Tag: Hot wallet exploit

  • Bitget Freezes Withdrawals After $351.6M Hack

    Bitget Freezes Withdrawals After $351.6M Hack

    Key Highlights

    • Bitget confirmed a $351.6 million exploit from its hot wallets on September 24, 2026, with on-chain data showing the first unauthorized transfer at 18:31:11 UTC and major outflows continuing for nearly three hours before the public notice.
    • The attacker rapidly converted freezable stablecoins (USDT, USDC, Tether Gold) into ether via a router contract, paying up to 5% above spot price, suggesting a deliberate race against issuer freeze functions.
    • CEO Gracy Chen stated user funds are safe and the loss is covered by Bitget’s $464 million User Protection Fund, while withdrawals remain suspended pending a full incident report due within 24 hours.

    Timeline Reveals Hours-Long Gap Between Detection and Containment

    Bitget chief executive Gracy Chen confirmed on Thursday night that attackers drained roughly $351.6 million from the exchange’s hot wallets, suspending customer withdrawals while an investigation proceeds. Chen published the notice at 21:30 UTC on September 24, 2026, stating: “At 18:31 UTC on September 24, 2026, Bitget’s security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.”

    On-chain data corroborates the 18:31 detection timestamp but paints a more granular picture of the subsequent three hours. At 18:31:11 UTC, a wallet labeled “Bitget 6” on Etherscan, Arbiscan, and BscScan sent 0.84 ether to a newly created address — a test transaction that typically precedes large transfers and marks the first movement of the breach. The outflows accelerated rapidly: by 18:58:59, the same wallet moved 34,751,168 USDT; at 19:01:20 on Arbitrum, 19,668,851 USDT0; at 19:01:23, 12,852,046 USDC; and at 19:01:35, 7,130.86 ether. A second wallet, “Bitget 35,” added 15,362 ether across three transfers, followed by another 223.2 ether at 21:23:11 — two hours and 52 minutes after detection and just seven minutes before Chen’s public notice.

    Across Ethereum and Arbitrum alone, $133.4 million exited Bitget-labeled wallets, plus 3,000 Tether Gold tokens worth approximately $12.8 million from a third address. The remainder of the $351.6 million moved on other chains. Chen emphasized that cold storage was never touched and described a three-tier wallet architecture in which “the breach contained only a portion of the hot wallet and warm wallet layers.” However, the extended window between detection and containment allowed substantial value to leave the exchange’s control.

    Attacker Strategy Signals Intent to Outrun Freeze Functions

    The composition of stolen assets and the speed of conversion provide the clearest signal of the attacker’s intent. Tether can freeze USDT, Circle can freeze USDC, and Tether can freeze its gold token — but ether cannot be frozen by any central party. Within six minutes of receiving the stablecoins, the attacker pushed all three asset types into router contract 0x7c96279E, which fanned them across Uniswap V3 pools and the Uniswap V4 PoolManager, converting everything into ether.

    Pseudonymous analyst DCF GOD, who identified the Arbitrum leg before Bitget’s public statement, noted the buyer was “paying up to +5% over spot” and drove one pool to $2,870 against a spot price near $2,688. “which makes no sense if someone was just trying to buy eth,” he wrote. The premium paid aligns with a seller racing issuer freeze functions rather than a typical market participant. The resulting ether — approximately 24,590 ETH — now sits in three previously inactive wallets: 10,000 ETH at 20:13, another 10,000 at 20:19, and 4,590 more at 21:41:11. That final transfer occurred ten minutes after Chen’s notice and one minute after Bitget’s official account stated it had “identified and flagged the relevant transfer addresses.”

    Exchange Response and Industry Context

    “User funds are safe,” Chen wrote. “The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million.” She added that deposits and trading continue normally and promised a full incident report within 24 hours: “We will not speculate on the attack vector until the investigation is complete.”

    That restraint reflects a pattern security experts recognize across recent major exchange breaches. Ido Sofer, founder and CEO of key management firm Sodot, described the dynamic on the On The Margin podcast: “Those are off-chain hacks that led to on-chain loss of funds. Developer credentials, deployment keys, API keys that are being stolen. And that provided access to moving funds on chain.” His blunter assessment: “There will be hacks. The question is, is it gonna be in your company or not?”

    Bitget’s $464 million protection fund against a $351.6 million loss provides a thin but real cushion. The exchange has published proof-of-reserves attestations for 45 consecutive months, most recently reporting a 122% reserve ratio for August. The immediate test is whether withdrawals reopen without disruption.

    Why This Matters

    This incident represents the largest exchange loss since the Bybit breach and follows a series of high-profile security failures including the $130 million Coldcard theft and a $137 million November exploit that reshaped DeFi’s yield infrastructure. The attack underscores a persistent industry vulnerability: custodial exchanges remain prime targets where compromised off-chain credentials — developer keys, API access, deployment infrastructure — translate directly into on-chain asset drainage. The attacker’s sophisticated conversion strategy, deliberately overpaying to swap freezable assets for censorship-resistant ether before issuers could intervene, demonstrates an evolving playbook that prioritizes speed and asset selection over stealth. For the broader market, the episode tests whether exchange-backed protection funds can credibly absorb nine-figure losses without contagion, and whether proof-of-reserves attestations translate into operational resilience when withdrawals are suspended. The 24,590 ether now parked in three fresh wallets remains a live threat vector; any movement will signal the next phase of laundering or liquidation.

    Frequently Asked Questions

    What assets were stolen and how much is the total loss?
    Approximately $351.6 million was drained from Bitget’s hot wallets across multiple chains. On Ethereum and Arbitrum alone, $133.4 million in USDT, USDC, USDT0, and ether left labeled wallets, plus 3,000 Tether Gold tokens worth ~$12.8 million. The remainder moved on other networks. The attacker converted all freezable stablecoins and gold tokens into ether within minutes.
    Are user funds affected and will withdrawals resume?
    CEO Gracy Chen stated “User funds are safe” and confirmed the loss falls within Bitget’s User Protection Fund, which holds over $464 million. Cold storage was not touched. Deposits and trading continue normally, but withdrawals remain suspended pending investigation. A full incident report is promised within 24 hours from the September 24 notice.
    How did the attacker move the funds and can they be recovered?
    The attacker used a router contract (0x7c96279E) to swap USDT, USDC, and Tether Gold for ether via Uniswap V3 and V4 pools, paying up to 5% above spot price to execute quickly before issuers could freeze the stablecoins. The resulting ~24,590 ether now sits in three previously unused wallets. Ether cannot be frozen by any central party. Tether and Circle have freeze capabilities for USDT and USDC respectively, but those assets were already converted. Recovery depends on law enforcement action, exchange cooperation, and whether the attacker makes operational security mistakes when moving the ether.
  • Crypto Casino Duelbits Goes Offline After $7 Million Hot Wallet Hack

    Crypto Casino Duelbits Goes Offline After $7 Million Hot Wallet Hack

    Key Highlights

    • Crypto gambling platform Duelbits suffered a $7 million hot wallet exploit on Thursday, prompting the site to go offline while co-founder Joe confirmed “user funds are safe.”
    • Blockchain security firm Scam Sniffer identified a suspected private key compromise affecting wallets on Ethereum, BNB Chain, Tron, and Bitcoin, with 8.1 BTC also stolen.
    • The attack mirrors the 2023 Stake.com breach, where hackers stole $40 million using the same private key compromise method.

    Duelbits Takes Platform Offline After $7 Million Hot Wallet Drain

    Crypto gambling platform Duelbits went offline on Thursday after attackers drained approximately $7 million from its hot wallets across multiple blockchains. The incident was first flagged by blockchain security firm Scam Sniffer, which reported that Duelbits hot wallets on Ethereum, BNB Chain, and Tron had sent funds to newly created addresses in what appeared to be a private key compromise. The firm later confirmed the company’s Bitcoin hot wallet also lost 8.1 BTC in the attack.

    Co-Founder Confirms Breach, Assures User Funds Secure

    Duelbits co-founder Joe addressed the incident on X, stating: “Confirming a ~$7M hack. Still investigating exactly what happened and how,” adding that “user funds are safe.” He indicated the platform would remain offline until the investigation concludes and its hot wallets are refilled. The direct acknowledgment from leadership came as on-chain data continued to reveal the full scope of the asset movements.

    On-Chain Analysis Reveals Multi-Chain Asset Losses

    Etherscan data shows the Ethereum wallet labeled as a Duelbits hot wallet transferred 836 ETH, approximately 593,000 USDT, 97,000 USDC, 31,500 DAI, and 12.4 billion SHIB to the attacker within minutes. The compromised Ethereum wallet now holds less than $25 in ether. Scam Sniffer’s analysis indicates the simultaneous compromise across Ethereum, BNB Chain, Tron, and Bitcoin networks strongly points to a private key breach rather than a smart contract vulnerability.

    Attack Method Mirrors 2023 Stake.com Breach

    The suspected private key compromise mirrors the methodology used in the 2023 attack on Stake.com, the largest crypto casino by volume, where hackers made off with $40 million. That incident, also attributed to a private key compromise, raised significant concerns about key management practices across the crypto gambling sector. The recurrence of this attack vector suggests persistent operational security challenges for platforms managing large hot wallet balances.

    Why This Matters

    The Duelbits hack underscores the ongoing vulnerability of centralized hot wallet infrastructure in the crypto gambling industry. Despite high-profile incidents like the Stake.com breach, platforms continue to maintain substantial assets in internet-connected wallets secured by single points of failure. The multi-chain nature of this exploit—hitting Ethereum, BNB Chain, Tron, and Bitcoin simultaneously—demonstrates how a single private key compromise can cascade across an operator’s entire treasury. For users, the incident reinforces the importance of platform solvency transparency and the risks inherent in custodial gambling platforms. Regulators and industry watchdogs will likely scrutinize whether Duelbits’ claim that “user funds are safe” holds up during the investigation and whether the platform maintains sufficient cold storage reserves to cover the hot wallet losses without impacting customer balances.

    Frequently Asked Questions

    How much was stolen in the Duelbits hack?

    Approximately $7 million was drained from Duelbits hot wallets across Ethereum, BNB Chain, and Tron, plus an additional 8.1 BTC from the platform’s Bitcoin hot wallet.

    What caused the Duelbits security breach?

    Blockchain security firm Scam Sniffer identified a suspected private key compromise as the attack vector, noting that wallets across multiple chains sent funds to newly created addresses simultaneously.

    Is Duelbits currently operational?

    No, Duelbits has taken its platform offline. Co-founder Joe stated the site will remain offline until the investigation is finished and hot wallets are refilled.