在上周针对加密货币交易所 Bitget 的网络攻击中被盗的近 3.88 亿美元中,约有 110 万美元已被冻结,该平台仍在继续努力追踪和追回资产。
Approximately $1.1 million of the nearly $388 million stolen from crypto exchange Bitget in last week’s cyberattack has been frozen, as the platform continues efforts to trace and recover the assets.
首席执行官陈茜(Gracy Chen)在接受 CNBC 电子邮件采访时表示,冻结的资产不一定已归还给交易所。她未透露已追回多少资金。
Frozen assets had not necessarily been returned to the exchange, CEO Gracy Chen told CNBC in an email interview. She did not disclose how much had been recovered.
陈茜周三在 CNBC 节目“Squawk Box Europe”上表示,她“不指望能追回大量资金”,并援引了以往加密货币交易所黑客攻击事件中有限的追回情况。不过她说:“交易所有责任展示其如何保护用户,尤其是在出现问题时。”Bitget 表示用户账户余额未受影响。
Speaking on CNBC’s “Squawk Box Europe” on Wednesday, Chen said she was “not expecting to recover a lot of funds,” citing the limited recovery from previous cryptocurrency exchange hacks. However, “exchanges have a responsibility to demonstrate how they protect users, particularly when something goes wrong,” she said. Bitget said user account balances were unaffected.
该交易所表示,其保护基金在被盗前价值超过 4.64 亿美元。据彭博社根据该基金披露的钱包地址计算,黑客攻击后该基金一度降至 2 亿美元以下,随后又恢复至 3 亿美元以上。陈茜表示,补充后的基金仍可在链上公开验证,且独立于支持客户余额的储备金。
The exchange valued its protection fund at more than $464 million before the theft. It was drawn down to below $200 million following the hack, according to Bloomberg's calculation of the fund's disclosed wallet addresses, before being restored to more than $300 million. Chen said the replenished fund remained publicly verifiable on-chain and was separate from the reserves backing customer balances.
Bitget 基于 9 月 29 日快照的最新储备金证明显示,其自报的整体储备率为 131%,所有 19 种涵盖资产的储备率均超过 100%。
Bitget’s latest Proof of Reserves based on a Sept. 29 snapshot, showed a self-reported overall reserve ratio of 131%, with all 19 covered assets backed above 100%.
陈茜表示:“我们使用 Bitget 自有资金恢复了该基金。财务影响由 Bitget 自行承担,而非转嫁给用户。”
“We restored the Fund using Bitget’s own capital,” Chen said. “The financial impact is being absorbed by Bitget rather than passed on to our users.”
Google Cloud 旗下 Mandiant 和区块链安全公司 SlowMist 于 9 月 30 日发布的调查报告发现,攻击者在入侵 Bitget 生产钱包系统前,先攻破了两款第三方安全产品。
Investigation reports released Sept. 30 by Mandiant part of Google Cloud, and blockchain security firm SlowMist found that the attackers compromised two third-party security products before gaining access to Bitget’s production wallet systems.
SlowMist 将可用日志中最早的恶意活动追溯至 8 月 31 日,当时攻击者利用了其中一款产品中一个此前未知的零日漏洞。
SlowMist traced the earliest malicious activity in available logs to Aug. 31, when a previously unknown, or zero-day, vulnerability was exploited in one of the products.
Mandiant 报告称,攻击者随后获得了内部特权访问权限,并在未窃取私钥的情况下绕过了正常的面向客户的提币流程。
The attackers were then able to obtain privileged internal access and bypass the normal customer-facing withdrawal process without stealing private keys, Mandiant reported.
“我认为这种手法相当复杂,”陈女士在《Squawk Box Europe》节目中表示,并补充说攻击者在转账后删除了痕迹以阻碍调查。
“The method, I would say, is quite sophisticated,” Chen said on “Squawk Box Europe,” adding that the attackers deleted traces after transfers to hinder the investigation.
两份报告均未指出受影响的安全产品。当被问及时,陈女士拒绝透露更多供应商或产品细节,理由是发布已公布调查结果之外的信息可能会带来额外的安全风险。
Neither report identified the affected security products. When asked, Chen declined to disclose further vendor or product details, citing the potential to introduce additional security risks by releasing information beyond the published findings.
报告并未将攻击归咎于朝鲜。陈女士此前曾表示,初步技术指标与已知朝鲜黑客组织高度一致。“我们还得进一步等待这方面的详细信息,”她告诉 CNBC。
The reports did not attribute the attacks to North Korea. Chen had previously said preliminary technical indicators were highly consistent with known North Korean hacking groups. "We will have to wait further for further details on this," she told CNBC.
比特币、以太坊和 USDT 的提币服务已恢复。Bitget 已安排其余加密货币的提币服务,以及法币和点对点服务于周五恢复。
在 Google 上
Withdrawals for bitcoin, ether and USDT have resumed. Bitget has scheduled withdrawals for its remaining cryptocurrencies, along with fiat and peer-to-peer services, to resume on Friday. Choose CNBC as your preferred source on Google and never miss a moment from the most trusted name in business news.