Bitget has confirmed that attackers stole $387.5 million from its exchange wallets on September 24. Withdrawals still remain suspended, while the company says its protection fund covers the loss.
Mandiant and SlowMist are investigating. CEO Gracy Chen suspects North Korean involvement, although the initial entry point remains undisclosed.
So, how did the hack potentially take place? BeInCrypto has structured a timeline based on publicly available info.
September 24, 18:31 UTC: Bitget Detects Unauthorized Transfers
Bitget says its security systems detected the transfers at 18:31 UTC and activated emergency procedures within minutes.
The breach affected parts of its hot and warm wallets, which support exchange operations. Its offline cold wallets remained secure, according to the company. The detection time does not establish when attackers first gained access.
19:57–21:06 UTC: Unusual Trades Raise the Alarm
At 19:57, analyst DCF GOD flagged a fresh wallet spending $19.67 million in USDT0 to buy 7,111 ETH in six minutes. It reportedly paid up to 5% above market prices.
The behaviour suggested someone prioritized moving funds quickly. Their motive was still unclear.
By 21:06, Bubblemaps reported roughly $180 million moving from Bitget wallets to a common receiving address, then splitting into several wallets.
21:30 UTC: Chen Confirms the Breach
Chen’s security notice put the initial loss at $351.6 million and confirmed that withdrawals were paused.
The notice came almost three hours after Bitget’s stated detection time. That gap leaves questions about its response, but does not prove funds kept leaving throughout that period.
September 25, 00:43 UTC: The Suspected Method Emerges
Chen said attackers compromised a critical backend system, meaning software that manages wallet operations behind the scenes.
They supplied false transaction data and triggered Bitget’s authorization process. In simple terms, its own system approved fraudulent transfers.
Chen said private-key theft had been ruled out. How attackers entered the backend, and which checks failed, still requires a detailed public explanation.
14:03 UTC: The Loss Reaches $387.5 Million
Bitget revised its estimate after including affected Zcash and TRON assets. It said the increase reflected a fuller accounting of the original theft.
The company says the vulnerability has been fixed. It promised a withdrawal-plan announcement by September 26 at 04:00 UTC, without committing to reopening withdrawals then.
Why Investigators Suspect North Korean Involvement
Chen cited IP behaviour and blockchain activity consistent with North Korean groups. Several features resemble the February 2025 Bybit theft, which the FBI attributed to North Korea.
- Manipulated approvals: Bitget describes false instructions reaching its authorization system. At Bybit, a compromised interface tricked signers into approving a malicious transaction. The mechanisms differ, but both exploited the approval process.
- Rapid asset conversion: Bitget-linked funds quickly bought ETH. The FBI documented rapid conversion of Bybit’s stolen assets into other cryptocurrencies.
- Splitting funds across wallets: Bubblemaps identified several receiving wallets. Bybit’s proceeds spread across thousands of addresses, according to the FBI.
- Using THORChain: MistTrack reported Bitget proceeds entering the protocol and identified its earlier use to move stolen Bybit funds.
These parallels support further investigation. They do not independently identify Bitget’s attackers.
Source: BeInCrypto