Bitget confirms $351.6 million security incident as New York sues Polymarket

Bitget confirms $351.6 million security incident as New York sues Polymarket

N
News Editor
2026-09-25 13:48:48
WuBlockchain’s daily crypto news roundup covered five separate developments across exchanges, regulation, corporate treasury strategy, and NFT security. Bitget CEO Gracy Chen said the exchange detected unauthorized transfers from some hot and warm wallets on Sept. 25, with estimated losses of about $351.6 million. The company said cold wallets and Bitget Wallet were not affected, user balances remain intact, and losses will be covered by its user protection fund. Bitget’s security team said it has preliminarily ruled out a private key leak, adding that the attacker appears to have compromised a critical backend wallet service, forged transfer information, and triggered the authorized signing process. Withdrawals have been temporarily suspended. In the U.S., New York state filed suit against prediction market platform Polymarket, accusing it of operating an illegal gambling business in the state. The Federal Reserve also released two proposed rules tied to the GENIUS Act stablecoin framework. Elsewhere, Sequans Communications said it sold its remaining 314 BTC and ended its bitcoin treasury strategy, while Magic Eden said older EVM listings may have been exposed to a Limit Break Payment Processor V2 flaw that led white hats to secure 23,155 NFTs.

Bitget says $351.6 million was involved in a security incident

Bitget CEO Gracy Chen said the exchange discovered unauthorized transfers from some hot wallets and warm wallets on Sept. 25, with an estimated $351.6 million involved. According to Chen, Bitget’s cold wallets and Bitget Wallet were not affected, user balances remain intact, and losses will be covered by the platform’s user protection fund.

Bitget’s security team said its preliminary assessment points to a compromise of a critical backend system tied to wallet services. The attacker allegedly forged transfer information and used the authorized signing process to move funds out. The company said it has preliminarily ruled out a private key leak, completed loss containment, and temporarily suspended withdrawals.

Bitget is investigating the incident with Mandiant and SlowMist. Bybit and Binance also said they are helping track and recover the stolen funds. Specter said some on-chain fund links suggest the attack may be connected to Lazarus Group, though Bitget has not confirmed the attacker’s identity.

New York files suit against Polymarket

New York state authorities on Thursday local time formally sued crypto prediction market platform Polymarket, accusing it of running an “illegal gambling operation” in the state.

Earlier, New York Attorney General Letitia James and related agencies had already taken a series of legal actions against institutions involved in prediction market businesses, including Kalshi, Coinbase, and Gemini. Those actions alleged that such platforms offered event-based betting without obtaining a license from the state Gaming Commission.

Federal Reserve issues two proposed rules under the GENIUS Act framework

The Federal Reserve released two proposed rules for public comment to implement the GENIUS Act and establish a supervisory framework for payment stablecoin issuers under its jurisdiction.

The first proposal would require stablecoin issuers to fully back their tokens with eligible high-quality liquid assets such as short-term U.S. Treasuries. It would also set unified capital and risk management requirements, establish custody rules for reserve assets, and define the scope of permitted stablecoin-related activities for banks supervised by the Federal Reserve.

The second proposal would create a dedicated approval process for Federal Reserve-supervised banks seeking to issue payment stablecoins. Applicants would need to submit materials including business plans and financial information, and the process would include appeals, hearings, and a final decision procedure.

The comment period will end 60 days after the relevant documents are published in the Federal Register.

Sequans exits its bitcoin treasury strategy

French fabless semiconductor company Sequans Communications (NYSE: SQNS) said it has sold the remaining 314 BTC it held as of June 30, formally ending its bitcoin treasury strategy.

The company had already redeemed its convertible notes in May. It said it now has no other outstanding debt apart from obligations tied to government-supported research and development programs, and it no longer holds crypto assets on its balance sheet. Sequans said it will refocus resources on its cellular IoT and software-defined radio, or SDR, semiconductor business.

Magic Eden says older EVM listings may have been exposed to a Limit Break flaw

After further review of the NFT security incident tied to Magic Eden, the vulnerability was identified as coming from Limit Break Payment Processor V2.

Yuga Labs Vice President of Blockchain Quit, also known as 0xQuit, said the team’s white hat rescue operation secured 23,155 NFTs worth more than $5.7 million, and those assets have now been moved to safety. He added that a similar flaw could also be used to steal WETH, and about 660 WETH could not be recovered in time.

Magic Eden said it stopped using Payment Processor V2 in October 2024 and shut down its EVM Marketplace in the first quarter of 2026, so current active listings were not affected. The potential risk is mainly tied to NFTs listed through its EVM marketplace between February 2024 and October 2024.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
2700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.