Bitget - Rekt



The keys were never stolen. The wallets were drained anyway.

Bitget initially said its security systems flagged unauthorized transfers at 18:31 UTC on September 24.

The newly published investigations push the story further back: SlowMist traces the earliest malicious activity in the available logs to August 31, when an attacker exploited a zero-day in a third-party security product.

Over roughly three hours, attackers pulled $387.5 million from the exchange across Ethereum and other EVM networks, XRP, Zcash and TRON, the largest crypto theft of 2026 so far by DefiLlama's count.

Mandiant’s Incident Response Status Report says Bitget found no evidence that private keys were compromised and that cold wallets were unaffected.

Instead, Mandiant says the attacker gained unauthorized privileged access to third-party security appliances, before moving laterally to Bitget’s production wallet job server.

SlowMist recovered a custom tool that forged risk-control parameters, constructed withdrawal requests and invoked the wallet’s withdrawal process.

Investigators are still working out how the attacker moved between the affected systems.

Arkham says $228 million left in just 18 minutes.

The largest asset component was roughly 103 million XRP ($157.48 million), which cannot be frozen on the ledger.

Bitget says its protection fund covers the loss. BTC withdrawals have resumed on Bitcoin and BNB Chain, while other assets remain on a phased schedule.

Gracy Chen, Bitget’s CEO, has raised a possible DPRK link, though attribution remains unconfirmed.

TRM Labs found overlaps between the laundering network handling the proceeds and wallets used in earlier North Korean-linked hacks, but says it has not definitively attributed the Bitget intrusion to North Korea.

Bitget has now published progress reports from Mandiant and SlowMist, but neither identifies the third-party vendor or fully explains the attacker’s movement between systems.

When the signer does exactly what it’s told, who’s really holding the keys?

Credit: Gracy Chen, Arkham, Bitget, DefiLlama, decrypt, Lookonchain, XRP, TheBlock, DCF GOD, CoinDesk, Officer’s Notes, Hacken, Foresight News, U Today, Bybit, vdiceco, AMLBot, MistTrack, ZachXBT, Ben Zhou, THORChain, Star Xu, GoPlus Security, Cos, Specter, Michael Perklin, Alex Shevchenko, Illia Polosukhin, TRM Labs, CoinTelegraph

One early public clue was a bad trade.

Around 19:57 UTC on September 24th, DCF GOD flagged a freshly created wallet dumping 19.67 million USDT0 for 7,111 ETH in six minutes, paying up to 5% over market through UniswapX and 1inch Fusion.

Nobody pays that kind of premium for convenience. Stablecoins can be frozen by their issuer and ether can't. It looked like a race against a blacklist.

About a quarter hour later, Officer’s Notes pointed to the broader Bitget outflows: "It looks like bitget hot wallet might've just been hacked."

By that count, $174 million had crossed multiple chains into a single address within the hour.

At 20:56 UTC, Hacken posted a preliminary on-chain assessment, with roughly $145 million traced in ETH, USDT, USDC and tokenized gold, and transfers on BNB Chain, Avalanche and USDT0 still under review. Bitget, it noted, had not issued any statement at the time.

The transactions showed money leaving Bitget; they did not show whether the attacker had reached its private keys or cold storage.

Bitget would later say its cold wallets were unaffected.

Mandiant’s preliminary status report repeats that assessment and says Bitget observed no evidence of compromised private keys.

Bubblemaps followed at 21:06 UTC, mapping around $180 million from Bitget wallets into one address before it scattered across six more.

The early tallies were still missing the biggest piece. Arkham's later reconstruction put roughly $153 million of XRP in the outflows, sent to a fresh XRP Ledger address, pushing its total to about $350 million.

At 21:30 UTC, Bitget spoke. Gracy Chen posted a security notice on Twitter that put the loss at approximately $351.6 million, said cold wallets "remain fully secure" and announced paused withdrawals. Chen promised a full incident report, including root cause analysis, within 24 hours.

Arkham’s observed drain window ended at 21:23 UTC, seven minutes before Chen’s notice and nearly three hours after Bitget’s initially reported detection time. By then, researchers had published the receiving address.

Just after midnight UTC, Chen offered the explanation that would define the incident: A compromised backend, spoofed transaction data and Bitget's own authorization process moving the funds.

The count kept climbing. On September 25, Bitget revised the loss to $387.5 million, adding Zcash and TRON transfers left out of its first estimate.

The higher figure, Gracy Chen said, reflected a more complete accounting, not additional theft.

The chain had given up its side of the story. Bitget's side was still unfolding, one statement at a time.

What exactly happened inside Bitget while the money kept moving?

Infiltrating the Defenses

The exploit appears to have been in the making weeks earlier.

SlowMist’s investigation traces the earliest malicious activity in the available logs to August 31, when a zero-day affected a service on a third-party security product it calls Product A.

A hidden script read an environment variable holding a database password and connected to the database; similar activity appeared on other Product A nodes on September 23 and 25.

Mandiant’s preliminary findings place unauthorized privileged access to two third-party security appliances on September 24. It says the attacker planted a web shell on one appliance, established a command-and-control connection, then moved laterally to Bitget’s production wallet job server and deployed malicious packages.

SlowMist reports all times in UTC+8; the times below have been converted to UTC.

SlowMist’s account picks up another part of the path: At 16:07 UTC on September 24, the attacker began trying to inject commands into Product B’s task parameters after accessing its management platform using an internal employee identity.

The attacker also submitted code through its web execution endpoint in attempts to alter configuration and assemble malicious files. SlowMist says it is still investigating how the attacker moved between the systems.

SlowMist recovered a customized withdrawal tool from the files the attacker had deleted. It says the tool forged risk-control parameters, constructed withdrawal requests and invoked the wallet system’s withdrawal process.

Host logs place the malicious program’s execution at 17:49 UTC on September 24, 42 minutes before the first verified on-chain transfer.

The newly released reports from Slowmist and Mandiant add the weeks-long intrusion and the path into the wallet environment.

Gracy Chen had already outlined the public-facing chronology in a September 28 livestream, summarized by Foresight News.

At 18:31 UTC, the attacker sent 0.84 ETH and 93 TRX out of Bitget's Ethereum and TRON hot wallets.

Both amounts sat below the exchange's risk-control threshold, and no alert fired.

Bitget initially said its systems detected unauthorized transfers at 18:31 UTC. Its later account says the small transfers at that time triggered no alert. It has not explained the discrepancy.

At 18:58, the large transfers began. Bitget counted 17 of them through 20:09 UTC, across XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism and more, worth about $360 million.

At 19:05, Bitget's reconciliation system spotted a significant discrepancy.

Bitget says its risk controls automatically blocked user withdrawal requests at the same time.

They did not stop the attacker's wallet-system commands: The large-transfer window in Bitget's account continued until 20:09, with a second wave later that evening.

At 19:14, Bitget declared a P0 emergency.

At 19:40, the technical team began loss mitigation.

At 20:40, with private key theft still not ruled out, the wallet team started moving funds into cold wallets.

Fifteen minutes later, a second wave hit. Seven more transfers between 20:55 and 21:13 UTC, across Avalanche and other chains, took roughly $28 million more.

SlowMist’s compiled transfer records run through 21:23:11 UTC. Its logs also show that, after the transfers had begun, the attacker attempted to alter withdrawal records and initiate two fabricated BTC withdrawal orders; both entered processing but returned errors.

Bitget halted its signing machines and isolated wallet withdrawal services at 21:44 UTC, two and a half hours after the emergency response began and 14 minutes after Chen's 21:30 notice.

At 08:43 UTC on September 25, Bitget says its security team identified the root cause. The story it tells is one of legitimate identities doing illegitimate work.

According to Chen, the attacker exploited vulnerabilities in third-party security products to steal internal credentials.

With those credentials, the attacker impersonated authorized activity and sent fraudulent withdrawal commands to Bitget’s wallet system, according to the exchange.

The reports make Bitget’s earlier account more concrete: Both firms identify compromised third-party security products as the route that ultimately enabled unauthorized access to Bitget’s wallet environment; SlowMist says the recovered withdrawal tool forged risk-control parameters and invoked the withdrawal process. Neither report yet fully explains how the attacker moved between the affected systems.

After the transfers, Chen said, the attacker disguised its activity as routine administrative work while “removing traces of their actions.”

Bitget said it found no common viruses or malware in the attack chain and described the breach as a highly targeted attack.

That “no common viruses or malware” claim should not be read as “no malicious code”: Mandiant reports a web shell and malicious packages, while SlowMist recovered the customized withdrawal tool from deleted files.

Private keys were not compromised, and insider involvement has been preliminarily ruled out.

The keys stayed put, Bitget says, while its wallet system executed fraudulent commands.

By contrast, Bybit’s signers saw a spoofed Safe wallet interface.

Bitget’s account, so far, describes forged commands sent to its wallet system, rather than a human signer being deceived.

Chen says Bitget has since isolated the affected servers, revoked and reissued internal credentials, restructured access to sensitive systems, and notified the vendor, disabling the affected functionality pending a fix.

It says it is also strengthening how it assesses and deploys third-party security products.

Bitget has not named the products or their vendor; SlowMist’s report identifies them only as Product A and Product B.

How did access to the compromised security products become control over the wallet job server, and where could that movement have been stopped?

The movement of the stolen funds, however, was already visible.

With the doors sealed and the signing machines finally dark, where was $387.5 million headed?

Catch What You Can

The attacker didn't wait to learn who would freeze what.

Within minutes of the drain, Arkham says, stablecoins and tokenized gold were already being sold for ETH.

$25 million of USDT went to Rizzolver, a UniswapX filler, in five $5 million fills. The remaining USDT moved through Uniswap, 1inch and Furucombo, while USDC was bridged to Ethereum and sold there.

Freezable tokens were being turned into ETH.

From 19:44 UTC, ETH on Arbitrum, Optimism and Base was bridged to Ethereum through Across, Stargate and LayerZero, mostly in 400 to 500 ETH lots.

By 20:04, the cross-chain legs were done, and roughly $100 million of non-ETH assets had become about 36,600 ETH.

Then came the parking. The first 10,000 ETH wallet was funded at 20:13 UTC. By 22:45 there were six, and Arkham later counted 68,300 ETH, about $183 million, across eight fresh addresses.

The XRP took a different route. Three transfers sent 102.98 million XRP out of Bitget. Six accounts holding the stolen XRP then sent it out in chunks; by 07:43 UTC on September 27, those accounts were empty. Bitquery traced the funds through new accounts to THORChain, where 90.5% of the stolen XRP was swapped for bitcoin and 7.6% for ETH.

BNB never sat still. Arkham tracked $6.9 million split across 12 BNB Chain wallets, with at least $4.7 million deposited to THORChain and $2 million to FixedFloat.

Some funds could still be frozen. The first public example was small. Circle blacklisted "Bitget Exploiter 8" at 05:00 UTC on September 25 and Tether followed, stranding about $318,000 in stablecoins by CoinDesk's count.

Bitget says other freezes have been secured through industry partners, without saying how much.

Tether later froze another 21,091 USDT in a second attacker wallet, bringing the publicly identified issuer freezes to about $339,000.

NEAR Intents separately says it froze $503,000 during attempted swaps. Together with the issuer freezes, that puts the publicly identified restricted funds at about $842,000, or 0.22% of Bitget’s $387.5 million loss.

That is not money recovered, nor a complete tally: Bitget says other affected assets were frozen through industry partners, without giving an amount.

In a September 25 snapshot, AMLBot counted about $343 million, roughly 88% of the roughly $389 million it tracked, dormant across 13 attacker wallets.

Elsewhere in the attacker's holdings, the money kept moving.

On September 26, AMLBot reported a possible Bitget-linked route into a Wasabi CoinJoin.

It traced roughly 4 BTC in the CoinJoin back to a TRON wallet through swaps and a USDT0 bridge: TRX became USDT, then about 145 ETH on Ethereum, then roughly 4.59 BTC through THORChain.

The ETH began moving too. Lookonchain flagged ETH-to-BTC swaps through THORChain on September 28.

In the same route, CoinDesk identified 27 successful swaps between about 03:55 and 06:23 UTC: Roughly 2,390 ETH, worth $6.3 million, became 75.2 BTC paid to one address.

That is one dated slice of the ETH movement, not a total for the route.

MistTrack reported that a Chainflip broker rejected a deposit from the Bitget exploiter and refunded it to the sender.

Then people alleged to be moving the money went looking for customer service.

On September 28, ZachXBT said operators he described as Chinese launderers acting for the alleged DPRK attackers were asking for help with orders in public Discord and Telegram channels.

He listed five aliases alongside transaction hashes and said one alias had also appeared in laundering linked to April’s $292 million KelpDAO exploit.

The aliases remain investigative leads. The addresses receiving the stolen funds are on Bitget’s published list.

Primary attacker receiving addresses, per Bitget:

EVM: 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee

XRP: rwNhefsz1UQEusxhCvHip3RANinWi4CTck

ZEC:
t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG

TRON:
TBWNguTTgezw9dVorX441C6nDrZpRxYwKD

For those who want to track the exploiter’s main address, here is the Bitget Hacker on Arkham

The addresses were public. The money kept moving.

When it reached someone who could stop it, would they?

The Big Red Button

Bitget's recovery effort has depended on others acting.

On September 25, they launched a Recovery Bounty Program, offering eligible voluntary contributors a bounty of up to 5% of funds they helped freeze or recover.

The bounty also covers freezes secured before the program launched, but excludes actions taken under court orders or law-enforcement requests. Bitget decides who qualifies and how much to award.

Bitget announced a live tracing dashboard, a recovery-submission portal and an attacker-address API, and named Bybit’s LazarusBounty platform as a core recovery channel.

Bybit CEO Ben Zhou offered help, noting that Bitget had backed Bybit through its own hack in 2025.

Then Bitget asked the one venue its tracers kept pointing at.

MistTrack had already framed the question on September 25. After Bybit, it said, nearly $1.2 billion in stolen funds was reportedly traced through THORChain, and Bitget exploiter funds were now heading the same way.

At 11:44 UTC on September 26, Chen went public with her request: "We are formally asking THORChain to refuse service to these addresses," she wrote, adding that decentralization "is a design principle, not a shield for facilitating known stolen funds."

THORChain's reply arrived that evening. It said it was "devastated" by the exploit, then described itself as decentralized and permissionless like Bitcoin, Ethereum and BNB Chain, and asked what responsibility those networks bear for known stolen funds?

Critics rejected the comparison.

OKX founder and CEO Star Xu rejected THORChain’s comparison with Bitcoin and Ethereum. Its selected validators collectively control assets in TSS vaults and can move them once a signing threshold is met, he argued, making THORChain an intermediary between users and the native chains: “Distributing an intermediary does not eliminate the intermediary.”

GoPlus Security said node votes can pause outbound signing on a single chain. By its estimate, the Bybit attacker moved nearly 499,000 ETH within ten days, mostly through THORChain, generating roughly $5.5 million in protocol fees. "Do not put the industry at risk for the fee line," they wrote.

SlowMist founder Cos, whose firm is working on Bitget’s investigation, pointed to THORChain’s emergency pause procedure.

His challenge was the apparent double standard: THORChain had halted the network when its own protocol was attacked, but would not halt it as stolen Bitget funds passed through.

Specter was blunter, saying THORChain only acts when the loss is its own.

On September 27th, THORChain answered again: "A halt is not a selective freeze of specific funds or an individual swap," it wrote, adding that it "doesn't censor by design." During its May 2026 exploit, it said, the attackers' addresses were never blacklisted either.

It found at least one defender. Michael Perklin called GoPlus's argument "cherry picking at best, a false equivalency at worst," arguing that all tools are inherently neutral.

Not every protocol took THORChain's line.

NEAR Intents general manager Alex Shevchenko reported that attackers tried to push more than $50 million through the cross-chain protocol. About $166,000 got through, and $503,000 was frozen mid-execution, figures he called indicative and rounded, within about 10%.

The blocking came from SHIELD, a risk-intelligence layer that, per Shevchenko, declines to quote a trade tied to a hack or halts it once execution has begun. "Permissionless doesn't mean neutral," he wrote. NEAR Intents also said it was waiving any bounty, while telling Bitget to pursue the frozen funds through legal and law-enforcement channels.

NEAR co-founder Illia Polosukhin backed the call. Permissionless, he wrote, "does not mean every application or liquidity provider must process every transaction."

Chen thanked NEAR Intents for showing what "permissionless but not 'facilitating known stolen funds” should look like.

On THORChain, the swaps kept clearing while the argument ran.

The two protocols described different ways to intervene.

NEAR Intents said its SHIELD layer could decline a quote or halt an execution already underway.

THORChain said a network halt is an emergency measure to protect the protocol, not “a selective freeze of specific funds or an individual swap.” It said the attackers’ addresses were not blacklisted during the May exploit and that it “doesn’t censor by design.”

Chen had asked it to refuse service to Bitget’s listed attacker addresses; THORChain’s stated policy left that request unanswered in practice.

Inside the exchange, recovery looked different.

Bitget said it had isolated the affected systems and remediated the vulnerability. It then began restoring withdrawals in phases, starting with BTC on Bitcoin and BSC on September 28.

ETH withdrawals reopened on September 29 across Ethereum, BSC, Arbitrum One, Base and Optimism.

Bitget says USDT withdrawals have now reopened on Ethereum, BSC, Solana and Tron. Chen says P2P withdrawals and the remaining services are scheduled for Friday, October 2, at 08:00 UTC.

Bitget reported that its Protection Fund was backed by 5,500 BTC before the incident. Chen said the fund would cover the incident’s financial impact and that users were “100% covered”.

Chen says the fund is back above $300 million, fulfilling her pledge to replenish it within a week.

She also reported a 131% proof-of-reserves ratio in the September 29 update.

Bitget has also launched two programs: The Bitget Alliance Program, which allocates a reward pool equivalent to 30% of eligible net transaction-fee revenue to qualifying users based on trading activity or asset holdings; and Project Stand Together, which offers PRO users 20% taker-fee discounts, increases maker rebates for Futures Group A under its Liquidity Incentive Program, and extends PRO tier protection.

Chen called this the exchange's first security incident of its kind in eight years.

The wallets were mapped. The people behind the breach were not.

If the money can be tracked in public but not stopped, wasn't the only real chance to stop it back inside Bitget?

Nobody needed to steal the keys.

By Bitget’s account, a vulnerability in an unnamed third-party security product handed an attacker valid internal credentials, and a wallet system built to obey its own backend did the rest. Bitget says its private keys were not compromised.

Chen says users’ funds are fully covered by Bitget’s Protection Fund, and BTC, ETH and USDT withdrawals have reopened.

Recovering the stolen assets is another matter: Bitquery documents about $339,000 frozen by Circle and Tether, while NEAR Intents says it stopped another $503,000 mid-execution, together roughly 0.22% of Bitget’s reported $387.5 million loss, with no confirmed total across all services.

Gracy Chen told CoinTelegraph she was “not very optimistic” about recovering the stolen funds. She pointed to the 2025 Bybit hack, saying only about 3.5% of its stolen funds had been frozen after roughly a year, and stressed that freezing is not the same as recovery.

TRM Labs links the laundering network to one previously used by TraderTraitor, but has not definitively attributed the intrusion to North Korea.

Bitget has not named the vendor. Progress reports from SlowMist and Mandiant now describe the compromise of third-party security products and access to Bitget’s wallet environment, but SlowMist says it is still investigating how the attacker moved between the affected systems.

The reports show where the trail leads, but not which products other exchanges should be examining.

How does the industry fix a shared weakness it still cannot name?


bu makaleyi paylaş

REKT, anonim yazarlar için halka açık bir platform olarak hizmet eder, REKT'te bulunan görüşler veya içerik için hiçbir sorumluluk kabul etmiyoruz.

bağış yap (ETH / ERC20): 0x3C5c2F4bCeC51a36494682f91Dbc6cA7c63B514C

sorumluluk reddi:

REKT, Web Sitemizde veya hizmetlerimizle bağlantılı olarak web sitemizin ANON yazarı veya REKT tarafından gönderilen, yayınlanan veya neden olunan hiçbir içerikten hiçbir şekilde sorumlu veya yükümlü değildir. Anon yazarın davranışları ve gönderileri için kurallar sağlamamıza rağmen, onun web sitemizde veya hizmetlerimizde yayınladığı, ilettiği veya paylaştığı şeylerden sorumlu değiliz veya web sitemizde ve hizmetlerimizde karşılaşabileceğiniz herhangi bir saldırgan, uygunsuz, müstehcen, yasa dışı veya başka şekilde sakıncalı olan içerikten sorumlu değiliz. REKT, Web Sitemizin veya Hizmetlerimizin herhangi bir kullanıcısının çevrimiçi veya çevrimdışı davranışlarından sorumlu değildir.