Home Blog

Bitget Traces $387.5 Million Hack to Compromised Security Appliances

TL;DR

  • Bitget says two compromised third-party security products gave attackers a path into its wallet infrastructure and led to losses of about $387.5 million.
  • In its latest update, Bitget explains how the hack bypassed the controls that had already blocked user-initiated withdrawals.
  • Bitget has restored major withdrawals, replenished its protection fund above $300 million and continues tracing stolen assets.

Bitget says the hack that drained approximately $387.5 million from its wallet infrastructure began with the compromise of two third-party security products, at least one of them through a zero-day vulnerability. Preliminary forensic findings from Mandiant and SlowMist, released by Bitget on September 30, trace how the attacker moved from those appliances into the exchange’s wallet systems. Bitget says its private keys and cold wallets remained secure, based on its investigation so far.

Bitget updated the estimated value of stolen assets from $351.6 million to $387.5 million, reflecting a more complete accounting of affected transactions. The estimate now includes Zcash and Tron transfers that were not captured initially. The exchange says there were no additional losses after the incident was contained.

Compromised appliances opened a path to the wallet system

SlowMist traced the earliest malicious activity in the available logs to August 31. A zero-day vulnerability affected a service on one node of a security product that SlowMist calls Product A. Zero-day means the product’s maker did not know about the flaw, so no patch existed when the attacker used it. The attacker ran a hidden script under that service. The script read an environment variable containing a database password, which the attacker used to connect to the database. SlowMist found similar activity on two other nodes later in September.

Starting at 16:07 UTC on September 24, the attacker used an internal employee’s identity to access the management platform of a second product, Product B, and made three attempts to inject system commands. The attacker then uploaded malicious files.

Mandiant’s findings label two appliances A and B, which may be the same products SlowMist describes. They say the attacker installed a web shell, a hidden script that allows remote control of a server, on appliance B. The attacker opened a command-and-control connection, a channel for sending instructions to the compromised system. From there, the attacker moved into Bitget’s production wallet job server, which processes the exchange’s wallet operations, and deployed malicious packages.

SlowMist recovered a custom withdrawal tool from files the attacker had deleted. The tool was built around the wallet system’s withdrawal logic. It forged risk-control parameters in its own code and used them to build and submit withdrawal requests. Host logs show the program began running at 17:49 UTC, 42 minutes before the first transfer reached the attacker. CEO Gracy Chen said the attacker also deleted traces left by the commands, complicating the reconstruction of the incident.

On Bitget’s account, the theft did not depend on its private keys. Control of the wallet job server let the attacker issue withdrawals that the system treated as legitimate.

Bitget has not named the appliances or their vendor, or said whether the vendor has released a fix.

From two small transfers to $388 million

Chen said the attacker first tested Bitget’s controls at 18:31 UTC with two small unauthorized transfers of 0.84 ETH and 93 TRX. She said the transactions remained below existing risk thresholds before larger transfers followed.

Bitget’s updated timeline says its reconciliation system detected a significant discrepancy at 19:05 UTC. Its risk system then blocked user-initiated withdrawals across the platform. Mandiant’s report says Bitget’s monitoring detected the unauthorized transfers at 18:31 UTC, the time the timeline gives for the first transfers. However, the withdrawal block did not stop the attacker’s commands. Chen said 17 transactions across eight networks between 18:58 and 20:09 UTC moved about $361 million. SlowMist’s onchain records run from 18:31 to 21:23 UTC, a span of 2 hours and 52 minutes. After 21:22 UTC, the attacker tried to edit withdrawal records directly in the wallet database. He pushed two fabricated BTC withdrawal orders, which returned errors.

The full technical report will need to explain why the fraudulent commands kept executing for more than two hours after the block.

Bitget changes access and withdrawal controls

Bitget says it has restricted internal access to sensitive systems, added independent checks for withdrawals, and increased abnormal-activity monitoring. It also has begun reviewing how it assesses and deploys third-party security products. The exchange says the vulnerability identified within its own environment has been remediated.

Mandiant and SlowMist continue to support the forensic investigation and asset tracing. Bitget still describes that investigation as ongoing and says detailed findings will be disclosed through an official security report.

Protection fund replenished

Bitget reopened Bitcoin withdrawals on the Bitcoin and BNB Smart Chain networks on September 28. ETH followed on September 29, and USDT across Ethereum, BSC, Solana and Tron on September 30. Other supported tokens, fiat withdrawals and P2P services are due to return at 08:00 UTC on October 2.

Chen said on September 30 that the User Protection Fund had returned above $300 million, meeting her pledge to replenish it within a week using corporate reserves. Bitget’s latest Proof of Reserves snapshot, taken on September 29, showed an overall reserve ratio of 131% across 19 covered assets.

Bitget is still tracing assets stolen in the hack. Its bounty program offers participants 5% of eligible assets they help freeze, plus another 5% of funds they help recover successfully.

Circle and Tether have blacklisted an attacker-controlled wallet holding about 99,990 USDC and 218,023 USDT, freezing approximately $318,000 in stablecoins. The same wallet also held ETH, which the issuers cannot freeze through their token contracts.

NEAR Intents separately said it rejected more than $50 million in attempted transfers linked to the attackers, which then moved to other providers. It froze about $503,000 during execution.

Bitget says the vulnerability it identified in its own environment has been remediated, and withdrawals have reopened on that basis. The investigation behind that statement is still open. Mandiant bases its conclusions on the analysis completed so far, and Bitget says it will update its findings as the work continues. Two gaps remain: how the attacker got from the security products to the wallet server, and how activity first logged on August 31 went unnoticed until funds started leaving on September 24.

Citi Institutional Clients Can Accept Stablecoin Payments Through Coinbase

TL;DR

  • Citi institutional clients can accept stablecoin payments through Coinbase while receiving settlement in fiat through Citi.
  • Coinbase Payments powers stablecoin acceptance, while Citi provides banking infrastructure through Spring by Citi and its Virtual Account Wallet.
  • The service launches first in the United States, while supported stablecoins, fees, transaction volumes and wider rollout dates remain undisclosed.

Citi and Coinbase, the crypto exchange, announced on September 28 an expanded collaboration that lets Citi institutional clients accept stablecoin payments at checkout through Coinbase’s payments infrastructure. Stablecoins are digital tokens designed to track currencies such as the US dollar. Coinbase converts the payments into fiat, or conventional currency, and Citi settles the client’s funds as the bank of record.

The service gives large businesses a way to accept stablecoins without holding or managing them. The announcement also has Coinbase using Citi’s Virtual Account Wallet to power Coinbase Virtual Accounts for its payments customers. The work extends the companies’ October 2025 collaboration.

Merchants receive fiat, not stablecoins

The checkout process runs through Spring by Citi, the bank’s platform for merchant acquiring, gateway technology and settlement. Coinbase Payments powers the stablecoin acceptance.

A customer pays with a stablecoin, Coinbase converts the payment into fiat currency, and Citi settles those funds for the merchant. The merchant receives only fiat, with no custody of the tokens and no separate exchange step.

The announcement leaves out the supported stablecoins, blockchain networks, conversion fees and settlement times, and it does not say how refunds or chargebacks will work.

Coinbase gains access to Citi’s banking rails

The expanded collaboration also works in the opposite direction. Coinbase Virtual Accounts give payments customers bank-account-like functions for accepting, holding and paying fiat funds, and incoming fiat is converted automatically into stablecoins. Coinbase says the setup removes the need for companies to operate separate banking and stablecoin systems. Citi provides the regulated banking infrastructure behind the fiat accounts. Coinbase lists branded virtual accounts for a client’s own customers among the things businesses can build on Coinbase’s payments infrastructure.

Launching first in the United States

Both initiatives are launching there first. Transaction volumes, merchant names and dates for expansion into other countries remain undisclosed, as does whether every eligible institutional client can activate the service immediately.

The October 2025 announcement covered fiat pay-ins and pay-outs for Citi’s institutional clients, supporting Coinbase’s on-ramps and off-ramps, the systems that convert between fiat and digital assets. Stablecoin payout methods were to be explored. The new service adds stablecoin acceptance to Citi’s merchant-payment channel.

Paying in stablecoins, settling in fiat

Stablecoins can move through blockchain networks outside banking hours, but businesses often need fiat for payroll, suppliers and other conventional payments. Splitting the roles between Coinbase and Citi could lower the operational burden for merchants. The companies put the market at more than 150 million stablecoin holders worldwide.

Citi and Coinbase plan to continue collaborating on additional capabilities in the coming months.

Senate Report Questions Tether’s Response to 846 Iran-Linked Wallets

TL;DR

  • A Senate Democratic report found that 84% of 846 Iran-linked wallets transacted exclusively or nearly exclusively in Tether’s USDT.
  • The report alleges Tether acted too slowly in several sanctions-related cases, while Tether says it froze about $550 million tied to Iran-linked wallets during 2026.
  • Democratic staff asked the Treasury and Justice departments to investigate Tether’s anti-money-laundering and sanctions compliance and requested responses by October 9, 2026.

Sen. Richard Blumenthal, a Democrat, released a report on September 28, 2026 finding that 84% of 846 Iran-linked wallets transacted exclusively or nearly exclusively in USDT, the dollar-pegged stablecoin issued by Tether. U.S. and Israeli authorities had designated the wallets over ties to Iran and its regional proxies.

Tether published its own tally of Iran-linked freezes the same day.

846 wallets

The report examined 846 wallets that authorities had designated in orders issued between June 2021 and August 2026. Two agencies issued the orders. The first is the U.S. Treasury’s Office of Foreign Assets Control (OFAC), which administers and enforces U.S. sanctions. The second is Israel’s National Bureau for Counter Terror Financing (NBCTF), which targets terrorist financing. Investigators reviewed transactions tied to oil sales, cross-border transfers and efforts to support Iran’s currency. The activity included transfers involving the Central Bank of Iran, the country’s central monetary authority.

Of the 846 wallets, 84% transacted exclusively or nearly exclusively in USDT. Broken down by source, 87% of the 757 NBCTF wallets and 57% of the 101 OFAC wallets predominantly used USDT. The report defines predominantly as more than 80% of a wallet’s aggregate transaction value. Investigators also found dozens of additional suspicious wallets with their own forensic tools and excluded them from the aggregate figures.

Tether is the world’s largest stablecoin issuer, with about 60% of the stablecoin market by the report’s figures. USDT emerged as a preferred cryptocurrency among the designated wallets between 2023 and 2024, while earlier designations more often involved Bitcoin. The report describes its conclusions as preliminary.

The report’s case on freeze timing

Tether can blacklist a wallet address, which freezes the USDT it holds so the tokens cannot move. Democratic staff allege that Tether either did not use that power on designated wallets or used it late, and the report points to four cases.

From 2021 through May 2023, Tether did not appear to freeze any NBCTF-designated wallets. It became regularly responsive after the October 7, 2023 Hamas attacks.

In June 2023, Israel designated 39 wallets tied to Tawfiq Muhammad Sa’id Al-Law. The report calls him a Hezbollah money launderer. Tether blacklisted five of the wallets and froze the other 34 in March 2024, shortly before OFAC sanctioned Al-Law. Investigators calculated that more than $34.6 million left the wallets after Israel published its seizure notice.

OFAC sanctioned the fundraising group Gaza Now in March 2024 for supporting Hamas. Tether did not freeze wallet addresses the group posted publicly on Telegram during 2025, and those wallets kept receiving contributions.

Babak Zanjani, an Iranian financier under U.S. sanctions, posted Central Bank of Iran wallet addresses on X in December 2025. Staff review of blockchain records indicated that Tether had not blacklisted them as of September 2026.

The report argues that a freeze after designation cannot pull back funds that have already left a wallet, which makes reactive action insufficient.

Tether’s $550 million tally

Tether says actions involving USDT froze approximately $550 million during 2026. By Tether’s account, U.S. authorities linked the wallets to the Central Bank of Iran and sanctions networks. In April, Tether said, it froze more than $344 million across two addresses on information from OFAC and U.S. law enforcement. Its release says OFAC formally added the same addresses to the Central Bank of Iran designation the next day. In July, the company reported a freeze of more than $130 million across four wallets. Treasury had added four addresses on the TRON blockchain to the designation. The release describes the two actions as together amounting to approximately $550 million, though the named figures add up to more than $474 million.

Beyond Iran, Tether’s wider freeze record

Israel’s NBCTF has worked with Tether for several years, according to the company. In 2023, Tether disclosed freezing 32 addresses holding $873,118.34 in alignment with the bureau. The company says it has frozen more than 22 million USDT across over 40 NBCTF-referred cases involving more than 640 addresses.

Across all case types, Tether puts its total at more than $4.9 billion frozen, with more than $2.4 billion connected to U.S. authorities. It says it works with more than 340 law enforcement agencies in 67 countries. Tether, TRON and blockchain analytics firm TRM Labs launched the T3 Financial Crime Unit in September 2024 to trace and freeze illicit USDT on the TRON blockchain. The unit reported in May 2026 that it had frozen more than $450 million. In June 2025, the Justice Department filed a forfeiture complaint against more than $225.3 million in cryptocurrency. The complaint links the funds to investment-fraud money laundering, and the department thanked Tether for its proactive assistance. A Secret Service official called the seizure the largest cryptocurrency seizure in the agency’s history.

Chief Executive Paolo Ardoino said USDT is not a haven for sanctioned actors, terrorist organizations or criminal networks. While the report faults the company for leaving wallets untouched even where public evidence tied them to illicit finance, Ardoino reiterated that Tether acts when law enforcement provides credible information.

Tether confirmed receiving Blumenthal’s June 4 request for records. The report says the company had not responded by the time of publication.

Blumenthal takes the findings to Treasury and Justice

Sen. Richard Blumenthal of Connecticut is the top Democrat on the Senate Permanent Subcommittee on Investigations. The subcommittee sits under the Senate Committee on Homeland Security and Governmental Affairs. He led the inquiry through the subcommittee’s Democratic staff.

On September 28, Blumenthal sent the report to Treasury Secretary Scott Bessent and Attorney General Todd Blanche in two separate letters. Sen. Ron Johnson, the subcommittee’s Republican chair, received copies of both.

Each letter asks the department to investigate Tether’s anti-money-laundering and sanctions compliance. Each also urges the strongest appropriate action if the department finds violations of the Bank Secrecy Act, the International Emergency Economic Powers Act or other federal law.

The letters say the Democrats’ investigation covers the illicit use of cryptocurrencies and the Trump administration’s self-enrichment and self-dealings with cryptocurrency firms. They point to Tether’s ties to the administration. Commerce Secretary Howard Lutnick ran Cantor Fitzgerald until recently, and his children now control the firm. The letters say it owns 5% of Tether. Bo Hines joined Tether after leaving his White House digital-assets role. The report says Tether reportedly gave Lutnick’s children a loan.

Answers requested by October 9

Both letters ask the departments to respond by October 9, 2026. They cite media reports that prosecutors in the Southern District of New York opened a Tether investigation in October 2024. According to the same reporting, the Treasury Department weighed sanctioning the company around then. Each letter asks whether that department has narrowed, paused, deprioritized or closed its inquiry.

Kalshi Loses Appeal Over Ohio and Tennessee Sports Betting Rules

TL;DR

  • A federal appeals court cleared Ohio and Tennessee to enforce their sports betting laws against Kalshi while the underlying lawsuits continue.
  • The Sixth Circuit rejected Kalshi’s argument that federal commodities law currently shields its sports contracts from state enforcement.
  • The decision adds to a widening split among federal appeals courts over whether states can regulate sports contracts offered by prediction markets.

A US appeals court has cleared Ohio and Tennessee to enforce their sports betting laws against Kalshi, a prediction market platform, while lawsuits over its sports-event contracts continue. The September 25 ruling removes a court order that had protected Kalshi from Tennessee enforcement and leaves an earlier Ohio decision against the company in place.

The dispute turns on whether a federal license to operate an event-contract exchange shields a platform from state rules when customers trade on sports results. For these two states, a three-judge panel of the Sixth Circuit said Kalshi had not shown that it does.

What changed in each state

Ohio and Tennessee regulators had told Kalshi to stop offering sports contracts to residents without state sports wagering licenses. Kalshi sued, arguing that federal commodities law gave the Commodity Futures Trading Commission (CFTC) exclusive authority over its exchange.

Ohio’s Casino Control Commission issued its order in March 2025, saying the contracts were open to people younger than 21. A federal judge refused Kalshi’s request to block the order in March 2026, and the appeals court upheld that decision. In April, the commission proposed a $5 million fine against Kalshi for offering unlicensed sports gaming.

Tennessee’s Sports Wagering Council issued its order in January 2026, and Kalshi won a temporary block within days. A federal judge turned that into an injunction in February. The appeals court vacated the injunction and sent the case back to the lower court. The council’s order can now be enforced.

Why the federal license did not settle the dispute

Kalshi operates a federally regulated designated contract market. On its platform, a sports-event contract pays out according to an outcome, such as which team wins a game. Kalshi argued that these contracts qualify as financial instruments called swaps. Federal law gives the CFTC exclusive jurisdiction over certain swaps traded on designated markets.

The Sixth Circuit rejected the argument at this stage. The court read the statutory definition to cover events with a direct financial consequence, such as an interest rate rise or a debt default. Effects of a game on sponsors, advertisers and local businesses were too indirect and speculative to meet that definition. The opinion also noted Kalshi’s earlier concession that its sports contracts have no inherent economic significance.

Addressing Kalshi’s fallback argument, the judges said that even if the sports contracts counted as swaps, the federal Commodity Exchange Act would not override Ohio’s or Tennessee’s sports gambling laws. Those laws govern wagering in the states and only incidentally affect a federally regulated exchange, the panel reasoned.

A Kalshi spokesperson told The Block that the law does not require a swap to involve intrinsic financial consequences, and that sports have them anyway. The company said differing state rules make operating unworkable and does not believe the ruling will survive further review.

What this means for users and other prediction markets

Whether Kalshi customers in Ohio and Tennessee keep access to sports contracts depends on what the states and Kalshi do next. Both states are free to act on their orders, which demand that Kalshi stop offering sports contracts to residents without a state license.

Users of other prediction markets have a stake as well, because regulators in both states sent orders to other providers. Ohio sent cease-and-desist notices to Robinhood and Crypto.com in March 2025, the same day as the one to Kalshi. Tennessee’s January order named Polymarket and Crypto.com’s Nadex.

The national picture remains unsettled. The Third Circuit previously sided with Kalshi in a New Jersey case at the preliminary stage, while the Ninth Circuit ruled against it in Nevada. New Jersey has asked the US Supreme Court to review its case. Kalshi’s appeal in a Maryland case is pending before the Fourth Circuit, which would be the fourth federal appeals court to rule on the company’s sports contracts.

The conflict runs between regulators as well as between courts. The CFTC, under Chair Michael Selig, holds that it alone oversees event contracts on designated exchanges, and it filed a brief backing Kalshi in the Ohio appeal in May. Numerous states have taken enforcement action or sued Kalshi over its sports contracts. New York sued Kalshi on July 31 to stop it from operating without a state license. The petition seeks restitution and penalties, including $100,000 for each unauthorized offer of sports wagering. New York sued Polymarket US on September 24, one day before the Sixth Circuit ruled. Polymarket filed its own federal lawsuit against the state and its Gaming Commission the same day, arguing that states cannot regulate swaps.

Crypto’s Next Big Bet? Gibraltar Goes All-In on Prediction Markets

Prediction markets are rapidly moving from a niche corner of online betting and crypto into a potentially significant new global industry.

The concept is simple: instead of betting against a traditional bookmaker, participants trade contracts based on whether a future event will occur. These events can range from elections and interest-rate decisions to economic indicators, technology developments, entertainment and sporting outcomes.

What makes prediction markets particularly interesting is that they sit at the intersection of gambling, financial markets, data and increasingly cryptocurrency. That convergence has created enormous commercial opportunities — but also a regulatory challenge.

While many jurisdictions are still debating whether prediction markets should be treated as gambling, derivatives or something entirely new, Gibraltar has taken a different approach: regulate them.

Gibraltar Moves First

In July 2026, Gibraltar introduced the Prediction Market Regulations 2026, establishing a dedicated regulatory framework specifically addressing prediction-market activity. The regulations came into force on 13 July. Specific Prediction Market Fees and Duties Regulations followed in August (scroll down to read the full regulation.).

This puts Gibraltar among the most advanced jurisdictions globally. Instead of forcing a new technology and business model into an old regulatory box, it provides a specific legal route for prediction-market businesses.

Importantly, this is not merely legislation waiting for an industry to arrive.

Gibraltar’s official register already includes Predict Street Limited and Wire Action Markets Limited, trading as WagerWire, as B2C betting intermediaries.

Why Prediction Markets Are Growing

Traditional betting asks: Who will win the match?

Prediction markets can ask almost anything. Will inflation be above 3% in December? Will a particular cryptocurrency exceed a certain valuation? Will a company launch a product before a specified date? Will a political or economic event occur?

Market prices continuously reflect what participants collectively believe the probability of an outcome to be.

This creates possibilities extending far beyond conventional gambling. Prediction markets can become tools for aggregating information, measuring sentiment and potentially forecasting economic, financial and commercial events.

But this expansion also creates questions around consumer protection, market manipulation, insider information, AML controls and the distinction between gambling and financial instruments.

That is precisely why regulatory clarity matters.

Where Crypto Enters the Picture

The convergence between prediction markets and digital assets could be particularly significant.

Blockchain technology can potentially provide transparent settlement, auditable transaction histories and smart-contract-based execution. Stablecoins could also enable efficient international deposits and settlement without some of the friction associated with traditional cross-border payment systems.

A prediction contract could, for example, be created digitally, traded between participants and automatically settled following verification of the relevant real-world outcome.

Gibraltar is well positioned for this convergence because it already has experience regulating both industries.

Its Distributed Ledger Technology regulatory framework dates back to 2018. Since then, Gibraltar has continued developing legislation covering digital assets, tokenisation and virtual-asset market infrastructure.

The Government has also publicly identified stablecoins and digital payments infrastructure as an area of increasing importance to Gibraltar’s internationally focused gaming and financial-services sectors.

This potentially creates an attractive regulatory environment for the next generation of prediction platforms: businesses combining a regulated prediction-market operation with blockchain infrastructure, digital wallets, stablecoin payments or other regulated virtual-asset services.

Such structures will not automatically fall under one licence. Depending on precisely how crypto assets are held, exchanged, transferred or used, additional financial-services or DLT regulatory requirements may apply. But Gibraltar has the advantage of having established regulatory expertise on both sides of the equation.

As prediction markets increasingly converge with crypto and financial technology, regulatory certainty may become one of the industry’s most valuable assets. And once again, Gibraltar has chosen to move early while the rest of the world still decides what comes next. 

source gibraltarlaws.gov.gi

- Advertisement -

FEATURED