Submit a Request

Bitget Hack Explained

Published On
01 Oct 2026 13:51
AuthorVigneshwaran Palanisamy

On September 24, 2026, cryptocurrency exchange Bitget suffered one of the largest security breaches of the year, losing approximately $388 million in digital assets through a sophisticated spoofing attack that tricked the platform's own authorization systems. Unlike traditional hacks involving stolen private keys, this incident exploited vulnerabilities in backend wallet infrastructure, allowing attackers to fabricate legitimate-looking transfer requests that Bitget's systems automatically approved.

Timeline of the Attack

The breach began at approximately 18:31 UTC on September 24, 2026, when Bitget's security monitoring systems first detected unauthorized transfers from portions of its hot and warm wallet infrastructure. Within the first hour, on-chain investigators had already tracked roughly $183 million in stablecoins, Ethereum, and other crypto assets moving out of wallets tagged as belonging to the exchange.

By the time Bitget publicly confirmed the incident hours later, total losses had climbed to $351.6 million, and subsequent reconciliation efforts that included previously omitted Zcash and TRON transfers raised the final tally to approximately $387.5 million. The attack unfolded across 19 to 23 separate transactions spanning multiple blockchain networks, with most of the funds drained in two coordinated bursts hitting five chains within seconds.

Despite detecting the breach at 19:05 UTC and activating emergency protocols, Bitget's wallets continued paying out to the attacker for more than two hours after initial detection, highlighting critical gaps in real-time response capabilities. The exchange suspended withdrawals as a precautionary measure while keeping deposits and trading functionality operational, and by September 28, 2026, began resuming Bitcoin and Ethereum withdrawals in phases after completing security reviews.

Attack Method

The defining characteristic of the Bitget hack was that attackers never stole private keys, the cryptographic credentials traditionally required to move funds from exchange wallets. Instead, the breach exploited a vulnerability in a third-party security product to obtain high-level internal network credentials, which were then used to compromise a critical backend system within Bitget's wallet infrastructure.

Once inside this backend system, attackers fed Bitget false transaction instructions that appeared legitimate, effectively spoofing transfer data and triggering the exchange's own authorization-signing process. In technical terms, the attackers sent fraudulent withdrawal commands that Bitget's systems accepted as genuine, causing the exchange to sign and execute transfers itself without any external key compromise.

This method differs fundamentally from the February 2025 Bybit hack, where attackers stole private keys directly from a Ledger hardware wallet used for cold storage multisig authorization. In the Bitget incident, no vaults were broken into and no secret codes were stolen instead the attacker simply sent fake instructions dressed up as real ones, and Bitget's systems followed them exactly as designed.

Blockchain analytics firm Bitquery traced all 23 transfers and noted that the transactions were signed by Bitget's own wallets using settings that customer withdrawals never employ, indicating the attacker had access to internal operational parameters. This level of access suggests the compromise extended deep into Bitget's wallet management architecture, potentially through a third-party security tool that provided elevated credentials.

Affected Assets and Blockchain Networks

The stolen funds spanned an extensive range of digital assets across 11 blockchain networks, making this one of the most geographically diverse crypto hacks on record. The affected networks included Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia.

On-chain tracker Lookonchain identified 102.93 million XRP (approximately $157.48 million) as the largest single asset category, followed by 31,890 ETH (about $85.75 million). Other affected assets included substantial amounts of Tether (USDT), USD Coin (USDC), USDT0, 3,000 XAUt of tokenized gold, BNB, AVAX, TRX, and Zcash (ZEC).

The transfers involved 12 wallet addresses associated with Bitget's hot or warm wallet infrastructure, with cold wallets remaining fully secure throughout the incident. Bitget CEO Gracy Chen emphasized that user funds were safe because the full amount of the loss fell within the coverage of Bitget's User Protection Fund, which held over $464 million at the time of the breach.

North Korea Attribution and Investigation

Within days of the incident, Bitget publicly stated that preliminary evidence pointed to North Korean hackers as the likely perpetrators, citing patterns consistent with previous state-sponsored crypto theft operations. CEO Gracy Chen described the attribution during a three-hour livestream on X, noting that the attack methodology aligned with known tactics used by Pyongyang-linked hacking groups.

Fortune reported that Bitget suspects North Korean attackers exploited the backend wallet system to make fraudulent withdrawals appear legitimate, a technique previously observed in other major crypto heists attributed to the Lazarus Group and related entities. The exchange partnered with third-party cybersecurity experts Mandiant and SlowMist to conduct a comprehensive forensic investigation into the incident. Bitget also launched a recovery-bounty program offering rewards of up to 5% for funds successfully frozen or recovered, and released a real-time tracking dashboard to help external researchers and other platforms identify the attacker's wallets.

Recovery Efforts and Fund Movement

Following the breach, the attackers moved quickly to convert stolen assets into more liquid forms, selling stablecoins for ETH within minutes and consolidating funds from multiple chains onto Ethereum. On-chain investigators tracked the movement of stolen BNB into Bitcoin through THORChain, a cross-chain exchange protocol, as part of ongoing laundering efforts. NEAR Intents, a permissionless cross-chain swap service, identified more than $50 million in attempted transfers linked to the Bitget hack, though most were subsequently rejected or moved through other providers. The service reported stopping approximately $503,000 in suspicious transactions while about $166,000 passed through before additional controls were implemented.

Bitget's User Protection Fund, valued at over $464 million, remains sufficient to cover the entire $388 million loss if recovery efforts prove unsuccessful. The exchange has committed to compensating affected users in full, maintaining that no customer funds are at risk despite the scale of the breach.

Security Implications for the Crypto Industry

The Bitget hack underscores a growing trend in 2026 where attackers target backend infrastructure and third-party integrations rather than pursuing traditional private key theft. This shift reflects increasing sophistication in attack vectors, with threat actors exploiting trust relationships between exchanges and their security vendors to gain elevated access.

Industry analysts note that the incident highlights the importance of zero-trust architecture in crypto exchange design, where every internal system and third-party tool must be treated as a potential attack surface. The fact that Bitget's own authorization process approved fraudulent transfers suggests that multi-layer validation and anomaly detection mechanisms may need strengthening across the sector.

Bitget's decision to publish attacker addresses, offer bounties for recovery, and maintain transparency throughout the investigation has been viewed positively by the crypto community, setting a precedent for how exchanges should respond to major security incidents. The phased resumption of withdrawals beginning September 28, 2026, demonstrated that rapid containment and remediation are possible even in complex multi-chain breaches.

Lessons for Exchange Security Architecture

The Bitget incident offers several critical lessons for cryptocurrency exchanges and their security teams. First, reliance on third-party security products introduces additional attack vectors that must be rigorously audited and monitored. Second, backend wallet systems require isolation and access controls that prevent compromised credentials from triggering unauthorized transfers.

Third, real-time transaction monitoring must include behavioral analysis capable of detecting anomalous transfer patterns even when transactions appear properly authorized. Finally, exchanges should maintain robust incident response playbooks that enable immediate fund freezing across all affected chains, rather than allowing continued outflows after initial detection. As the crypto industry continues to mature, incidents like the Bitget hack will drive innovation in security architecture, pushing exchanges toward more resilient designs that can withstand increasingly sophisticated attacks.

Current Status and User Guidance

As of October 1, 2026, Bitget has resumed Bitcoin withdrawals on the Bitcoin network and BNB Smart Chain, with Ethereum withdrawals following on September 29 and USDT withdrawals on September 30 across multiple chains. The exchange continues to work with security partners on asset tracing and recovery efforts while maintaining full transparency through its incident dashboard.

Users affected by the withdrawal suspension are advised to monitor official Bitget communications for updates on phased service restoration. The exchange has confirmed that all user balances remain intact and fully backed by the User Protection Fund, ensuring no financial loss to customers despite the scale of the breach.


Leave a Comment