GoPlus: Bitget’s $387.5M Hack Exploited the Transaction-Signing Trust Chain, Not Private KeysGoPlus Security said its re | Hanami
GoPlus: Bitget’s $387.5M Hack Exploited the Transaction-Signing Trust Chain, Not Private Keys
GoPlus Security said its review of Bitget’s $387.5 million security incident found that the attack did not involve a private-key leak, but rather a compromise of the transaction-signing trust chain. Attackers breached a critical wallet backend system, forged transaction data, and caused Bitget’s authorized signing flow to generate valid signatures for transfers the exchange did not intend to make.
GoPlus said the fund-drain window lasted about 2 hours and 25 minutes, with the largest wave moving roughly $185 million in about one minute. It has blacklisted attacker-linked addresses and shared them with ecosystem partners. GoPlus said the incident shows structural similarities to the 2025 Bybit hack, though Bitget has not yet published a full technical report and the initial intrusion method remains unconfirmed.