Bitget says approximately $387.5 million was transferred to attacker-controlled addresses in Thursday’s breach. CEO Gracy Chen described attackers compromising a wallet backend and tricking the exchange’s authorization process into approving transfers, rather than stealing private keys. Withdrawals were suspended. The company says the vulnerability has been remediated and is working with Mandiant and SlowMist on the investigation.
We have now watched Coldcard, Liquid and Bitget suffer very different compromises in a short period. None was a failure of bitcoin’s base-layer consensus, but each exposed a weakness in the systems people use to hold or move value. My read is that we are seeing the beginning of an AI-driven cascade of compromises. Digital money is an obvious early target: find the vulnerability, exploit it and take the money. The reward is immediate, and the entire process can happen online.
I expect this to accelerate over the next six months and spread further into the rest of the digital world. Attackers and defenders have access to increasingly capable tools, and the race is to find weaknesses before the other side does. Some businesses strengthen their security before a compromise. Others get a very expensive lesson first. Bitcoin and crypto have a powerful incentive to adapt quickly because the money is sitting right there. Critical infrastructure operators face the same technological shift, often with older systems and much less room for disruption.
We already have a preview. The Colonial Pipeline ransomware attack in May 2021 hit its business IT systems and prompted the company to shut down pipeline operations, disrupting fuel supplies along the East Coast. Attackers did not need to take direct control of pipeline equipment to create a physical-world problem. An exchange losing money is bad enough. A compromised system that stops fuel, water or hospital operations is a different order of problem. I think we are going to see a lot more of it. Prepare accordingly.