Preview surface — demo data. Where real data exists today (e.g. RealT, BlackRock BUIDL, Lift Dollar) we render it; everywhere else we render synthetic enrichment generated deterministically from public signal and clearly marked Demo or Inferred. The Phase 3 roadmap replaces every synthetic source with live ingestion — see Methodology → Exposure Graph & Similarity Engine.
← back to incident ledger

phishing drainerDemo

Nov 17, 2025 · $739.9K · human op

Narrative

On 2025-11-17, Bitget suffered a phishing drainer incident resulting in approximately $739,910 in losses. The exploit targeted the human_op layer. Attribution: unknown. This is a demonstration entry — not a real incident.

Victims

Classification

Root cause
phishing_drainer
Secondary causes
ice_phishing_approval
Attack layer
human_op
Strategy
human_exploit
Actor role
target
Attribution
unknown
Attacker address
0x45ebf93f01917bb007f6172e33ae31fdbbbddeb4
Flash loan
no
Audited at time
no
Bounty at time
no

AADAPT mappings

DEMO:AADAPT.TA0001DEMO:AADAPT.TA0040DEMO:AADAPT.T1566.003

Evidence

Disclosure date
Nov 19, 2025
Funds recovered
$285.1K
Audit firms at time
Post-mortem URLs (synthetic)
  • https://medium.com/bitget/post-mortem-bitget-2025-11-17
tx hashes (3)
  • 0x0f15a5d3ab0610932c492dafbec1abedbf66b24a306380becbecafda10513aa1
  • 0x1037763e8b4e60805514a59ba1573747866acd36d1e41c6b2e9810bcd0c22060
  • 0x2bd354a97f78264b29fbbe9cc9b46dd228fb2843705d9d4c3999efc83f2ebf8f