet labeled “Bitget Exploiter 8” on Etherscan, linked to Thursday’s $351.6 million Bitget exchange hack.
    • The frozen assets represent a small fraction of the total haul; blockchain analytics firm MistTrack confirms other exploiter addresses still hold over 63,000 ETH (valued at roughly $200 million+), which no issuer can freeze because they are native ether, not permissioned stablecoins.
    • Bitget CEO Gracy Chen stated the breach stemmed from a compromised backend system in the exchange’s wallet infrastructure that allowed attackers to spoof transaction data and trigger the authorization process, ruling out a private key compromise. She confirmed the exchange’s $464 million user protection fund covers the loss.

    Rapid Stablecoin Freeze by Circle and Tether

    Circle moved swiftly to blacklist the Ethereum address tagged as “Bitget Exploiter 8” at 05:00 UTC on Friday, according to onchain data. The wallet contained 170.47 ETH, 218,023 USDT, and 99,990 USDC at the time of the freeze. Blockchain security firm MistTrack reported that Tether subsequently banned the same wallet, effectively immobilizing the USDT and USDC balances—totaling roughly $318,000. While the action demonstrates the ability of centralized stablecoin issuers to intervene when funds hit permissioned tokens, the vast majority of the stolen assets remain in ether, which operates without a central freeze mechanism.

    Breach Mechanics: Backend Compromise, Not Private Key Theft

    Bitget CEO Gracy Chen provided a technical post-mortem, explaining that attackers compromised a backend system in the exchange’s wallet infrastructure, spoofed transaction data and triggered its authorization process to move funds out. Chen explicitly ruled out a private key compromise, distinguishing this incident from typical hot-wallet private key thefts. She added that Bitget’s user protection fund, which holds over $464 million, covers the loss, aiming to reassure users that deposits remain fully backed.

    Contrast with April’s Drift Protocol Incident

    The response stands in sharp contrast to Circle’s handling of the April $285 million Drift hack, where the attacker moved about $232 million in USDC from Solana to Ethereum using Circle’s own cross-chain transfer protocol. At the time, critics including onchain investigator ZachXBT argued Circle could have moved faster to blacklist wallets and freeze funds. Circle maintained that it freezes assets when legally required, underscoring the regulatory and procedural constraints that govern stablecoin issuers’ intervention policies.

    Why This Matters

    The Bitget hack highlights the persistent vulnerability of centralized exchange infrastructure—specifically backend authorization layers—even when private keys remain secure. It also illustrates the asymmetric power of stablecoin issuers: they can neutralize a portion of stolen funds once they touch USDC or USDT, but they have no control over native assets like ETH. For the broader crypto market, the incident reinforces the importance of exchange solvency reserves and user protection funds, while reigniting debate over the speed and transparency of stablecoin freeze decisions in the absence of uniform legal mandates.

    Frequently Asked Questions

    How much of the stolen $351.6 million has been frozen?
    Only about $318,000—comprising 218,023 USDT and 99,990 USDC—has been frozen. The remaining assets, primarily over 63,000 ETH held in other exploiter wallets, cannot be frozen by any issuer.
    What caused the Bitget security breach?
    According to CEO Gracy Chen, attackers compromised a backend system in the exchange’s wallet infrastructure, spoofed transaction data, and triggered the authorization process to withdraw funds. A private key compromise was explicitly ruled out.
    Will Bitget users lose funds?
    Bitget says no. The exchange’s user protection fund holds over $464 million, which CEO Gracy Chen confirmed is sufficient to cover the entire $351.6 million loss.
  • Bitget’s $352M Hack Stemmed from Spoofed Transfers, Not Private Keys, CEO Gray Chen Says

    Bitget’s $352M Hack Stemmed from Spoofed Transfers, Not Private Keys, CEO Gray Chen Says

    Key Highlights

    • Bitget exchange detected unauthorized transfers from hot wallets at 18:31 UTC on September 24, with the breach extending to the warm-wallet layer.
    • Loss containment is confirmed and no further unauthorized transfers are possible, though the specific intrusion method remains under active investigation.
    • A full technical report will be released once the investigation is confirmed, according to Bitget representative Chen.

    Breach Detection and Immediate Containment

    Bitget’s security systems flagged unauthorized transfers originating from several exchange hot wallets at 18:31 UTC on September 24, triggering an immediate response from the platform’s security team. A hot wallet, which remains connected to the internet to facilitate rapid fund movement for instant trades, deposits, and withdrawals, functions as a temporary liquidity hub analogous to an online cash drawer. The breach did not remain confined to this layer; Chen confirmed the intrusion also reached the warm-wallet tier, a semi-connected buffer that sits between automated hot wallets and fully offline cold storage, managing liquidity top-ups and pulling excess deposits off the internet to limit capital exposure.

    Anatomy of the Attack: Forged Digital Withdrawal Slips

    Describing the breach mechanism, Chen likened the exploit to the digital equivalent of slipping forged withdrawal slips through a bank’s own teller window. In this analogy, the vault keys never left the building; instead, an attacker gained access to the office responsible for preparing the slips, created paperwork that appeared official, and routed it through the same approval window the bank uses daily. To the system processing the approvals, the transactions looked like routine payouts, allowing the unauthorized outflow to proceed undetected until internal monitoring flagged the anomaly.

    Containment Confirmed, Investigation Underway

    Chen provided a definitive update on the platform’s status, stating: “Loss containment is confirmed. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation. A full technical report will follow once confirmed,” she said. The confirmation that the outflow has been stopped and no further unauthorized transfers can occur addresses the most immediate concern for users and stakeholders. However, the root cause—the specific vector used to penetrate the warm-wallet layer and manipulate the approval logic—has not yet been publicly disclosed, pending the completion of the forensic investigation.

    Why This Matters

    The incident underscores the persistent operational risk inherent in the multi-tier wallet architecture employed by centralized cryptocurrency exchanges. While cold storage remains the gold standard for asset security, the necessity of hot and warm wallets for liquidity creates attack surfaces that sophisticated actors continue to probe. Bitget’s experience highlights how attackers are shifting from brute-force key theft to logic-layer exploits—subverting legitimate approval workflows rather than cracking encryption. For the broader industry, the breach serves as a reminder that security audits must extend beyond key management to include rigorous testing of transaction validation logic, access controls for internal tooling, and real-time anomaly detection across all wallet tiers. The forthcoming technical report will be closely watched by security teams across the sector for indicators of compromise and mitigation strategies applicable to similar infrastructure.

    Frequently Asked Questions

    What wallets were affected in the Bitget breach?
    The unauthorized transfers originated from Bitget’s hot wallets—internet-connected wallets used for immediate liquidity—and the intrusion extended to the warm-wallet layer, which acts as a semi-connected buffer between hot wallets and offline cold storage.
    Has the breach been fully contained?
    Yes. According to Bitget representative Chen, loss containment is confirmed and no further unauthorized transfers are possible. The platform has secured the affected infrastructure.
    When will details on how the attack happened be released?
    A full technical report will be published once the active investigation into the specific method of system intrusion is confirmed and complete.
  • Bitget Hack Still Ongoing as New Developments Emerge

    Bitget Hack Still Ongoing as New Developments Emerge

    Key Highlights

    • On-chain data indicates a potential exploit at cryptocurrency exchange Bitget, with over $170 million in assets moved from three hot wallets and one cold wallet across multiple networks, primarily converted to Ethereum ($ETH).
    • An attacker address on Arbitrum acquired 7,111 $ETH in six minutes using approximately 19.67 million USDT0 via UniswapX and 1inch Fusion, executing some trades at a 5% premium to spot prices.
    • Bitget has begun moving remaining funds—approximately $530 million—from the affected wallets to secure addresses in what appears to be an emergency containment effort, while the root cause and potential North Korea links remain unconfirmed.

    Massive On-Chain Outflows Trigger Hack Suspicions at Bitget

    Unusual on-chain activity detected in wallets allegedly controlled by the centralized exchange Bitget has sparked widespread suspicion of a significant security breach. Blockchain analytics reveal that high-value assets have been systematically drained from the exchange’s hot and cold wallet infrastructure, with the bulk of the stolen funds rapidly converted into Ethereum ($ETH). The incident appears to span multiple blockchain networks, suggesting a broad compromise rather than an isolated vulnerability on a single chain.

    Arbitrum Transactions Reveal Speed and Scale of Attack

    Initial alarm was raised by a flurry of transactions on the Arbitrum network. A newly created address purchased 7,111 $ETH in a mere six minutes, spending approximately 19.67 million USDT0 sourced directly from a Bitget hot wallet. The trades were routed through UniswapX and 1inch Fusion, with several executions occurring at prices roughly 5% above the prevailing spot rate. This aggressive buying pressure momentarily pushed the WETH/USDC pool price to $2,870, illustrating the urgency and volume of the asset conversion.

    Compromise Extends Across Multiple Wallets and Asset Classes

    Subsequent blockchain analysis indicates the breach is not confined to a single wallet or network. Data shared by on-chain investigators suggests three hot wallets and one cold wallet associated with Bitget have been impacted. A diverse range of assets—including $ETH, AVAX, BNB, $USDC, $USDT, USDT0, and XAUT—have been moved from these addresses. The addresses attributed to the attacker continue to swap remaining stablecoin balances ($USDC and $USDT) for $ETH, driving the total tracked on-chain loss above $170 million. Early social media speculation had placed the figure at over $100 million, but cross-network transaction tracing has since revised the estimate upward.

    Exchange Initiates Emergency Containment Measures

    In a significant development approximately five minutes prior to this report, Bitget-owned addresses began actively transferring assets remaining in the compromised wallets to new destinations. Roughly $530 million in assets are still held within the affected wallet cluster. This movement is being interpreted by analysts as an emergency fund transfer and a security measure to isolate wallets not yet believed to be compromised. The exchange has not yet issued a formal public statement detailing the root cause, leaving critical questions unanswered regarding whether private keys were exposed or if a deeper infrastructure vulnerability was exploited.

    Why This Matters

    The suspected breach at Bitget represents one of the largest exchange-related security incidents in recent months, underscoring the persistent systemic risk posed by centralized custody of digital assets. The sophistication of the attack—leveraging advanced DEX aggregators like UniswapX and 1inch Fusion for rapid, high-slippage conversion to Ether—suggests a highly capable actor. Unverified claims attributing the hack to North Korea-linked groups, such as the Lazarus Group, align with historical patterns of state-sponsored cybercrime targeting crypto exchanges to fund sanctioned regimes. If confirmed, this would mark another major success for such actors. For the broader market, the incident tests the resilience of exchange solvency proofs and the effectiveness of real-time on-chain monitoring in mitigating losses. The next 24 to 48 hours are critical: the industry will be watching for Bitget’s official incident report, proof-of-reserves updates, and whether the remaining $530 million in identified wallets can be fully secured.

    Frequently Asked Questions

    How much money was stolen in the Bitget hack?

    On-chain analysis currently estimates the total value of assets moved by the attacker exceeds $170 million. Approximately $530 million remains in the affected wallets, which Bitget is actively moving to secure addresses.

    Which networks and tokens were affected?

    The exploit spanned multiple networks, with initial major activity on Arbitrum. Assets moved include Ethereum ($ETH), AVAX, BNB, $USDC, $USDT, USDT0, and XAUT. The attacker is converting stablecoins into $ETH.

    Has Bitget confirmed the hack and are user funds safe?

    As of this report, Bitget has not released an official statement confirming the hack or detailing the cause. However, on-chain data shows the exchange has begun transferring remaining funds from the compromised wallets, suggesting an active emergency response. Users should monitor official Bitget channels for updates.