Specter: Bitget attacker may be North Korean hacking group Lazarus Group, and the path of stolen funds is linked to funds from the earlier AFX hack.
According to on-chain detective Specter’s monitoring, by tracing on-chain fund flows, North Korean hacking group Lazarus Group is suspected to be the behind-the-scenes attacker of the Bitget theft. The incident is linked to the AFX attack that occurred in July this year, which caused approximately $24 million in losses and was attributed to TraderTraitor, an entity associated with Lazarus Group. The stolen XRP from Bitget, after cross-chain transfers, has a fund trail directly connected to the funds stolen in the AFX attack.
4 minutes ago
Hyperliquid Strategies Inc Buys 494,200 $HYPE ($45.8M) in 16 Hours, 5.51M Monthly
Wallet 0x6436, linked to Hyperliquid Strategies Inc (@HypeStrat), bought another 494,200 $HYPE ($45.8M) over the past 16 hours.
Over the past month, the wallet has bought a total of 5.51M $HYPE ($476M), averaging 183,574 $HYPE ($15.86M) per day.
@HypeStrat currently holds 35.1M
4 minutes ago
Stolen assets from Bitget total approximately $357 million, including around 103 million XRP and 31,890 ETH.
According to Lookonchain monitoring, the total value of assets stolen in the Bitget attack is approximately $356.86 million. The stolen funds are primarily composed of 102,926,478 XRP (worth $157.48 million) and 31,890 ETH (worth $85.75 million), which account for the majority of the lost assets. Other stolen assets include 34,751,168 USDT ($34.75 million), 21,056,725 USDC ($21.06 million), 19,668,852 USD?0 ($19.67 million), 3,000 XAUt ($12.82 million), 12,719 BNB ($9.88 million), 821,012 AVAX ($8.38 million), and 20,593,377 TRX ($7.07 million).
4 minutes ago
Federal Reserve Seeks Public Comments on Stablecoin Issuance Regulatory Framework Under the GENIUS Act
The U.S. Federal Reserve Board announced on September 24 that it is seeking public comment on two proposals to establish a regulatory framework for payment stablecoin issuers under its oversight, pursuant to the GENIUS Act. The first proposal mandates that issuers back stablecoins with full reserves of approved high-quality liquid assets such as short-term U.S. Treasury securities, and sets standardized capital requirements and risk management standards to mitigate credit and operational risks associated with stablecoin operations. It also proposes to set rules for Federal Reserve-supervised institutions holding stablecoin reserve assets, and clarify the permissible scope of activities for regulated banks engaging in stablecoin and related operations. The second proposal aims to establish a dedicated application process for Federal Reserve-supervised banks seeking to issue payment stablecoins, requiring applicants to submit documents including business plans and financial information, while establishing procedures for application appeals, hearings, and final rulings. The public comment period will conclude 60 days after the proposals are published in the Federal Register.
4 minutes ago
Bitget hack totals $356.8M: 102.93M $XRP, 31,890 $ETH, 34.75M $USDT and more stolen
Update:
The funds hacked from #Bitget include:
102.93M $XRP ($157.48M)
31,890 $ETH ($85.75M)
34.75M $USDT ($34.75M)
21.05M $USDC ($21.05M)
19.67M $USD?0 ($19.67M)
3,000 $XAUt ($12.82M)
12,719 $BNB ($9.88M)
821,012 $AVAX ($8.38M)
20.59M $TRX ($7.07M)
4 minutes ago
Bitget CEO suspects the recent attack was perpetrated by North Korean hackers, noting that IP clues align with VPN signatures.
Bitget CEO Gracy Chen said during a live Q&A session on the crypto exchange’s security incident that preliminary investigations have found some related IP addresses match the VPN service used by a North Korean hacking group, and the attack pattern aligns with the group’s previous operations. As such, Bitget cannot rule out the group’s involvement in the attack, which involved approximately $351.6 million. However, attribution efforts remain in the preliminary stage. Chen noted that Bitget does not currently believe the incident was an inside job. Attackers directly breached the platform’s systems to transfer funds, did not forge user withdrawal requests, and did not obtain private keys for cold or hot wallets. Investigators are still working to confirm the specific affected systems and the attackers’ intrusion vector.
4 minutes ago