Uneasy Money: The $388M Bitget Hack Started With a Security Vendor
Uneasy Money: The $388M Bitget Hack Started With a Security Vendor
1 hour ago•Unchained•Laura Shin
Podcast1 hr 23 min
Listen to Episode
Note: AI-generated summary based on third-party content. Not financial advice. Read more.
Quick Insights
  • Treat Bitget as a heightened counterparty risk after the reported $388 million hack; wait for independent forensic findings before relying on its assurances.
  • Consider ETH only as a long-term, execution-dependent investment, and monitor whether planned upgrades ship and attract developers and applications.
  • Avoid or thoroughly scrutinize RUNE exposure given concerns raised about THORChain’s governance, emergency controls, and links to laundering flows.
  • NVDA may benefit from continued AI demand, but the discussion offered no valuation or price target—assess its financials and current price before investing.
  • Treat prospective OpenAI and Anthropic IPOs as speculative: no confirmed price or timeline was given, so evaluate spending, revenue, competition, and valuation before committing.
Detailed Analysis

Bitget

  • Bitget suffered a hack involving approximately $388 million. The discussion said attackers exploited a zero-day vulnerability in a third-party security product and accessed systems that let them spoof or reinsert withdrawals without triggering controls.
    • The attackers reportedly did not obtain private keys, and the exchange’s wallets were not completely drained.
    • Bitget said it had sufficient resources to cover the loss, but the hosts noted that the full forensic picture was still developing.

Takeaways

  • The incident highlights security and operational risks at centralized exchanges, including risks introduced by vendors and complex internal systems—not just private-key theft.
  • Treat an exchange’s assurances about its ability to absorb losses as claims to monitor, not as a substitute for assessing custody and counterparty risk.

Ethereum (ETH)

  • The hosts were strongly bullish on Ethereum’s proposed long-term technical direction, describing the roadmap as potentially competitive if it is delivered.
    • They argued that AI coding tools could help teams build and test ambitious upgrades faster.
    • They also said Ethereum’s challenge is not only technical: confidence in its future and the ability to attract useful applications matter.
  • The discussion emphasized that Ethereum may benefit if it becomes a strong place to build, rather than relying on incentives to attract developers.

Takeaways

  • The discussion supports a long-term, execution-dependent thesis for Ethereum, not a near-term price prediction. Track whether roadmap plans turn into shipped upgrades and whether developers and applications follow.
  • Faster development could help, but the hosts also stressed the importance of testing and getting important changes right.

Bitcoin (BTC)

  • Bitcoin was used as a point of comparison for systems described as censorship-resistant and permissionless. The conversation did not offer a specific Bitcoin investment thesis.

Takeaways

  • No buy, sell, or price view was given. The relevant insight is that censorship resistance and governance are important distinctions when comparing crypto networks.

Bitget Hack Routes: Avalanche (AVAX), Arbitrum (ARB), and USDC

  • The discussion said the attackers moved funds across chains and stablecoins after the Bitget incident, including through USDC, Avalanche, and Arbitrum.
  • The hosts noted that Arbitrum can freeze funds, and said the attackers appeared to move quickly to avoid that possibility.
  • The incident prompted debate about when networks or their governance bodies should intervene to freeze stolen assets.

Takeaways

  • Cross-chain movement can complicate tracing and recovery after a hack; assets and bridges may face operational or intervention risk during an incident.
  • When evaluating a chain or token, consider whether administrators, councils, or issuers can freeze or otherwise intervene—and whether that is viewed as protection or a threat to permissionless operation.

THORChain (RUNE)

  • The hosts were sharply critical of THORChain’s decentralization and security claims. They cited past instances of halting the chain and reallocating assets, along with concerns about the project’s software distribution and governance.
  • They also argued that THORChain has been used repeatedly in laundering flows involving stolen funds.

Takeaways

  • The discussion presents a bearish risk assessment of THORChain’s governance, transparency, and exposure to illicit activity.
  • Before considering exposure, examine who controls upgrades and emergency actions, whether the software is openly available, and how the network has handled prior incidents.

NEAR Protocol (NEAR)

  • NEAR was discussed favorably for its transaction-screening and behavioral anomaly-detection measures. The hosts said it had blocked a large volume of suspicious attempted activity and frozen some funds.
  • They highlighted the idea of delaying or screening unusual transactions—for example, activity involving a newly funded address—rather than allowing it to proceed immediately.

Takeaways

  • The discussion points to security controls as a potentially important differentiator for blockchain networks.
  • Weigh those protections against the trade-off raised in the episode: stronger screening can limit malicious activity but may also reduce permissionlessness.

1inch (1INCH) and Aqua

  • The sponsor described 1inch Aqua as a shared-liquidity platform that lets liquidity providers back multiple positions using the same wallet balance and keep tokens in their wallets until a swap fills.
  • The ad said that about $540 million in concentrated liquidity sat idle in a given week in the first half of the year, and that fees from providing liquidity are not guaranteed.

Takeaways

  • Aqua was presented as a way to use liquidity more efficiently across positions, but the discussion did not provide independent performance evidence or a return estimate.
  • Liquidity provision still carries risk, and fees are uncertain. Assess the mechanics and potential losses before committing tokens.

AI Companies and Potential IPOs: OpenAI and Anthropic

  • The hosts debated whether high-risk AI companies should go public while they still need large amounts of capital, potentially allowing retail investors to participate in future gains—and losses.
  • The conversation characterized these companies as spending heavily and having substantial downside risk, including the possibility of failure. It also discussed a hypothetical $2 trillion IPO valuation and a possible $20 trillion future value as part of the debate—not as a price target or recommendation.
  • One speaker cited Anthropic’s valuation as having risen from $62 billion to a much higher prospective figure over roughly 18 months; the discussion did not establish a verified IPO valuation.
  • Speakers also discussed the possibility that AI companies could seek regulation that disadvantages open-source competitors, while noting that open-source models are already widely available.

Takeaways

  • The discussion frames AI IPOs as high-risk, potentially high-upside investments. The central question is whether future growth justifies current valuations, spending, and the risk of losing capital.
  • Evaluate actual revenue, spending, competitive position, and regulatory exposure rather than treating speculative valuation scenarios as forecasts.
  • The episode did not provide a specific buy recommendation, confirmed IPO price, or timeline.

NVIDIA (NVDA)

  • NVIDIA was described as potentially benefiting across different AI outcomes, including a future with more open-source models and locally run AI.
  • The discussion noted that AI companies still rely on NVIDIA hardware to train models, while wider access to GPUs could also create demand.

Takeaways

  • The speakers presented NVIDIA as an AI-infrastructure beneficiary, but did not discuss its valuation, earnings outlook, or a price target.
  • A broad AI-growth thesis does not by itself establish that a stock is attractively priced; consider the company’s financial performance and valuation separately.

Meta (META), Alphabet (GOOGL), and Amazon (AMZN)

  • These companies were cited as examples of firms that delivered substantial returns to investors who bought around their IPOs.
  • The discussion acknowledged that those outcomes unfolded over many years and were not typical proof that future IPOs will perform similarly.

Takeaways

  • Historical IPO success stories provide context, not a reliable forecast for new listings.
  • Consider the entry valuation, time horizon, and possibility of losses rather than assuming a new AI IPO will repeat past technology-stock gains.

Tesla (TSLA)

  • Tesla was mentioned in a discussion about household robots. The speakers raised the possibility that robots could be hacked or remotely operated, creating safety and privacy risks.
  • The conversation did not assess Tesla’s business, stock valuation, or investment outlook.

Takeaways

  • The discussion raises a potential product-security risk for household robotics, but gives no basis for a stock recommendation.
  • For companies developing connected robots, security, safety, and control of remote access are issues worth monitoring.
Ask about this postAnswers are grounded in this post's content.
Episode Description
Taylor Monahan ties the Bitget hack to North Korea and the crew asks why THORChain still avoids the scrutiny Tornado Cash got. ======================================================== Thank you to our sponsors! Visit 1inch to swap tokenized securities, crypto and more. Simple. Secure. Self-custodial. Whatever asset you’re buying - swap it at ⁠⁠⁠⁠⁠⁠http://unchainedcrypto.com/go/1inch-sn⁠⁠⁠⁠⁠⁠ ======================================================== Quick favor: We’re deciding what Unchained does next; new shows, stream times, what’s worth paying for. ⁠Our listener survey⁠ takes five minutes, it’s anonymous, and I read the write-in answers myself. Everyone who takes it can enter a drawing for a free year of Unchained Premium or Bits + Bips Premium. Open through Sunday, October 18. — Laura ======================================================== Attackers took $388 million from Bitget without ever getting its private keys. Opsek founder Pablo Sabbatella explains that the way in was a zero-day in a third-party security product the exchange relied on. Sabbatella, who now sits on Arbitrum's Security Council, joins Kain Warwick, Taylor Monahan, and Austin Griffith to trace the hack. Monahan attributes it to North Korea's TraderTraitor group and flags how fast the funds left Arbitrum, while the hosts ask why THORChain, which has halted its chain and reallocated balances before, still handles stolen funds. They also cover NEAR's SHIELD anomaly detection, reports of rogue AI agents hacking outside systems, whether retail should get the upside of a $2 trillion Anthropic IPO, and Vitalik Buterin's 2030 roadmap for Ethereum. Warwick's case: the harder the problem, the more superintelligence helps, and Ethereum is one of the hardest problems there is. Hosts: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Kain Warwick⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ - Host of Uneasy Money and Founder of Infinex and Synthetix ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Taylor Monahan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ - Co-host of Uneasy Money and Security Expert ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Austin Griffith⁠⁠ - Co-host of Uneasy Money and Builder Enablement at Ethereum Foundation Guest: Pablo Sabbatella - Founder at Opsek Timestamps 🚨 02:32 How Bitget got hit for $388M and covered the losses 🛡️ 08:24 Why Pablo says a third-party security product was the way into Bitget 🕵️ 11:22 Taylor ties the hack to North Korea and highlights their rush to exit Arbitrum ❄️ 13:34 Pablo on why security councils restart the freeze debate every time ⛓️ 14:17 Why Kain says THORChain can't claim it's like Bitcoin and Ethereum 🧭 30:24 How NEAR's Shield blocks funds using behavioral anomaly detection 📣 34:51 1inch: See how 1inch Aqua lets LPs back multiple positions with one token balance at http://unchainedcrypto.com/go/1inch-yt 🤖 36:16 Rogue AI agents are hacking outside systems as the labs eye IPOs 🔓 39:11 Why Pablo thinks the AI labs want to regulate open-source models 📈 48:55 Kain's case for letting retail take the risk on a $2T Anthropic IPO 🧱 01:05:47 Why Kain calls Vitalik's 2030 roadmap the most bullish Ethereum read in years 🏪 01:19:18 Pablo asks whether Ethereum's real challenge is commercial, not technical Learn more about your ad choices. Visit megaphone.fm/adchoices
About Unchained
Unchained

Unchained

By Laura Shin

Crypto assets and blockchain technology are about to transform every trust-based interaction of our lives, from financial services to identity to the Internet of Things. In this podcast, host Laura Shin, an independent journalist covering all things crypto, talks with industry pioneers about how crypto assets and blockchains will change the way we earn, spend and invest our money. Tune in to find out how Web 3.0, the decentralized web, will revolutionize our world. Disclosure: I'm a nocoiner.