Bitget detected unauthorized transfers on September 24 at 18:31 UTC, but the main fund movements occurred approximately 30 minutes later. An initial $87.6 million left hot wallets at 19:01, followed by a second transfer of $202.8 million at 19:16. Of Bitget’s reported $387.5 million in losses, roughly $290 million was moved after the exchange’s initial alert. The attacker compromised a backend system in Bitget’s wallet infrastructure, spoofed withdrawal data, and tricked the exchange’s authorization process without compromising private keys. Hypernative identified several security controls that could have interrupted the attack, including automated transaction verification and transfer velocity limits, but the exchange did not suspend the compromised signer until 21:23 UTC, nearly three hours after initial detection.
Source: Read the original article

