SEC Commissioner Hester Peirce steps down October 2; Bitget suffers $185M fund drain in 2.5 hours via transaction-signing exploit; 53 Robinhood Chain tokens traced to coordinated rug-pull extracting $18.43M.
Security & Exploits ·
Security researchers at GoPlus determined that Bitget's $387.5 million incident stemmed not from leaked private keys but from a compromised transaction-signing infrastructure. Attackers accessed a critical wallet backend system, manipulated transaction data, and tricked Bitget's signing process into authorizing transfers the exchange did not authorize. The fund drain unfolded over approximately 2 hours and 25 minutes, with a single peak wave moving roughly $185 million in one minute.
GoPlus has blacklisted attacker-associated addresses and distributed them to ecosystem partners. The attack shows structural parallels to a 2025 Bybit hack, indicating a potential pattern of similar trust-chain exploitation across exchanges. The exact entry point and initial intrusion method have not yet been confirmed, and Bitget has not released a comprehensive technical postmortem.
Separately, researchers traced 53 token launches on Robinhood Chain to a coordinated rug-pull scheme that extracted at least $18.43 million. The scale and coordination across multiple tokens suggests a systematic operation rather than isolated fraud.