⚠️ Bitget $387.5M hack: status update and security analysis
Bitget now puts the theft at about $387.5M, up from the fir | Hanami
⚠️ Bitget $387.5M hack: status update and security analysis
Bitget now puts the theft at about $387.5M, up from the first $351.6M figure. The increase adds Zcash and TRON. It is not a second raid. Compromised wallets were some of Bitget Exchange’s hot and warm wallets. Bitget says cold storage and the separately operated Bitget Wallet self-custody product were not hit.
This was not a private-key leak. It was another break in the transaction-signing trust chain. Attackers got Bitget’s own signing stack to produce valid signatures for transfers the exchange never meant to send, then those transfers confirmed. Same structural risk as the 2025 Bybit hack ($1.5B, Safe signing UI tampered): one signing pipeline, one trust root, an obvious target.
GoPlus has blacklisted attacker-linked addresses and shared the set with ecosystem partners to help freeze flows and cut residual loss.
I. Timeline
Sept 24, 18:31 — attacker receive address funded with 0.84 ETH for gas. The gas came from a Bitget hot wallet already under attacker control. Bitget says unauthorized transfers were detected the same minute.
18:58 — first large out: ~$34.75M USDT to the same address funded 27 minutes earlier.
19:16 — largest wave: ~$185M withdrawn in about a minute, including 13,966 ETH on Ethereum, ~91.4M XRP on XRPL, and 20.6M TRX on TRON.
18:58–21:23 — 2h 25m multi-chain drain window: ETH / USDT / USDC / AVAX / BNB / XAUt / XRP / TRX.
From 19:00 — attacker swapped stables to ETH via DEX and bridged the pile onto Ethereum.
~21:30 — Bitget CEO Gracy Chen posted the security notice and paused withdrawals.
~22:00 — ~$155M on EVM (ETH/AVAX) split into multiple “dormant vault” addresses.
Sept 25, 02:13 onward — continued splitting and movement. Trace: https://trace.bgblockchain.xyz/v2#explorer
Sept 26 — Bitget said root-cause work and system fixes were done and began reopening withdrawals.
II. Root Cause Analysis
Official update
Gracy Chen: attackers compromised a critical backend system in the wallet infrastructure, forged transaction data, and drove Bitget’s own authorized signing flow to move funds. Key leak ruled out. Full technical report and the exact intrusion path are still unpublished.
Structural root cause: signing pipeline trusts a single backend
Typical CEX withdrawal path: user request → backend checks (balance / risk / whitelist) → build unsigned tx → MPC / multisig / HSM signs → broadcast.
What broke: attackers bypassed backend checks and built unsigned txs that risk controls never stopped. The signer — MPC or multisig — cannot judge what it should sign. It signs whatever the backend hands it.
They did not take the key layer. They took the risk-decision layer. Once the “what to sign” data source was poisoned, every control sitting on that same backend — rules, limits, approvals — was skipped.
Supporting detail: the 0.84 ETH gas on the receive address came from Bitget’s own compromised hot wallet. Before the main drain, they could already drive the signing path. That was a dry run.
Forged data also explains the ~3-hour gap: “detected” at 18:31, last out at 21:23. Those transfers likely looked legitimate to internal monitoring, or the signing pipeline had no remotely triggerable kill switch. That delay needs a postmortem as much as the intrusion itself.
Possible initial paths (speculation, pending the official report)
▪️ Direct tampering / fake rows in the withdrawal database
▪️ Forged or replayed internal API calls (weak request-level auth / no replay protection between backend and signer)
▪️ Injection into the backend → signer message queue
▪️ Whitelist / address-map swap (user withdrawal address replaced with the attacker’s)
Compared with the 2025 Bybit hack
Bybit: Safe frontend injected with a malicious script. Signers saw one thing, signed another.
Bitget: backend data forged. No human “see” step. Automated signing just ran.
Same WYSIWYS failure, front-end vs back-end. Both incidents are being tied to DPRK clusters.
III. Attacker addresses and attribution
Bitget and the industry published primary attacker / first-hop receive addresses early, including:
0xA6dD3F218B65E32Ccc37BE30f74884133c655545
0xD2C2f029eFF5caCc686F24377CfdDcfc82d9F899
0x600cfeDc6Bd65Fa79B604dC44964f419e45784b2
0x94A43df7687A8494948Be937400e9d5D33135DA0
0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee
0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C
They have kept splitting and hopping to slow tracing and freezes. Related addresses are now near 900. More: https://trace.bgblockchain.xyz/v2#explorer
“Highly likely DPRK-linked,” on three layers:
▪️ On-chain links — researcher Specter tied bridged stolen XRP to proceeds from the July 2026 $24M AFX attack. Elliptic further linked this case to Bybit 2025 laundering addresses.
▪️ Off-chain signals — Bitget investigators matched IPs to a VPN pattern used by a known DPRK cluster (disclosed by Gracy Chen on an X live).
▪️Laundering pattern — stables / non-native assets swapped to native gas tokens within minutes to dodge issuer freezes. Classic DPRK playbook. Funds on Arbitrum were also jumped to Ethereum L1 fast, after the KelpDAO lesson: Arbitrum’s Security Council froze 30,766 ETH; Ethereum L1 cannot.
Note: Bitget has not published the technical basis for the DPRK attribution. Chen’s wording is “very likely.” High-confidence assessment, not a closed case.
IV. What CEXs should do now
1️⃣ Stand up an independent pre-sign risk engine
The failure mode: every control that trusted the business backend died with it. A separate system should simulate and score every tx before sign — size, outflow velocity, first-seen receive address, threat-intel denylist. “Tens of millions in one shot, brand-new receive address, several hot wallets firing in the same window” should have tripped any independent rule.
2️⃣ Circuit breakers and rate limits
Detected 18:31, last send 21:23. Almost three hours with no halt. If the first $34.75M had tripped a breaker, about 90% of the funds stay in the house.
3️⃣ People and supply chain
DPRK clusters live on social engineering, fake recruiting, and vendor compromise. Treat staff security, operational risk, and software supply chain as first-class controls, and reassess them on a schedule.