Advertise

Avalanche

Bitget Attacker Converted $75.48M Into ETH and Avalanche (AVAX) Within 41 Minutes

The Bitget attacker converted $75.48 million in stolen stablecoins into ETH and Avalanche (AVAX) within 41 minutes; about $342 million remains unfrozen.

Be a creator
October 2, 2026, 09:32 AM UTC4 min read
AI SummaryAI
  • Bitget attacker stole about $387.5 million across 13 assets on 12 chains on September 25.
  • The attack ran 2 hours 52 minutes, from 02:31 test transfers to the final 05:23 withdrawal.
  • About $75.48 million in stablecoins and 3,000 XAUt were converted into ETH or AVAX within 41 minutes.
  • The attacker still controlled roughly $342 million, 88.3% of the haul, as of September 29.
mexc.com

The intrusion ran for 2 hours and 52 minutes. At 02:31 Beijing time on Friday, September 25, two test withdrawals left Bitget: 0.84 Ethereum (ETH) from its Ethereum hot wallet and 93 TRX from its TRON wallet, both below thresholds that would have triggered an alert. Large-scale outflows began at 02:58. Bitget's reconciliation system flagged a major discrepancy at 03:05 and risk controls blocked user withdrawals across the platform, but the transfers did not stop, because the attacker had written forged withdrawal commands directly into the wallet system. The final transfer went out at 05:23, the 26th successful outbound movement logged on the exchange's tracking panel; at 05:44, Bitget shut down its signing machines. The exchange's post-incident account describes a zero-day vulnerability in a third-party security product that let the intruder steal high-privilege internal network credentials, inject the forged commands, bypass risk-control checks and delete records after each transfer. Private keys were never exposed, Bitget said, and its cold wallets, kept separate from the HD wallet infrastructure behind its hot wallets, were untouched. Estimated losses were first reported at about $351.6 million, then revised to roughly $387.5 million once Zcash and TRON were counted, spread across 13 assets on 12 chains, with XRP the largest single-chain loss. User balances were unaffected, covered by the protection fund. Speed, not the Avalanche (AVAX) price or Ether's, drove the sequencing. About $75.48 million in USDT, USDC and USDT0, plus 3,000 XAUt gold tokens, were converted into Ethereum (ETH) or AVAX within 41 minutes of each theft, through UniswapX, Uniswap, 1inch and MetaMask's built-in swap, all clearing before Bitget CEO Gracy Chen first posted publicly at 05:30.

On-chain tracing through September 29 shows the funds moved in three steps: swap the freezable assets into native tokens, funnel everything toward Bitcoin (BTC), then feed the BTC into CoinJoin mixing. The exchange's tracking panel, with data as of 20:30 Beijing time on Tuesday, September 29, put about 90% of in-flight cross-chain volume as originating from Ethereum, a run that had lasted nearly five days by that snapshot. THORChain, the largest of the cross-chain bridges in the mix, took in roughly $269 million net across 7,804 transactions; the service settles asset exchanges between chains without custodians, an approach built on the atomic swap model. Chainflip followed at about $37.27 million. These are pass-through figures and cannot be added together, since one batch of funds can cross several services. Cumulative CoinJoin volume stood near $3.94 million, small next to the attacker's Bitcoin holdings. One CoinJoin transaction recorded at 19:03 on Sunday, September 27 carried 356 inputs and 401 outputs; four inputs of 2.5 BTC each traced back to attacker addresses, and its output list included 21 identical entries of 0.02097152 BTC that on-chain analysis cannot attribute to any single owner. By the fifth day after the breach, the attacker still controlled about $342 million, or 88.3% of the stolen total: roughly 83.7% in BTC, about 3,386 coins, 8.5% in ZEC, 7.3% in Ethereum (ETH), about 9,357 coins, and 0.2% in stablecoins. Publicly visible freezes came to only about $840,000, roughly 0.2% of the haul. Tether and Circle froze about $340,000, chiefly stablecoins that lingered as bridging intermediates, while NEAR Intents disclosed on Monday, September 28 that its SHIELD screening halted about $503,000 mid-execution after the attacker tried to push more than $50 million through the service. Gracy Chen publicly demanded on Saturday, September 26 that THORChain refuse the attacker's addresses; the protocol answered that it does not censor, and stolen funds were still moving from ETH to BTC through it as of September 29.

The $342M Still in Attacker Hands

The 41-minute swap window is the number COINOTAG's on-chain read keeps returning to. Once the freezeable stablecoins became ETH and AVAX, issuer freezes could only catch stragglers, and the roughly $840,000 ultimately frozen against $387.5 million taken measures that margin. Bitget's post-incident account puts the root cause at a zero-day vulnerability in a third-party security product used to steal privileged credentials and write forged withdrawal commands, with signing machines shut down at 05:44 as remediation. As of September 29, about $342 million still sat at attacker-controlled addresses. The same Avalanche network that carried stolen funds also settles institutional pilots, from NYSE's year-long technology trial to Goldman Sachs' tokenized treasury fund, and our Best Crypto Exchanges checklist treats custody discipline, not chain choice, as the deciding variable.

COINOTAG's editorial and research desk.

AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.