Buy
Market
🔥
Prediction Market

Bitget Hack: $387.5M Stolen After System Approved Transfers

Bitget confirmed a $387.5 million hack on Sept 24. Attackers compromised its backend system, and withdrawals remain suspended.

25/09/2026 16:5715 min read

Bitget acknowledged that $387.5 million was taken from its exchange wallets on September 24. Withdrawals stay halted, but the firm states its protection fund will cover the damage.

Investigations are underway by Mandiant and SlowMist. Gracy Chen, the CEO, said North Korean groups might be behind the attack, though how attackers first got in has not been revealed.

To understand how the breach could have occurred, BeInCrypto compiled a timeline from public information.

18:31 UTC on Sept 24: Bitget Spots Unauthorized Transfers

According to Bitget, its security systems identified the transfers at 18:31 UTC and triggered emergency steps within minutes.

Parts of the exchange's hot and warm wallets — used for daily operations — were compromised. The company said its offline cold wallets were not affected. The time of detection does not indicate when the attackers initially broke in.

最新的进展同步一下:我们正在与独立第三方专家 @Mandiant 和 @SlowMist_Team 合作,对此次事件进行全面调查。
其他几点都是说过的,我再强调一下:
-我们的首要任务是保障用户。用户余额保持完整,Bitget 用户保护基金将覆盖此次平台层面事件造成的影响。
-Bitget Wallet 为自托管钱包,运行于与… https://t.co/pZM4XzFolp

— Gracy Chen @Bitget (@GracyBitget) September 25, 2026

19:57 to 21:06 UTC: Suspicious Trades Trigger Warnings

At 19:57, analyst DCF GOD pointed out a new wallet that spent $19.67 million in USDT0 to purchase 7,111 ETH over six minutes. The trades reportedly went through at prices as much as 5% above the market rate.

The pattern indicated that whoever was behind it wanted to shift funds rapidly. The purpose remained uncertain.

By 21:06, Bubblemaps noted about $180 million had been transferred from Bitget wallets to a single receiving address, later divided among multiple wallets.

21:30 UTC: Chen Acknowledges the Attack

In a security update, Chen initially estimated the loss at $351.6 million and said withdrawals had been halted.

The announcement arrived roughly three hours after Bitget said it detected the incident. The delay raises questions about the exchange's response, but it does not necessarily mean funds were still being drained during that interval.

00:43 UTC Sept 25: Possible Method Revealed

Chen stated that the attackers broke into a crucial backend system — the software that controls wallet functions in the background.

They submitted fake transaction information and activated Bitget's approval mechanism. Put simply, the exchange's own system authorized the fraudulent movements.

Chen said theft of private keys was not the cause. A thorough public explanation is still needed regarding how the attackers accessed the backend and which security checks were bypassed.

Tough day for Bitget. I expect and know @Binance, the @BNBCHAIN ecosystem, and the community will do everything we can to help.

Stay SAFU! 🙏 pic.twitter.com/cyAEHdSi1S

— CZ 🔶 BNB (@cz_binance) September 25, 2026

14:03 UTC: Loss Updated to $387.5 Million

Bitget updated its loss figure after factoring in impacted Zcash and TRON holdings. The exchange said the revision came from a more complete tally of the initial theft.

The firm said the vulnerability has been patched. It pledged to announce a withdrawal plan by 04:00 UTC on September 26, though it did not guarantee that withdrawals would resume at that time.

Why Investigators Point to North Korea

Chen pointed to IP patterns and blockchain activity that match those of North Korean groups. Several characteristics are similar to the February 2025 Bybit hack, which the FBI linked to North Korea.

  • Manipulated approvals: In Bitget's case, fake instructions were sent to the authorization system. With Bybit, a corrupted interface deceived signers into approving a harmful transaction. The methods are not identical, but each case took advantage of the approval flow.
  • Rapid asset conversion: Funds tied to Bitget swiftly purchased ETH. The FBI noted that Bybit's stolen assets were also quickly converted into other digital currencies.
  • Splitting funds across wallets: Bubblemaps spotted multiple receiving wallets. According to the FBI, Bybit's stolen funds were dispersed across thousands of addresses.
  • Using THORChain: MistTrack noted that Bitget's stolen funds entered the THORChain protocol and pointed out that the same protocol had earlier been used to move Bybit's stolen assets.

These similarities warrant additional investigation. However, they alone do not identify who attacked Bitget.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles