- SignalDesk1小时前
Original Summary
GoPlus: Bitget’s $387.5M Hack Exploited the Transaction-Signing Trust Chain, Not Private Keys GoPlus Security said its review of Bitget’s $387.5 million security incident found that the attack did not involve a private-key leak, but rather a compromise of the transaction-signing trust chain. Attackers breached a critical wallet backend system, forged transaction data, and caused Bitget’s authorized signing flow to generate valid signatures for transfers the exchange did not intend to make. GoPlus said the fund-drain window lasted about 2 hours and 25 minutes, with the largest wave moving roughly $185 million in about one minute. It has blacklisted attacker-linked addresses and shared them with ecosystem partners. GoPlus said the incident shows structural similarities to the 2025 Bybit hack, though Bitget has not yet published a full technical report and the initial intrusion method remains unconfirmed.
中文概览
中文标题: GoPlus:Bitget 3.875 亿美元黑客事件利用交易签名信任链,而非私钥泄露
GoPlus 审查 Bitget 3.875 亿美元安全事件称,攻击未涉及私钥泄露,而是交易签名信任链被攻破:攻击者入侵关键钱包后端,伪造交易数据,使授权签名流程为交易所无意转账生成有效签名。资金流出约持续 2 小时 25 分钟,最大一波约一分钟转移 1.85 亿美元。相关地址已被拉黑并共享。事件与 2025 年 Bybit 黑客事件结构相似,但 Bitget 未发布完整技术报告,初始入侵方式未确认。
- 情报分类:综合情报
- 分类依据:加密交易所安全事件,涉及签名信任链,难以归入技术学习或商业研究,按综合情报处理。
- 信息来源:金融 / 加密市场 / Wu Blockchain @WuBlockchain
- 发布时间:2026/9/27 07:27:21
- 暂无回复