HomeMalware & ThreatsCryptohack Roundup – $387M Bitget Hack

Cryptohack Roundup – $387M Bitget Hack

Published on

spot_img

Cybersecurity Weekly Roundup: Major Cryptocurrency Incidents

In a detailed overview of recent cybersecurity incidents involving digital assets, significant developments have emerged in the world of cryptocurrencies, particularly focusing on high-profile breaches and fraudulent schemes. The latest updates from the cybersecurity community reveal staggering sums involved, revealing the pervasive risks associated with the digital asset space.

Bitget Suffers a Massive $387 Million Attack

In a shocking turn of events, the cryptocurrency exchange Bitget reported a substantial security breach that saw approximately $387.5 million stolen from its online wallets. CEO Gracy Chen revealed the underlying issues, stating that the attacker managed to manipulate transaction information to initiate an unauthorized fund transfer. Thankfully, Bitget assured users that private keys—vital components that secure cryptocurrencies—remained uncompromised, as did their offline wallets responsible for safeguarding funds from internet threats.

This incident came to light on September 24, when the exchange promptly suspended withdrawals after detecting the fraudulent activity. The hacked assets included Ethereum and various other cryptocurrencies. Fortunately, Bitget reported that it possesses a protection fund exceeding $464 million, designed to offset losses like these. To gain further insights into the attack, the exchange has enlisted the help of noted security firms, Mandiant and SlowMist, to assist in their ongoing investigation into the breach’s origins and execution.

Malicious Browser Extensions Exploit Investor Names

Simultaneously, security researchers flagged a burgeoning campaign involving malicious browser extensions masquerading as tools endorsed by iconic investors like Warren Buffett and John Paulson. The research group LayerX, which is now part of Akamai, began tracking these deceptive extensions back in March and found about 30 variants designed to lure unsuspecting users under false pretenses.

The extensions purported to be productivity, privacy, and digital-asset services, but were in reality crafted to siphon crucial information, such as recovery phrases from digital wallets. Notably, researchers identified a common code framework linking 21 of these extensions, enhancing their effectiveness against targeted users. By employing checks on browser language and other settings, the extensions could act benignly during assessments, thereby evading detection while ensnaring their victims. Emerging data suggests that artificial intelligence may also have played a role in their sophisticated design.

Sentencing in High-Profile Phishing Case

In yet another alarming case, Ronald Spektor, a resident of Brooklyn, was sentenced to four to 12 years in prison for orchestrating a phishing scheme that netted nearly $16 million from around 100 users of the cryptocurrency exchange, Coinbase. His modus operandi involved impersonating a Coinbase representative, indicating to victims that their accounts were under threat from hackers. By creating a sense of urgency, he persuaded them to transfer cryptocurrency into wallets under his control.

Legal authorities leveraged transaction records, blockchain analytics, and other digital evidence to establish Spektor’s guilt, which ultimately led to his conviction on multiple counts, including money laundering. The judge also mandated that he pay restitution amounting to nearly $16 million to victims and relinquish assets valued over $500,000.

Charges Filed Against Vietnamese National in Investment Scam

In a related case, U.S. federal prosecutors have arrested Trung Nguyen Van, a Vietnamese national linked to a significant cryptocurrency scam costing an estimated $16 million. Victims were recruited under the guise of investing in a fictitious platform known as "Triangle" during the summer of 2024. The scheme, reportedly involving romance scams, showcased fraudulent tactics to win the trust of potential investors online before directing them towards non-existent high-yield investment opportunities.

As the investigation unfolded, indications suggested that Nguyen was not acting alone, as further victims across the United States also reported losses of vast sums through similar schemes. The added complexity highlights the multifaceted nature of cryptocurrency-related fraud, where scammers prey on emotions to exploit unwitting participants.

Magic Eden’s Security Flaws Expose Vast Amounts

In yet another distressing incident, a security breach related to the platform Magic Eden resulted in the theft of 305 digital collectibles due to vulnerabilities within its payment system. Although the report did not disclose the exact value of these stolen assets, it is estimated that over $5.7 million worth of collectibles were left vulnerable to further potential theft.

After the flaws were discovered, security teams acted swiftly to relocate assets before they could be exploited. Magic Eden ceased operations involving the affected payment system back in October 2024 while ensuring active listings remained unaffected. Additionally, the incident touched on 660 additional Wrapped Ether—a digital token closely tied to Ether’s market value.

As the cryptocurrency landscape continues evolving, these incidents serve as stark reminders of the vulnerabilities and risks inherent to the ecosystem. Stakeholders and end-users alike must remain vigilant, implementing robust security measures to safeguard their digital assets against an escalating tide of cyber threats.

Source link

Latest articles

Zammad Vulnerabilities Enable Attackers to Execute Code and Escalate Privileges to Root

Critical Vulnerabilities Found in Zammad Helpdesk Platform: Urgent Response Required Recent security findings have unveiled...

Armadin Secures $255.5 Million Series B for Autonomous Remediation Efforts

Company Plans to Extend Compensating Controls Across MDR and WAF Platforms A notable development in...

Shadow AI and the Permissions Dilemma: What to Consider Before Granting Access to AI

The Rise of AI and the Urgent Need for Caution AI tools have transitioned from...

Cyber Briefing – 2026.10.02 – CyberMaterial

In a rapidly evolving digital landscape, several key issues related to cybersecurity have emerged,...

More like this

Zammad Vulnerabilities Enable Attackers to Execute Code and Escalate Privileges to Root

Critical Vulnerabilities Found in Zammad Helpdesk Platform: Urgent Response Required Recent security findings have unveiled...

Armadin Secures $255.5 Million Series B for Autonomous Remediation Efforts

Company Plans to Extend Compensating Controls Across MDR and WAF Platforms A notable development in...

Shadow AI and the Permissions Dilemma: What to Consider Before Granting Access to AI

The Rise of AI and the Urgent Need for Caution AI tools have transitioned from...