Bitget clarifies $388M in assets affected by security breach
Related
Bitget confirms $351M security breach, suspends withdrawals
Bitget said unauthorized transfers affected a limited number of hot wallets, while cold wallets and most platform assets remained unaffected.
Security firm Coinspect reports that a wallet vulnerability dating back to 2018 resulted in the theft of $3.14 million last month, with Chinese users' assets at higher risk.
PANews reported on July 5th that security firm Coinspect Security published an article on the X platform stating that through analysis of crypto wallet seeds generated using insecure code since 2018, they discovered thousands of seeds that had been actually used. Last month alone, they found that these wallets had a total of $3.14 million stolen, most of which went unreported. Some funds were concentrated in a single address, exhibiting money laundering patterns. One affected address transferred $2 million out just hours after the alert was issued; it is unclear whether this was for theft. Coinspect warned that users who believe many of their assets remain at risk may be located in China.
Richard Teng posted an article regarding the MiCA transition: Affected users' assets are safe, and withdrawals can still be made after July 1st.
According to Foresight News , Binance Co-CEO Richard Teng stated that Binance is facilitating the MiCA compliance transition. Affected users' assets are safe, and they can still use previously announced options such as withdrawals after July 1st. He said the platform is directly communicating with affected users regarding subsequent steps and reminded users with account issues to contact customer service through official channels.
SecondFi Important Security Notice: A mechanism will be launched early next week to help users check if their wallets have been affected.
According to Foresight News , SecondFi has issued an important security alert, stating that there has been an increase in malicious activity and impersonation attempts related to certain incidents recently. As a precaution, users are advised not to deposit any additional funds into their existing SecondFi wallets until further notice. SecondFi will launch a mechanism early next week to help users check if their wallets have been affected and to provide a secure process for smoothly removing assets from the platform afterward. No user-initiated recovery operations have been initiated at this stage, and users' wallets should remain undisturbed until official recovery instructions are received. SecondFi will not request private keys, seed phrases, or wallet credentials under any circumstances, nor will it ask users to transfer assets. For support, please submit your request only through official support channels.
Reflect announced a recovery plan for USDC+ position holders affected by the Drift hack.
BlockBeats reported on July 2nd that Reflect, the a16z-backed stablecoin protocol, announced an independent voluntary recovery plan for USDC+ position holders affected by the April Drift (now Velocity) hack. Starting immediately, a 180-day window is open for holders to voluntarily sell their positions to Palindrome Engineering at a price of 0.20 USDC + 80 Reflect Credit (RC) per unit, with fully on-chain settlement. This plan is pre-funded by Palindrome and is completely independent of the Drift recovery process. Participation means relinquishing recourse to Drift in exchange for immediate, deterministic liquidity; non-participation will still support the Drift DFX recovery channel.
EMURGO announced that SecondFi, the Cardano wallet that was hacked, will permanently cease operations.
ChainCatcher reports that Cardano's founding entity, EMURGO, stated on Monday that SecondFi, the wallet service that suffered a hack, will not resume normal operations even after a security audit is completed. All users are required to migrate their assets through the official recovery process. SecondFi is a rebranded version of the Yoroi wallet and is described by EMURGO as Cardano's largest wallet provider. According to EMURGO's incident report on June 25th, the service suffered four separate wallet thefts on June 22nd, with 374 addresses compromised and approximately 16 million ADA (worth about $2.4 million at the time) stolen. The team also took emergency measures to recover approximately 129 million ADA. EMURGO stated that compromised wallets should be considered permanently exposed at the address and private key levels, and restoring the damaged seed phrase to other wallets cannot eliminate the risk. EMURGO plans to launch an isolated wallet state inspection tool this week, followed by a secure export tool and an offline migration workshop in Tokyo. They are also building a dedicated recovery fund for the on-chain recovery system, and will return assets to affected users after the external audit is completed.