Timeline
- 7.5
Bitget CEO ‘not very optimistic’ on recovering funds from $388M breach
Bitget CEO Gracy Chen said she is "not very optimistic" about freezing or recovering the funds lost in the exchange's $388 million security breach, speaking on Cointelegraph's Chain Reaction released Tuesday. She pointed to the February 2025 Bybit hack as a "good reference point," noting that roughly a year later only about 3.5% of Bybit's stolen funds had been frozen. The on-record assessment signals that most of the $388 million taken from Bitget is unlikely to be frozen or returned to affected users, framing recovery expectations well below the full loss. Chen distinguished freezing from recovery, saying the 3.5% figure for Bybit "is only the freezing. It's not about recovery yet." Bitget launched a bounty program offering 5% of funds frozen and 5% of funds recovered; NEAR Intents said Monday it blocked more than $50 million in assets tied to the attack and froze about $500,000, while Chen confirmed Tether and Circle blacklisted an exploit-linked wallet, freezing $318,013 in USDT and USDC. Withdrawals have resumed in stages, starting with Bitcoin on Monday and ETH on Tuesday, and Chen said Bitget had not "totally ruled out" an inside job while describing the investigation as preliminary.
- 8.5
Nearly 5,000 BTC leaves Bitget as hackers begin laundering $387 million haul
After Bitget resumed Bitcoin withdrawals at 08:00 UTC on Sept. 28, CEO Gracy Chen said the exchange had processed 9,585 withdrawal orders totaling 4,098.036 BTC as of 17:00 UTC+8. Separate DeFiLlama data showed Bitget's tracked Bitcoin balance falling to about 30,770 BTC from 35,412 BTC, a decline of roughly 4,642 BTC (about $391 million). The rapid outflow is the first indication of how users are responding after Bitget froze withdrawals for four days while investigating the largest security incident in its eight-year history. At the same time, investigators are racing to trace the $387.5 million haul as laundered assets are scattered across chains and privacy tools. The reserve decline is larger than the withdrawal volume Chen reported, and DeFiLlama tracks assets held in wallets attributed to exchanges, so changes can also reflect wallet movements or differences in address coverage rather than customer withdrawals alone. Ethereum withdrawals are scheduled to resume on Sept. 29, USDT on Sept. 30, and remaining tokens, fiat and peer-to-peer services on Oct. 2.
- 9.0
North Korean Hackers Linked to $388M Bitget Crypto Exchange Theft: CEO
Bitget said on Sept. 25 that it raised its estimate of assets taken in its Sept. 24 breach to $387.5 million from $351.6 million, after further on-chain tracing identified Zcash and TRON assets excluded from its initial accounting. CEO Gracy Chen attributed the theft to North Korean hackers in the same update. Withdrawals remained suspended more than a day after the breach, and other exchanges including Binance and Bybit are publicly supporting efforts to freeze and trace the stolen funds. Bitget said the increased figure reflected transfers made during the original incident and that no additional unauthorized transactions had occurred. Bitget detected unauthorized transfers from some hot wallets at 18:31 UTC on Sept. 24, suspended withdrawals while keeping deposits and trading operational, and said its security team has identified and patched the underlying vulnerability. Its investigation with blockchain security firms Mandiant and SlowMist remains underway, with further forensic findings expected.
- 7.5
Chainalysis: Blockchain Dead Drop Attacks Surge 420% as State Hackers Expand
Chainalysis reported that blockchain dead drop attacks rose 420% over the past 12 months, with North Korea- and Iran-linked operators accounting for roughly two-thirds of newly observed activity by the second quarter of 2026. The North Korea-linked group UNC5342 uses Tron and Aptos as redundant routes pointing infected devices to malware instructions stored on BNB Smart Chain, while suspected Iranian actors embedded command-and-control routing data inside Bitcoin transactions sent to an address historically associated with Satoshi Nakamoto. This marks a shift from domain-based command-and-control to public blockchain infrastructure that conventional takedowns cannot easily disable, meaning defenders would have to coordinate action across multiple chains simultaneously. It raises the security and compliance burden for crypto exchanges, wallet providers and enterprises whose legitimate traffic shares the same networks that attackers are abusing. Chainalysis said malicious blockchain writes rose from 2.06 per day to 11.1 per day after the emergence of high-capacity open-weight Chinese AI models, a 440% increase in under a year, though the firm cautioned its measurement does not identify a single model or prove that AI alone caused the rise. The malware queries Tron first and falls back to Aptos if that route fails, and disrupting the operation would require action across all three chains at once.
- 7.5
Chainalysis: state hackers drive 420% surge in onchain malware
Chainalysis reported a 420% year-over-year rise in the number of times attackers wrote malware instructions or infrastructure data onto public blockchains, with state-linked actors accounting for roughly two-thirds of new activity each quarter. The firm attributed previously unattributed activity across Tron, Aptos and BNB Smart Chain to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence, and identified suspected Iran-linked actors writing command-and-control routing data into Bitcoin transactions. Using public blockchains as malware infrastructure gives campaigns a durability that conventional domain takedowns and server seizures cannot easily disrupt, because the pointers remain readable on an immutable ledger. It also drags major public chains into a security and compliance spotlight, raising questions for exchanges, analytics vendors and regulators about how abuse of these networks is monitored. Chainalysis recorded a 440% increase in malicious blockchain writes since July 2025, a date it links to high-capacity open-source Chinese AI models becoming capable of producing malicious code with limited safeguards, though research lead Eric Jardine described this as a "clear point-in-time association" rather than proof of causation. The Iran assessment relied on malware family, decoding method, timing and server infrastructure tied to previously reported Iranian operations, and in that campaign attacker-controlled wallets sent small payments to a well-known Bitcoin address with historical ties to Satoshi Nakamoto that had no connection to the attackers and served only as a permanent public location for updated directions.