Bitget Hack Hits $387.5M After Its Own System Approved Fraudulent Ethereum (ETH) Transfers

Bitget confirmed a $387.5M hack on Sept 24 after its own backend approved fraudulent transfers. Withdrawals stay suspended; on-chain ETH buying traced live.

(03:33 AM UTC)
4 min read
AI SummaryAI
  • Bitget confirmed attackers stole $387.5 million from its wallets on September 24.
  • Bitget's security systems detected abnormal transfers at 18:31 UTC and activated emergency procedures.
  • A fresh wallet spent $19.67 million in USDT0 to buy 7,111 ETH within six minutes.
  • Bubblemaps traced roughly $180 million from Bitget wallets to a common receiving address.
k7rq2fdm

$387.5M Drained Through Its Own Approval System

Crypto exchange Bitget has confirmed that attackers stole $387.5 million from its wallets on September 24, in a breach where the platform's own authorization system approved the fraudulent transfers. Bitget's security systems detected the abnormal movements at 18:31 UTC and activated emergency procedures within minutes, but the intrusion reached parts of the hot and warm wallets that support daily exchange operations. The company says its offline cold wallets remained secure — although the detection timestamp does not establish when the attackers first gained access.

On-chain activity exposed the theft as it unfolded. At 19:57 UTC, analyst DCF GOD flagged a freshly created wallet that spent $19.67 million in USDT0 to buy 7,111 ETH in six minutes, paying up to 5% above market prices — behavior pointing to someone prioritizing speed of exit over execution cost. By 21:06 UTC, Bubblemaps traced roughly $180 million from Bitget-linked wallets to a single common receiving address before the funds split into several wallets. At 21:30 UTC, CEO Gracy Chen published her security notice — almost three hours after the stated detection time — confirming an initial loss of $351.6 million and the suspension of withdrawals. That gap leaves open questions about the response, though it does not prove funds kept leaving throughout.

The method, per Chen, involved no stolen private keys, which have been ruled out. Instead, attackers compromised a critical backend system — the software managing wallet operations behind the scenes — and fed it false transaction data, triggering Bitget's authorization process into approving the transfers. Bitget revised the loss to $387.5 million at 14:03 UTC on September 25 after including affected Zcash and TRON assets, said the vulnerability has been fixed, and promised a withdrawal-plan announcement by September 26 at 04:00 UTC without committing to reopening withdrawals then. How the attackers entered the backend, and which internal checks failed, still awaits a detailed public explanation.

North Korea Parallels Mount

Bitget has brought in Mandiant and SlowMist to investigate, and Chen has publicly suspected North Korean involvement, citing IP behavior and blockchain activity consistent with North Korean groups. The initial entry point remains undisclosed. When we line this incident up against the February 2025 Bybit theft — which the FBI attributed to North Korea — four patterns converge. First, manipulated approvals: Bitget describes false instructions reaching its authorization system, while at Bybit a compromised interface tricked signers into approving a malicious transaction; the mechanisms differ, but both exploited the approval process itself. Second, rapid asset conversion: the Bitget-linked funds immediately bought ETH, echoing the FBI's documentation of Bybit's stolen assets being swiftly converted into other cryptocurrencies. Third, fund-splitting: Bubblemaps identified several receiving wallets, mirroring how Bybit's proceeds spread across thousands of addresses. Fourth, THORChain: MistTrack reported Bitget's proceeds entering the cross-chain protocol, the same route previously used to move Bybit's stolen funds — a network whose liquidity pools give thieves fast cross-chain exit liquidity.

These parallels justify deeper investigation, but they do not independently identify Bitget's attackers, and the company has yet to name a suspect group. What the comparison does establish is method: social engineering aimed at the operational layer rather than at cryptography — the pattern behind the largest exchange losses of recent years. Withdrawals remain suspended as of publication, and Bitget says its protection fund covers the loss in full, a claim the market cannot verify until the withdrawal plan is published and payout mechanics become visible. The 18:31 UTC detection shows monitoring worked; the question investigators will press is why a compromised backend passed internal checks in the first place. Readers tracking the market in real time can follow live spot and futures prices on Binance.

Withdrawal Plan Due September 26

From COINOTAG's desk, the defining detail is that no key was stolen — the safeguard failed at the authorization layer, so remediation hinges on input validation and segregation of duties rather than key rotation alone. The on-chain record, from the wallet cluster split to the $19.67 million ETH sweep, remains fully traceable, which supports recovery if platforms freeze flagged flows. Unlike a flash loan exploit, this was a process breach — harder to patch. Bitget's withdrawal plan, due by September 26 at 04:00 UTC, is the next test of user confidence, and traders weighing custody risk can compare platforms in our guide to the best crypto exchanges.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.