CryptoReal
CASE FILE — Sep 30, 2026

Bitget Hot Wallet Breach Exposes $387.5M to Sophisticated Attack via Third-Party Security Flaw

Bitget suffered a significant breach, with wallets compromised despite no theft of private keys.

On September 24 at 18:31 UTC, Bitget reported its security systems detected unauthorized transfers.

Subsequent investigations from SlowMist have traced the timeline of the attack even earlier, identifying the first malicious actions as occurring on August 31, when an attacker leveraged a zero-day vulnerability in a third-party security solution.

Within approximately three hours, attackers withdrew $387.5 million from Bitget across Ethereum, EVM networks, XRP, Zcash, and TRON. According to DefiLlama, this incident stands as the largest crypto theft of 2026 to date.

Mandiant's Incident Response Status Report confirms that there was no evidence of private key compromise, and cold storage wallets remained intact.

According to Mandiant, the attacker achieved high-level access to third-party security devices, subsequently infiltrating Bitget’s production wallet job server.

SlowMist uncovered a bespoke tool used by the attacker to manipulate risk parameters, create withdrawal requests, and trigger the wallet system’s withdrawal functions.

The means by which the attacker navigated between internal systems is still being determined by investigators.

Arkham reported that $228 million was moved out in just 18 minutes.

The largest single asset taken was approximately 103 million XRP (valued at $157.48 million), which is not subject to freezing on the XRP ledger.

Bitget has stated that its protection fund will absorb the loss. BTC withdrawals have resumed on both Bitcoin and BNB Chain, while the restoration of other assets is proceeding in stages.

CEO Gracy Chen suggested a potential link to DPRK, though firm attribution has not been established.

TRM Labs identified overlaps between the laundering networks used in this case and those from previous hacks tied to North Korea, but has not definitively attributed the Bitget attack to North Korea.

Progress reports from Mandiant and SlowMist have been released, but neither has publicly named the third-party vendor or fully clarified the attacker’s internal movement.

This incident raises questions about the nature of control within automated wallet systems.

Early Signs and Escalation

A suspicious transaction provided one of the first hints:

At 19:57 UTC on September 24, DCF GOD observed a newly created address converting 19.67 million USDT0 to 7,111 ETH within six minutes, paying up to a 5% premium via UniswapX and 1inch Fusion.

The urgency suggested an attempt to evade stablecoin freezes, as stablecoins can be frozen by their issuers, but ether cannot.

Roughly 15 minutes later, Officer’s Notes highlighted large outflows from Bitget: "It looks like bitget hot wallet might've just been hacked."

Their tally showed $174 million bridging multiple chains into a single address within an hour.

By 20:56 UTC, Hacken posted an initial on-chain analysis, tracing about $145 million in ETH, USDT, USDC, and tokenized gold, with BNB Chain, Avalanche, and USDT0 transfers still under review. At this stage, Bitget had not yet commented publicly.

These movements confirmed funds were exiting Bitget, though at the time it was unclear if private keys or cold storage were involved.

Bitget later clarified that its cold wallets were not affected.

Mandiant’s preliminary findings echoed this, stating there was no indication of private key compromise.

Bubblemaps subsequently visualized around $180 million flowing from Bitget wallets to a single address, later dispersing to several more.

These early counts missed a major component. Arkham’s later reconstruction revealed about $153 million in XRP sent to a new address, bringing the total outflows to around $350 million.

At 21:30 UTC, Bitget broke its silence. Gracy Chen posted a notice on Twitter, citing losses of approximately $351.6 million, assuring cold wallet safety, and announcing a halt on withdrawals. She promised a full incident report within 24 hours.

Arkham’s data showed draining ended at 21:23 UTC, just before Chen’s statement and nearly three hours after Bitget’s initial detection window. By this point, the receiving address was already public.

Shortly after midnight UTC, Chen clarified that the breach resulted from backend compromise, manipulated transaction data, and Bitget’s own authorization processes moving the funds.

The total loss estimate increased on September 25, as Bitget updated the figure to $387.5 million, now including Zcash and TRON assets omitted from the initial count.

Chen emphasized that the revised figure reflected more thorough accounting, rather than ongoing theft.

While blockchain evidence was clear, Bitget’s internal narrative unfolded gradually via public statements.

Unpacking the Attack

The groundwork for this breach began weeks earlier.

According to SlowMist, the first signs of compromise appeared on August 31, when an unpatched vulnerability in a third-party product (referred to as Product A) was exploited.

An embedded script extracted a database password from an environment variable and accessed the database; similar actions were noticed on other Product A instances on September 23 and 25.

Mandiant’s findings indicate that on September 24 the attacker obtained privileged access to two third-party security devices, deployed a web shell, established remote control, and proceeded laterally into Bitget’s production wallet job server, where malicious packages were installed.

All times in SlowMist’s report are UTC+8; converted here to UTC.

At 16:07 UTC on September 24, the attacker began injecting commands into Product B’s task parameters, having accessed its management console using internal credentials.

Further, the attacker submitted code via a web endpoint to modify configurations and compile malicious files. The exact method by which the attacker traversed between internal systems is still being analyzed.

SlowMist recovered a custom withdrawal tool deleted by the attacker, which forged risk-control parameters, constructed withdrawal requests, and triggered the wallet’s withdrawal process.

Logs indicate this tool was executed at 17:49 UTC on September 24, 42 minutes before the first confirmed on-chain transfer.

These detailed reports from SlowMist and Mandiant clarify the intrusion’s extended duration and the path into wallet infrastructure.

On September 28, Gracy Chen recapped the timeline during a livestream, with Foresight News providing a summary.

At 18:31 UTC, the attacker sent small amounts of ETH and TRX from Bitget’s hot wallets.

Both were below the platform’s risk-control threshold and did not trigger alerts.

Bitget originally said its systems detected unauthorized transfers at 18:31 UTC. In a later update, however, it said the small transfers at that time did not trigger alerts](https://www.theblock.co/news/regulation/2026-09-28-bitget-attacker-tested-risk-controls-small-transfers-388-million-theft-ceo-says-417045). The reason for this discrepancy remains unaddressed.

Large-scale withdrawals commenced at 18:58. Bitget counted 17 significant transfers between then and 20:09 UTC, spanning XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism, and others, totaling about $360 million.

At 19:05, Bitget’s reconciliation system detected a major inconsistency, and risk controls automatically blocked user withdrawal requests.

However, the attacker’s fraudulent wallet-system commands were not prevented, and the transfers continued until 20:09, followed by a second wave that evening.

At 19:14, Bitget initiated a P0 emergency response.

By 19:40, the technical team began efforts to mitigate losses.

At 20:40, with private key theft not yet ruled out, the wallet team transferred assets into cold wallets.

A second surge took place 15 minutes later: Seven more transfers between 20:55 and 21:13 UTC across Avalanche and additional chains, accounting for a further $28 million.

SlowMist’s records show transfers continuing until 21:23:11 UTC. The logs also reveal that, after the transfers began, the attacker attempted to edit withdrawal records and initiate two fake BTC withdrawals, both of which encountered errors during processing.

Bitget stopped its signing machines and isolated wallet withdrawal services at 21:44 UTC, roughly two and a half hours after emergency response began and 14 minutes after Chen’s announcement.

At 08:43 UTC on September 25, Bitget stated its security team had determined the root cause: unauthorized use of legitimate credentials.

Chen explained that the attacker exploited vulnerabilities in third-party security products to obtain internal credentials, then used these to impersonate authorized processes and send fraudulent withdrawal instructions to Bitget’s wallet system.

Reports from both SlowMist and Mandiant confirm that compromised third-party products enabled unauthorized access, with SlowMist noting the custom withdrawal tool forged risk parameters and triggered withdrawals. Neither report yet clarifies the entire route of movement between internal systems.

After the transfers, Chen reported, the attacker disguised activities as typical administrative work and attempted to erase evidence.

Bitget reported that no common viruses or malware were involved, describing the breach as a highly targeted operation.

It is important to note that while “no common viruses or malware” were found, both Mandiant and SlowMist documented malicious code: a web shell, malicious packages, and the custom withdrawal tool.

There was no compromise of private keys, and insider involvement has been preliminarily excluded.

Per Bitget, the private keys remained secure, while fraudulent commands were processed by the wallet system.

Sums referenced in this case file

This differs from the Bybit incident, where signers were deceived by a spoofed Safe wallet interface.

So far, Bitget’s version of events centers on forged instructions sent to its wallet system, not human error.

Since then, Bitget has isolated impacted servers, revoked and reissued credentials, reorganized sensitive system access, and suspended the affected vendor’s functionalities until a permanent fix is available.

The company is also strengthening its procedures for evaluating and deploying third-party security software.

The vendor and products involved have not been named; SlowMist refers to them only as Product A and Product B.

The industry is left to wonder how privilege escalation from third-party security products granted access to critical wallet servers, and where intervention might have been possible.

Following the Funds

Immediately after the breach, the attackers began moving and laundering the stolen assets.

Within minutes, Arkham observed stablecoins and tokenized gold being exchanged for ETH.

$25 million in USDT was routed to Rizzolver via five $5 million fills; the rest was moved through Uniswap, 1inch, and Furucombo, with USDC bridged and sold on Ethereum.

The attackers quickly converted freeze-prone tokens to ETH.

From 19:44 UTC, ETH on Arbitrum, Optimism, and Base was bridged to Ethereum using Across, Stargate, and LayerZero, mostly in 400–500 ETH increments.

By 20:04, assets worth roughly $100 million had been converted to about 36,600 ETH.

Subsequently, the first new ETH address with a 10,000 ETH balance was funded at 20:13 UTC. By 22:45, six such addresses existed, and Arkham later tallied 68,300 ETH (about $183 million) across eight new wallets.

The XRP portion took another route. Three transactions sent 102.98 million XRP out of Bitget. These funds were then distributed in batches by six accounts, which were emptied by September 27. Bitquery tracked the XRP through new wallets to THORChain, where 90.5% was swapped for bitcoin and 7.6% for ETH.

BNB was also divided. Arkham tracked $6.9 million across 12 BNB Chain wallets, with at least $4.7 million going to THORChain and $2 million to FixedFloat.

A limited amount could be frozen. The first public freeze was about $318,000 in stablecoins by Circle and Tether.

Bitget has stated that additional funds were frozen thanks to industry partners, without specifying the amounts.

Tether later froze another 21,091 USDT in a separate wallet, raising the public tally of frozen issuer assets to $339,000.

NEAR Intents reported freezing $503,000 during attempted swaps. Combined with issuer freezes, this brings the publicly identified frozen funds to about $842,000—just 0.22% of Bitget’s total $387.5 million loss.

This sum does not represent recovered funds or a comprehensive total; Bitget says more assets were frozen, but has not released a figure.

A September 25 snapshot by AMLBot found about $343 million (roughly 88% of $389 million) dormant in 13 attacker wallets.

The movement of stolen assets continued elsewhere.

On September 26, AMLBot flagged a possible route into a Wasabi CoinJoin linked to the Bitget theft.

Roughly 4 BTC in CoinJoin was traced back to a TRON wallet through a series of swaps and bridges: TRX was swapped to USDT, then to about 145 ETH on Ethereum, and finally to approximately 4.59 BTC via THORChain.

The stolen ETH was also on the move. Lookonchain noted ETH-to-BTC swaps via THORChain on September 28.

During that process, CoinDesk documented 27 successful swaps between 03:55 and 06:23 UTC, converting about 2,390 ETH ($6.3 million) into 75.2 BTC sent to a single address.

This reflects only one portion of ETH movements, rather than a full account.

MistTrack reported that a Chainflip broker rejected and refunded a deposit from the attacker.

In some cases, those moving funds sought customer support; ZachXBT reported that purported Chinese launderers acting for the suspected DPRK attackers were seeking assistance in public channels.

He identified five aliases linked to transaction hashes, noting that one had also appeared in laundering efforts following the April $292 million KelpDAO exploit.

Bitget has published the main receiving addresses involved in the breach:

EVM: 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee

XRP: rwNhefsz1UQEusxhCvHip3RANinWi4CTck

ZEC: t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG

TRON: TBWNguTTgezw9dVorX441C6nDrZpRxYwKD

For ongoing tracking, see the Bitget Hacker entity on Arkham.

While the addresses are public, the funds remain in motion.

Industry Response and Recovery Efforts

Bitget’s attempts to recover assets have increasingly relied on cooperation from industry partners.

On September 25, Bitget introduced a Recovery Bounty Program, offering up to 5% rewards for those who help freeze or retrieve stolen funds.

The bounty applies retroactively to freezes secured before the program’s launch, but excludes actions compelled by legal or law enforcement orders. Bitget retains discretion over eligibility and reward amounts.

The exchange also rolled out a live tracking dashboard, recovery portal, and API for attacker addresses, designating Bybit’s LazarusBounty as a key channel.

Bybit CEO Ben Zhou extended support, referencing Bitget’s assistance after Bybit’s own hack in 2025.

The trail led to THORChain, prompting Bitget to seek direct action.

MistTrack noted on September 25 that nearly $1.2 billion in stolen crypto had been traced through THORChain, with Bitget’s stolen assets now following suit.

On September 26 at 11:44 UTC, Gracy Chen publicly requested THORChain to block service to the attacker’s addresses, emphasizing that decentralization is a principle, not an excuse for facilitating theft.

THORChain responded that evening, expressing regret but underscoring its decentralized, permissionless nature. The protocol compared itself to Bitcoin, Ethereum, and BNB Chain, questioning their responsibility for stolen assets.

This analogy was challenged by critics.

OKX CEO Star Xu argued that THORChain’s validator model and TSS vaults make it an intermediary with the ability to act, as opposed to Bitcoin or Ethereum.

GoPlus Security noted that node votes can pause signing on a specific chain, estimating that the Bybit exploiters moved nearly 499,000 ETH via THORChain in ten days, generating $5.5 million in protocol fees. "Do not put the industry at risk for the fee line," they wrote.

SlowMist founder Cos, involved in Bitget’s investigation, pointed to THORChain’s emergency pause procedure and questioned the protocol’s willingness to act only for attacks against itself.

Specter bluntly stated that THORChain only intervenes for its own losses.

On September 27, THORChain restated its position: network halts are emergency protocol measures, not means to freeze specific funds. It added that no attacker addresses were blacklisted during its own May exploit, maintaining a policy against censorship.

Michael Perklin countered GoPlus’s arguments, asserting that all tools are neutral by design.

Some protocols opted for a more proactive stance.

NEAR Intents general manager Alex Shevchenko disclosed that attackers tried to launder over $50 million via NEAR, with $166,000 making it through and $503,000 frozen by its SHIELD risk layer. SHIELD can block or halt trades linked to hacks, and NEAR Intents declined any bounty while advising Bitget to pursue frozen assets through legal channels.

NEAR co-founder Illia Polosukhin supported this approach, saying that permissionless does not obligate every service to process every transaction.

Chen thanked NEAR Intents for providing an example of “permissionless but not ‘facilitating known stolen funds’”.

Meanwhile, THORChain continued to process swaps.

The two cross-chain protocols exemplified distinct approaches: NEAR Intents’ SHIELD actively blocks suspicious activity, while THORChain maintains that its network halt is a last-resort measure for protecting the protocol, not for freezing user funds.

Chen’s request for THORChain to block attacker addresses was not implemented.

Internally, Bitget’s recovery focused on remediation and resumption:

The affected systems were isolated and the exploited vulnerability resolved. Withdrawals were reopened in phases, starting with BTC and BSC on September 28, followed by ETH on multiple networks on September 29.

USDT withdrawals have reopened on Ethereum, BSC, Solana, and Tron; Chen announced P2P and remaining services would resume on October 2 at 08:00 UTC.

Before the incident, Bitget’s Protection Fund was backed by 5,500 BTC. Chen confirmed that the fund would absorb the losses, ensuring users were “100% covered”](https://x.com/GracyBitget/status/2104515761691939026).

The fund’s value has already been restored to over $300 million, as Chen pledged to replenish it within a week. She also reported a 131% proof-of-reserves ratio as of September 29.

Bitget launched two additional initiatives: The Bitget Alliance Program, sharing 30% of net transaction-fee revenue with qualifying users, and Project Stand Together, which provides PRO users with fee discounts, increased maker rebates, and extended tier protection.

Chen characterized this as Bitget’s first security breach of this nature in eight years.

While the flow of stolen assets has been mapped, the individuals responsible remain unidentified.

Lessons and Unanswered Questions

The breach did not require direct key theft—compromised credentials and backend vulnerabilities were sufficient.

According to Bitget, a vulnerability in an unnamed third-party security solution allowed attackers to obtain internal credentials, which were then used to authorize fraudulent wallet system actions. Private keys were not compromised.

Chen states that all user funds are fully covered by Bitget’s Protection Fund, and withdrawals for BTC, ETH, and USDT have resumed.

Asset recovery remains limited: Bitquery documents $339,000 frozen by stablecoin issuers, and NEAR Intents reports freezing $503,000 mid-execution, together accounting for only 0.22% of the $387.5 million loss, with no comprehensive tally provided.

Chen told CoinTelegraph she was “not very optimistic” about recovering the stolen funds. She referred to the 2025 Bybit hack, noting that only 3.5% of those funds were frozen after a year and emphasizing that freezing is not equivalent to recovery.

TRM Labs has connected elements of the laundering process to networks used in past North Korea-linked hacks, but has not definitively attributed the incident to North Korea.

The vendor involved has not been disclosed. Recent reports from SlowMist and Mandiant outline the exploitation of third-party security products leading to wallet environment compromise, but SlowMist’s investigation is ongoing regarding lateral movement between systems.

The industry is left with open questions about which specific products may present similar risks for other exchanges.

How can the sector address a critical vulnerability when its source remains unnamed?

BitgetCEXThird Party Breach
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.