Bitget Loses $352M in Spoofed Transfer Hack, Not Private Key Breach

Share

On September 25, 2026, Bitget CEO Gracy Chen confirmed a $351.6 million hack caused by a compromised internal backend that spoofed transaction data, not stolen private keys. Attackers moved funds across multiple blockchains within one hour, and IP addresses point to North Korea.

🔑 Key Takeaways

  • $351.6 million stolen on September 24, 2026 via spoofed transfers without compromising private keys
  • Breach detected at 18:31 UTC; funds moved across multiple blockchains in one hour
  • XRP accounted for roughly $157.4M of the loot; ETH, USDT, and USDC combined exceeded $140M
  • User Protection Fund of $464M covers the full loss; withdrawals remain frozen
  • Attribution likely points to North Korea’s Lazarus Group based on VPN fingerprints and MO

The Breach: A Compromised Backend, Not Stolen Keys

Bitget CEO Gracy Chen publicly confirmed the hack on September 25, 2026 via X. Attackers stole $351.6 million by compromising a backend system within the exchange’s wallet infrastructure. Rather than targeting private keys directly, they spoofed transaction data and tricked the internal authorization process into validating unauthorized transfers.

The breach was detected on September 24, 2026, at 18:31 UTC, when Bitget’s systems flagged unauthorized transfers from multiple hot wallets (internet-connected wallets used for daily transaction processing). Funds were moved within one hour, distributed across several blockchains to hinder the defensive response. The attackers reached the warm wallet layer, the semi-connected buffer zone between automated hot wallets and fully offline cold storage. Cold wallets remain fully secure, according to Chen. The exchange stated it halted unauthorized transfers and does not anticipate further movement.

« Private key compromise has been ruled out. »

Gracy Chen, CEO of Bitget

Stolen Asset Breakdown: XRP Takes the Lead

The composition of stolen assets reveals the attackers’ strategy. XRP accounted for nearly half the loot, with approximately $157.4 million. Ethereum, USDT, and USDC made up the remainder, for a combined total exceeding $140 million. This distribution reflects a priority on immediate liquidity rather than concentration in any single token.

On-chain analysts tracked the funds in real time. Arkham Intelligence publicly flagged the outflows within minutes, identifying significant movements of AVAX, BNB, ETH, and multiple stablecoins. A newly created wallet converted approximately $19.7 million of USDT0, Tether’s cross-chain variant, into 7,111 ether within six minutes, according to data reported by Decrypt. The attacker agreed to pay up to 5% above market price to execute the swap quickly.

Laundering Through Tornado Cash

The same pattern continued: after converting USDT to ether, the assets were sent to Tornado Cash, the mixing protocol used to obscure transaction trails. The attacker has already routed 6,300 ETH, worth approximately $19.4 million, into the mixer. More recently, they withdrew 1,000 ETH, roughly $3.24 million, from the lending protocol Aave and funneled them through Tornado Cash. In total, approximately $183.8 million in stolen funds has been identified across six blockchain networks, including Arbitrum and BNB Chain, through thirteen linked wallets.

Attacker Maintains Open Trading Positions

An unusual detail stands out: the attacker continues to maintain open trading positions. On-chain data shows leveraged long positions worth approximately $9.75 million, including $20.5 million in ETH exposure and $10.7 million in DAI. This activity suggests either a lack of concern about being traced or confidence that the laundering pipeline is fast enough to make the risk secondary.

Bitget’s Response: Withdrawals Frozen, Protection Fund Mobilized

Bitget responded by freezing withdrawals within hours of detection. Deposits and trading remain open. The CEO confirmed that the exchange’s User Protection Fund, which held more than $464 million at the time of the breach, covers the entire loss.

« Your funds are safe. Your account balances are accurate and your assets are protected. »

Gracy Chen, CEO of Bitget

The promise to reimburse users without touching deposits has been repeated. Multiple engineering teams are working in parallel on system remediation and security hardening. No timeline for resuming withdrawals has been communicated. The protection fund fluctuated between $510 and $600 million in 2025, as it is partially held in cryptocurrencies.

Likely Attribution: North Korea and Lazarus Group

Attribution remains ongoing, but early indicators point toward North Korea. Gracy Chen stated that certain identified IP addresses match the VPN choices of a specific RDP group, using the official name for North Korea, according to remarks reported by Cointelegraph. She added that the pattern closely resembles what the North Korean team has done before. The exchange called the link highly probable without confirming it definitively.

The modus operandi fits a known pattern: Lazarus Group, the North Korean state-sponsored hacking group, has previously carried out large-scale operations. The FBI confirmed Lazarus’s involvement in the Bybit hack in February 2025, which caused $1.5 billion in losses, the largest in cryptocurrency history. DMM Bitcoin lost $308 million in 2024, and WazirX lost $234.9 million the same year. The tactic of rapid conversion into non-freezable assets and the exploitation of a backend system align with the methods attributed to this group.

Market Reaction: A Measured Decline

The market reaction was contained. Bitget’s native token BGB moved from a range of $2.02 to $2.06 on Thursday to approximately $1.963 during Friday’s Asian session, a decline of 3 to 5%. Bitcoin fell roughly 0.29% and ether approximately 0.2% within twenty-four hours of the disclosure. The broader crypto market remained up nearly 10% on the week.

This muted reaction contrasts sharply with the aftermath of the Bybit hack, when bitcoin dropped several percentage points and the entire sector wobbled. Operators appear to treat isolated exchange breaches as one-off operational failures, provided the exchange has a visible reserve to absorb the loss.

September 2026: The Year’s Most Expensive Month

September 2026 has become the most costly month of the year for cryptocurrency losses. Total thefts exceed $684 million for the month, according to a CryptoSlate tally. Bitget accounts for $351.6 million of that total. April 2026 had already been heavy, with the KelpDAO and Drift Protocol exploits totaling $577 million. Liquid Network had also lost approximately $320 million in early September 2026.

In annual comparison, this hack represents the largest single exchange breach of 2026 and ranks second all-time behind Bybit’s $1.5 billion in February 2025. The difference in methodology deserves emphasis: in Bybit’s case, attackers compromised the interface of a third-party wallet provider during a routine cold-to-hot transfer. For Bitget, the vulnerability lay in the backend logic of the withdrawal authorization system. A flaw of this type is potentially harder to defend against than key theft, as it does not require compromising hardware security modules or multisig signers.

PlatformDateAmount StolenMethod
BybitFebruary 2025$1.5 billionThird-party wallet provider
BitgetSeptember 2026$351.6 millionBackend system, spoofed transfers
DMM Bitcoin2024$308 millionPrivate keys compromised
WazirX2024$234.9 millionMultisig signature

Protection Funds as a Differentiator

This breach highlights the financial solidity and preparedness of mid-tier exchanges. Bitget ranks among the top ten global platforms by trading volume, but its security reserves are proportionally more modest than those of the largest players.

Binance’s SAFU held approximately $1 billion in February 2026, while OKX’s Risk Shield stood at roughly $700 million. Bitget’s fund, at $464 million at the time of the breach, covered this loss, but a breach even 30% larger would have depleted the majority of its reserve in a single event. The transparency and size of protection funds have become a key differentiator for users and could influence platform choices in the months ahead.


Conclusion

Bitget’s hack illustrates an emerging threat: private keys are no longer the primary target. Instead, attackers are going after backend authorization systems, bypassing the hardware security modules and multisig layers that historically protected exchanges. The mobilization of a $464 million User Protection Fund confirms Bitget’s capacity to absorb a shock of this magnitude, but the coverage window remains narrow against larger-scale attacks.

Two scenarios emerge in the weeks ahead: if the Lazarus Group attribution is confirmed, sanctions and address freezes by U.S. authorities could slow the laundering of the $183.8 million already identified. If the attacker maintains their leveraged trading activity and Tornado Cash pipeline, recovery will be considerably more complex. In either case, users should reassess their allocations based on the robustness and size of each platform’s protection fund.

Sources

This article is published for informational and educational purposes. It does not constitute investment advice in any way. Do your own research (DYOR) before making any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles