Bitget CEO says $388M hack exploited third-party security vulnerability
Related
Bitget CEO suspects North Korea behind $352M hack, citing IP clues
Bitget CEO Gracy Chen said a preliminary investigation found IP addresses matching VPN choices associated with a DPRK hacking group.
Crypto hacker losses decreased by 47% year-on-year in the first half of 2026, but the overall security situation has not improved.
According to Foresight News , citing Cointelegraph, total losses from cryptocurrency security incidents in the first half of 2026 amounted to approximately $1.32 billion, a 46.8% decrease year-over-year. However, CertiK warns that this figure is misleading. The data from the same period last year was severely distorted by the massive $1.4 billion theft from Bybit, the largest single hack in history. In reality, attackers are becoming more targeted and destructive. Specifically, phishing attacks resulted in $508.2 million in losses in the first quarter, while losses in the second quarter rose 59% quarter-over-quarter to $807.5 million. Over 70% of these losses came from the KelpDAO and Drift Protocol incidents, both believed to be the work of North Korean state-sponsored hackers. A report from TRM Labs during the same period also indicated that the number of attacks surged from 83 to 207 in the first half of the year, the highest on record, with smart contract vulnerability attacks accounting for 60%. CertiK also points out that private key and multi-signature wallet management remain the most vulnerable security areas that attackers can exploit. He recommends that protocol providers strengthen private key management from multiple levels, including hardware security, multi-signature governance, and geographically dispersed signers.
Gnosis Pay Security Incident Recap: Vulnerability stemmed from a flaw in signature verification logic; fix completed.
According to Foresight News , Gnosis Pay released a post-incident report on June 1st, disclosing that the root cause of the vulnerability was a flaw in the ERC-1271 signature verification logic within the Zodiac module: the system only reads the contract's return result and does not check whether the call was actually executed successfully. Attackers exploited this flaw to deploy a contract that intentionally failed but still returned a "valid" status, forged authorization, and then withdrew funds from accounts not owned by them. This vulnerability was introduced with Zodiac code version 3.4.0 in October 2023 and was patched on June 5th. The report shows that attackers withdrew approximately $1.5 million from 5,281 wallets, including approximately $641,000 in GNO, approximately $453,000 in EURE, and approximately $399,000 in USDC.e; another approximately $300,000 is locked in inaccessible accounts, and the team is exploring recovery methods. Gnosis Pay stated that it will expand its security team, introduce external audits, broaden the scope of smart contract audits, and has completed a complete product rebuild (v2) to improve its security response capabilities.
David Sacks strongly supports Palantir CEO's criticism of AI labs: True enterprise AI security lies in controlling one's own data, models, and computing power.
According to Beating, David Sacks, co-chair of the U.S. President's Council of Advisors on Science and Technology, published an article supporting Palantir CEO Alex Karp's sharp criticism of cutting-edge AI labs, stating that the mainstream media's portrayal of his interview as a "disastrous outburst" precisely demonstrates that Karp hit the nail on the head. Sacks points out that true "AI security" in a corporate environment is not abstract "alignment research" or government-led certification systems, but rather the ability to control one's own data, model weights, and computing power—preventing cutting-edge labs from "absorbing" a company's proprietary knowledge and turning it into the next product. He quotes Karp as saying, "They want to own their means of production, not hand them over to others." Sacks cites the conflict between Figma and Anthropic as a prime example: three days before the release of Claude Design, Anthropic's Chief Product Officer was still a member of Figma's board of directors, and Figma's founder stated that Anthropic "hadn't always been honest with them"; subsequently, Figma's stock price plummeted while Anthropic's valuation soared. He further listed products such as Claude Science, Claude Security, Claude Legal, and Claude Code, pointing out that Anthropic consistently targets vertical sectors originally served by companies that relied on its models, following a consistent pattern: "Observe where value is created first, then jump in." Sacks believes that the perception of open-source models as "dangerous" is not true for companies—retaining choice at the model layer and deciding who can use their core strengths is the real bottom line for corporate security. Previously, Palantir partnered with NVIDIA to deploy Nemotron's open AI models in sovereign environments, serving the US government and critical infrastructure customers, helping organizations train and deploy AI locally while maintaining complete control over data and intellectual property. Palanitir CEO Alex Karp recently gave a scathing interview on CNBC's "Squawk Box," criticizing leading AI model companies as "completely wrong" in their approach to selling AI. Karp emphasized that companies are currently dissatisfied with "cutting-edge labs" like OpenAI and Anthropic, believing they only pursue token maximization, wasting companies' time and money while handing over proprietary value and intellectual property. Karp stated that companies are "angry" and will strive to own their own AI production resources rather than relying on third parties. On June 29th, Palantir partnered with Nvidia to deploy Nvidia Nemotron open AI models in a sovereign environment, primarily serving the US government and critical infrastructure.
Bitget resumes Bitcoin withdrawals as hacker swaps ETH via THORChain
Ether withdrawals are scheduled to return Tuesday and USDt on Wednesday as Bitget restores services following last week’s $388 million hack.
Bitget Hack Losses Climb to $387M: Here’s What Happened, and Why North Korea Is a Suspect
An attacker faked internal transfer requests to drain $387.5 million from Bitget's hot and warm wallets, and the exchange's CEO says the fingerprints look like Pyongyang's.