Bitget förlorade precis 350 miljoner dollar
Bitget's eighth birthday ended with hackers walking off with roughly $350 million. Not a bad haul for one night's work.
The first sign of trouble came late on September 24, when wallets tagged as Bitget's started bleeding funds across multiple chains. Arkham analyst Emmett Gallic caught it first, flagging the outflows more than an hour before Bitget said a word publicly. By the time CEO Gracy Chen confirmed the incident on X, roughly $183 million had already moved. The final tally came in higher: about $351.6 million.
"At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets," Chen wrote.
Cold storage, she said, was never touched — the breach was confined to the hot and warm wallet layers, and withdrawals were frozen while the team scrambled to contain it.
No stolen keys, just a very convincing forgery
Here's the part that should worry every exchange running similar infrastructure: the attackers didn't need Bitget's private keys at all. Chen later explained that hackers compromised a backend system tied to Bitget's wallet infrastructure, used it to spoof transfer data, and then rode that fake data straight through the exchange's own authorization process. The system approved transactions it should never have seen. "Private key compromise has been ruled out," Chen said — which, depending on how you look at it, is either reassuring or the more unsettling option. Losing keys is a known failure mode. Getting your own signing process tricked into approving fraud is something else.
Roughly 40% of the stolen assets were $XRP, based on early breakdowns circulating alongside Chen's updates, with the rest spread across ETH, BNB, AVAX, USDT and USDC. Some chain foundations reportedly began freezing hacker-linked addresses within hours, though how much that actually recovers remains to be seen.
The getaway was fast and expensive
Whoever did this wasn't interested in being careful. One newly created address swapped 19.67 million USDT0 for 7,111 ETH in six minutes flat, running the trade through UniswapX and 1inch Fusion and paying up to 5% above market rate to get it done. That's not how you trade if you're worried about price. That's how you trade if you think someone's about to freeze your funds.
The laundering pattern — funds consolidated into a single address, then peeled off through a chain of wallets — is the same playbook security researchers have pinned on North Korean-linked operators for years.
Lazarus, again
Chen pointed to North Korea, saying investigators found IP addresses matching VPN infrastructure tied to the country's hacking apparatus, and that the attack "looks very much like what the North Korean team did before." Independent analyst SpecterAnalyst went further, tracing the stolen XRP back to the same wallet cluster used in July's $24 million AFX hack — an incident already attributed to TraderTraitor, a Lazarus-linked unit. Not everyone's convinced by the label; some researchers on X pushed back, noting "Lazarus" gets pinned on a lot of incidents that may not share an actual operator. Bitget's own report is still pending.
If it does hold up, it's just the latest entry in a very long ledger. Chainalysis puts North Korea-linked crypto theft at over $2 billion for 2025 alone, and that's before this one gets added to next year's count. Bybit's $1.5 billion hack in February 2025 — still the largest crypto theft on record — carries the same fingerprints.
There's a small, almost funny footnote here: Bybit CEO Ben Zhou offered to help trace the funds, noting Bitget had done the same for Bybit back when it was the one getting robbed. Crypto exchange leadership apparently has a group chat for this now.
The fund that's supposed to cover it
Bitget says none of this touches user balances. The exchange maintains a User Protection Fund that, as of Chen's statement, held more than $464 million — comfortably above the $351.6 million loss. Deposits and trading kept running the whole time; only withdrawals were paused, and Chen said restoration would take "hours or days," not weeks.
Whether that promise holds is the next thing worth watching. A fund on paper is different from a fund that pays out cleanly during a bank-run mood, and BGB dipped after the news broke before recovering some ground. Bitget has committed to a full incident report with root-cause analysis — that document, once it lands, will say a lot more than any X thread can.

5% insättningsbonus upp till 100 ädelstenar

0% avgifter på insättningar och uttag.


11% insättningsbonus + FreeSpin
EXTRA 10% INSÄTTNINGSBONUS + GRATIS 2 HJULSPINN
Gratis case och 100% välkomstbonus
5 gratisfodral, daglig gratis & bonus

3 gratis casinos och en bonus på 5% på alla kontantinsättningar.

+5% till insättning


Kommentarer