Back to news

Jiayi: Traces of Bitget's Associated Sites Not Cleared

Crypto observer Jiayi publicly questioned Bitget CEO Gracy Chen, stating that after mistakenly entering the Foresight Ventures website, she still saw traces left by hackers that had not been cleared, and suggested a comprehensive inspection of all platform assets.

She added: "The flag is still up, which means the inspection is not thorough." This statement came after the Bitget exchange's hot wallet was hacked. English public records show that on September 24 at 18:31 UTC, unauthorized transfers were detected, initially reporting a loss of approximately $351.6 million, which was later revised to about $387.5 million after accounting for Zcash and Tron the next day, covering hot wallets across multiple chains and some warm wallets. The company stated that cold wallets and private keys were not compromised, and the independent product Bitget Wallet was unaffected.

Mandiant and SlowMist's mid-term forensics pushed the intrusion window earlier: attackers had entered some third-party security devices by August 31, and on September 24, they obtained high-privilege credentials to write forged withdrawal instructions to the wallet operating system. Bitget stated that the signatures appeared to be from the platform's own wallets, but the parameters differed from ordinary user withdrawals; related records were deleted after the transfer. The largest single asset was approximately 103 million XRP, valued at about $157 million at the time. The user protection fund disclosed that it exceeded $464 million, dropping below $200 million after compensation, and on September 30, the company stated it had replenished to $309 million, including 3,705 BTC.

Gracy Chen initially pointed to IPs and on-chain patterns commonly associated with North Korean organizations while ruling out the preliminary possibility of insider involvement. She also mentioned that after the theft, someone impersonated an investment institution team to conduct social engineering against her, which had been verified and exposed through another channel. Withdrawals were temporarily suspended, and some cryptocurrencies were gradually reopened; recovery efforts involved freezing limited funds from Tether, Circle, etc., with the disclosed amounts still far less than the stolen amount.

Foresight is adjacent to the Bitget ecosystem: Foresight News continuously published the timeline of the incident, and Foresight Ventures is a brand within the same investment circle. Current mainstream English reports have verified that the exchange's hot wallet was hacked but have not issued a separate report confirming the Foresight Ventures website was compromised. Jiayi's incremental information is that the attackers' messages on the associated site page remain, which she considers evidence of "incomplete cleanup."

In market mechanics, the sellers are the recently hacked centralized exchanges and their associated brand sites, while the buyers are users who still keep funds on hot wallet paths. The event-driven factor comes from the trust check following the $387.5 million theft, not a new announcement of on-chain transfers. Funds are temporarily flowing from Bitget's hot wallets and associated entrances to cold storage, competing exchanges, and self-custody; benefiting are narratives that can prove cold wallet isolation, while under pressure are brand sites, media sites, and investment sites that may share the same operational domain as the breached ones.

Source: Public Information

ABAB AI Insight

Bitget characterizes the incident as a "third-party security product zero-day + forged withdrawal instructions," deliberately separating it from "private key theft." This is similar to the February 2025 Bybit incident where the authorization interface was overlooked: the signing machine was still present, but the content seen during audits was altered. Gracy Chen also maintains the IPO stance within three years and uses the protection fund to balance user accounts, with the logic being to first protect customer balances, then address vendor issues. If the flag remains on the Foresight site, it indicates that the cleanup scope is limited to the wallet operation server and does not cover the same brand site group.

The capital path involves the protection fund acting as a safety net, Mandiant/SlowMist issuing reports, stablecoin issuers freezing funds, and then reducing the fund from $464 million to $309 million to indicate solvency. The motivation is not to immediately recover the $387.5 million but to prevent a bank run. Resource allocation is reflected in the shutdown of hot wallets, assets being swept into cold wallets, and phased reopening of withdrawals. Money flows from the user protection pool to the theft gap, then back through new deposits; the failure to remove flags from associated sites will make the statement "fully inspected" hard to sell.

Analogies include the delayed cleanup of operational traces discovered after the Mt. Gox incident, the Poly Network being publicly announced as compromised, and multiple exchanges being attacked while their official sites or status pages still show tampering. Bitget is currently in a control phase: funds are temporarily covered, and the narrative needs to expand from "hot wallet incident" to "comprehensive digital asset inspection of the group." Historical comparisons show that before FTX collapsed, associated entities had unclear ledgers, and the market punishes not just a single hot wallet but also the inability to distinguish which domains, funds, and hot wallets belong to the same attack surface.

Structural judgment indicates a custodial reconstruction before regulatory changes. The mechanism is: users want verifiable isolation, while exchanges sell a unified brand. When investment sites, information sites, and trading hot wallets share vendors or the same operational domain, a single zero-day can simultaneously breach both funds and facade. Whoever first clears the residual traces of associated sites and publishes asset boundaries can reprice the protection fund as trust, rather than emergency loans.

ABAB News · Cognitive Law

  1. The flag is still up, which means the inspection is not over.
  2. The private key is not lost; the hot path can still transfer funds.
  3. The brand site group is a manual for the same attack surface.

Source

·ABAB News
·
8 min read
·22 hrs ago
分享: