Bitget had 30 minutes to contain its hack before $290 million started moving
Hypernative places the major transfer waves roughly 30 and 45 minutes after Bitget's reported detection. The post Bitget had 30 minutes to contain its hack before $290 million started moving appeared first on CryptoSlate.
Bitget detected unauthorized wallet transfers about 30 minutes before attackers began draining hundreds of millions of dollars from the crypto exchange, raising questions about why its security response failed to contain the breach.
The exchange said its systems flagged unauthorized transfers at 18:31 UTC on Sept. 24 and that its security team immediately activated emergency protocols.
However, blockchain security firm Hypernative's reconstruction of the attack shows that most losses came later: $87.6 million left hot wallets at 19:01, and another $202.8 million left warm wallets at 19:16.
Those two bursts, completed in a combined 24 seconds, accounted for about three-quarters of the $387.5 million Bitget ultimately said was moved to attacker-controlled addresses.
The sequence suggests Bitget had roughly half an hour after its initial alert to prevent the first major wave and about 45 minutes before the largest transfer burst. It also shifts scrutiny from how the attacker first gained access to how the exchange responded once its own systems indicated something was wrong.
Hypernative said the attacker initially tested the compromised route at 18:31 with transfers of 0.84 ETH and 93 TRX to new addresses. After waiting about 28 minutes, the attacker moved $34.75 million of USDT at 18:58 before accelerating the drain across multiple blockchains.
Bitget said its investigation found that the attacker compromised a backend system in its wallet infrastructure, spoofed withdrawal data, and tricked the exchange's authorization process into approving the transfers. The company said private keys were not compromised.