MetaMask Reports No Immediate Wallet Danger After Infrastructure Incident
A MetaMask security incident poses no immediate threat to wallets, but the company is exiting affected Lido staking validators as a precaution.
Bitget confirmed a $387.5 million hack on Sept 24. Attackers compromised its backend system, and withdrawals remain suspended.
Bitget acknowledged that $387.5 million was taken from its exchange wallets on September 24. Withdrawals stay halted, but the firm states its protection fund will cover the damage.
Investigations are underway by Mandiant and SlowMist. Gracy Chen, the CEO, said North Korean groups might be behind the attack, though how attackers first got in has not been revealed.
To understand how the breach could have occurred, BeInCrypto compiled a timeline from public information.
According to Bitget, its security systems identified the transfers at 18:31 UTC and triggered emergency steps within minutes.
Parts of the exchange's hot and warm wallets — used for daily operations — were compromised. The company said its offline cold wallets were not affected. The time of detection does not indicate when the attackers initially broke in.
最新的进展同步一下:我们正在与独立第三方专家 @Mandiant 和 @SlowMist_Team 合作,对此次事件进行全面调查。
— Gracy Chen @Bitget (@GracyBitget) September 25, 2026
其他几点都是说过的,我再强调一下:
-我们的首要任务是保障用户。用户余额保持完整,Bitget 用户保护基金将覆盖此次平台层面事件造成的影响。
-Bitget Wallet 为自托管钱包,运行于与… https://t.co/pZM4XzFolp
At 19:57, analyst DCF GOD pointed out a new wallet that spent $19.67 million in USDT0 to purchase 7,111 ETH over six minutes. The trades reportedly went through at prices as much as 5% above the market rate.
The pattern indicated that whoever was behind it wanted to shift funds rapidly. The purpose remained uncertain.
By 21:06, Bubblemaps noted about $180 million had been transferred from Bitget wallets to a single receiving address, later divided among multiple wallets.
In a security update, Chen initially estimated the loss at $351.6 million and said withdrawals had been halted.
The announcement arrived roughly three hours after Bitget said it detected the incident. The delay raises questions about the exchange's response, but it does not necessarily mean funds were still being drained during that interval.
Chen stated that the attackers broke into a crucial backend system — the software that controls wallet functions in the background.
They submitted fake transaction information and activated Bitget's approval mechanism. Put simply, the exchange's own system authorized the fraudulent movements.
Chen said theft of private keys was not the cause. A thorough public explanation is still needed regarding how the attackers accessed the backend and which security checks were bypassed.
Tough day for Bitget. I expect and know @Binance, the @BNBCHAIN ecosystem, and the community will do everything we can to help.
— CZ 🔶 BNB (@cz_binance) September 25, 2026
Stay SAFU! 🙏 pic.twitter.com/cyAEHdSi1S
Bitget updated its loss figure after factoring in impacted Zcash and TRON holdings. The exchange said the revision came from a more complete tally of the initial theft.
The firm said the vulnerability has been patched. It pledged to announce a withdrawal plan by 04:00 UTC on September 26, though it did not guarantee that withdrawals would resume at that time.
Chen pointed to IP patterns and blockchain activity that match those of North Korean groups. Several characteristics are similar to the February 2025 Bybit hack, which the FBI linked to North Korea.
These similarities warrant additional investigation. However, they alone do not identify who attacked Bitget.
Share to
Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.
A MetaMask security incident poses no immediate threat to wallets, but the company is exiting affected Lido staking validators as a precaution.
Misha Komarov from alloc/init discussed Shielded Bitcoin, a research concept using zero-knowledge proofs to hide transaction details, requiring no soft fork.
HSBC named its Hong Kong dollar stablecoin RedCoin, set to launch in H2 2026 via PayMe and HSBC HK app, but key details are missing.
MicroStrategy's Michael Saylor supports competitor Strive, saying its Bitcoin purchases benefit the broader sector. The firms also share financial ties.