Summaries
Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.
Showing 1-2 of 2 results
| Date | Provider | Score | Summary |
|---|---|---|---|
| 02 Oct 2026, 2:03 PM | CNBC Technology | 3.0 | Bitget 'not expecting to recover a lot' from $388 million hack, CEO tells CNBC
Bitget CEO Gracy Chen told CNBC that only about $1.1 million of the roughly $388 million stolen in a cyberattack last week has been frozen, and that she is 'not expecting to recover a lot of funds' based on recovery rates from previous exchange hacks. Bitget has refilled its Protection Fund to $300 million from its own reserves to cover losses, and Chen declined to name the third-party vendors that were breached, citing security risk. Why: The recovery number is the useful one: ~$1.1M frozen out of ~$388M, and frozen does not mean returned — so roughly 0.3% at best, with the shortfall absorbed by Bitget's own reserves rather than recovered. If you or your users keep funds on a centralised exchange, that ratio is the realistic planning assumption, not the $300M Protection Fund headline. The undisclosed third-party vendor breach is the second takeaway: you cannot check your own exposure against a named vendor, so any dependency on exchange or custody vendors has to be treated as unverified until Bitget says who was hit. |
| 29 Sep 2026, 1:42 AM | The Hacker News | 2.5 | Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
Bitget says an attacker stole about $388 million from its hot and warm wallets by exploiting a zero-day vulnerability in an unnamed third-party security product it used, which gave access to high-level internal credentials. On September 24 the attacker sent fraudulent withdrawal commands into wallet backend services, starting with two small test transfers at 18:31 UTC that stayed under Bitget's risk-control threshold, then larger transfers roughly 30 minutes later that the wallet system executed while bypassing risk controls. Bitget says cold wallets and private keys were unaffected, has isolated systems, revoked and reissued credentials, and disabled the affected functionality, but has not said whether the vendor has shipped a fix; CEO Gracy Chen described the incident in a livestream and interviews. Why: This is a crypto-exchange incident with no stated Malaysia angle and nothing here that changes what most Malaysian developers, database learners, or SaaS founders build this week. The one transferable detail is the detection design: two test transfers below Bitget's risk-control threshold raised no alert, and the real drain followed ~30 minutes later — if you operate any withdrawal or approval flow, that is a concrete argument for alerting on threshold-adjacent sequences and not just on absolute size. Beyond that, the article does not name the third-party product, the vendor, or a fix, so you cannot act on the supply-chain angle from this text alone. |