In a striking statistical shift, September witnessed a dramatic increase in the total value lost to cryptocurrency hacks, soaring to approximately $766.49 million. According to security firm PecShield, this figure represents a staggering 462% rise from August’s losses of $136.3 million. However, the majority of these losses can be attributed to two major incidents involving Bitget and Liquid Network, overshadowing the remaining 53 breaches.
Major Incidents Dominate Losses
PeckShield highlighted that the incidents involving Bitget and Liquid Network stand as the most significant crypto thefts of the year so far. The Bitget hack, which was reported on September 24, led to losses estimated at around $387 million. CEO Gracy Chen stated that the exchange’s security systems detected suspicious transfers from its hot wallets, exposing vulnerabilities in the backend infrastructure that allowed attackers to manipulate transaction data and authorize fund releases.
Chen assured users that the private keys remained uncompromised, emphasizing that the cold storage wallets which house the majority of their assets were unaffected. To mitigate the breach’s impact, Bitget plans to utilize its User Protection Fund, which contains over $464 million, to cover losses incurred by users. Chen conveyed determination in her statement:
“We won’t run away from this and every dollar will be held accountable.”
In a separate incident on September 6, Liquid Network experienced a breach wherein an alleged white-hat hacker withdrew around 4,000 BTC from the Liquid Federation wallet. Liquid clarified that the withdrawal utilized a SideSwap pegout authentication key that had not been compromised. The hacker communicated a commitment to return the funds once security measures were bolstered, though skepticism remains regarding the authenticity of such claims.
Trace Laundering and Continued Threats
Additionally, research from SlowMist revealed that hackers linked to North Korea are attempting to launder the stolen Bitget funds. They employ techniques involving CoW protocol order combinations with Chainflip deposit addresses and subsequently convert the proceeds to BTC, masking the movements through CoinJoin. SlowMist’s founder, Koss, criticized the lag in anti-money laundering measures against such automated laundering strategies.
Despite the large sums involved in the top two hacks, the other eight breaches within PeckShield’s top rankings reported losses ranging from $3.15 million to $7.81 million. One notable incident involved a front-running mechanism with the MEV bot named “yoink”. Additionally, a September 25 incident concerning Payment Processor V2 and the LimitBreak contract resulted in a reported loss of $6.6 million, with $3.4 million successfully returned due to efforts from security researchers.
The recent surge in hacking incidents underscores the ongoing vulnerabilities in the cryptocurrency ecosystem and highlights the need for continuous improvement in security protocols across platforms.
