Abstract. On 24 September 2026 the cryptocurrency exchange Bitget lost $387.5 million from its hot and warm wallets in what is, at the time of writing, the largest theft of 2026 and one of the ten largest in the industry's history. No private key was stolen. According to the exchange, an attacker exploited a zero-day vulnerability in a third-party security product to obtain high-level internal credentials, entered an internal management system, and inserted fraudulent withdrawal commands into the wallet backend, where Bitget's own signing infrastructure treated them as legitimate and executed them. Two sub-threshold test transfers at 18:31 UTC were followed by seventeen large transactions across eight blockchains between 18:58 and 20:09 UTC; Bitget's reconciliation system flagged the discrepancy at 19:05, but the last confirmed outflow — 9.3 million XRP — landed at 21:19:21 UTC, a timestamp we verified directly on the XRP Ledger. This report reconstructs the theft asset by asset (XRP was 41% of it, ETH 22%, stablecoins 19%, ZEC 7%), traces the laundering through stablecoin-to-ETH swaps completed within ninety minutes, the deletion of XRP Ledger accounts, and THORChain swaps into Bitcoin that the protocol refused to block, and shows why the entire industry freeze apparatus recovered about $318,000 — 0.08% of the haul. We assess the North Korea attribution (Bitget's IP evidence, Elliptic's and TRM Labs' laundering overlaps with Bybit and AFX Bridge) as likely but not yet governmental, place the incident in the 2024–2026 lineage of "signer deception" attacks (DMM Bitcoin, WazirX, Radiant, Bybit) and in a 2026 in which suspected North Korean theft has passed $1 billion, and examine the response: a 5,500-BTC Protection Fund that absorbs the loss, a withdrawal freeze of three and a half days for Bitcoin and eight for everything else, and a promised root-cause report that, as of 29 September, has not named the vendor. All figures are frozen as of 29 September 2026.
Key findings
- The keys were never the target. The attacker obtained valid administrative credentials through a zero-day in a third-party security product, reached an internal management system, and wrote forged withdrawal commands into the wallet backend. Bitget's signing infrastructure did exactly what it was built to do — sign what the backend told it to — on fabricated input. This is the fourth major exchange loss since 2024 in which the signer was deceived rather than the key stolen.
- It was rehearsed, then executed in about seventy minutes. Two test transfers (0.184 ETH and 193 TRX) at 18:31 UTC stayed under risk-control thresholds and raised no alert. The first large transfer ($34.75 million USDT) came at 18:58; a single wave at 19:16 moved about $185 million in one minute; the CEO counts seventeen major transactions across eight chains by 20:09.
- Detection was fast; containment was not complete. Reconciliation flagged the discrepancy at 19:05 and user withdrawals were halted, yet the XRP Ledger shows a final 9,306,865.8 XRP payment to the attacker's consolidation account at 21:19:21 UTC, more than two hours later. Bitget's initial loss figure ($351.6 million) rose to $387.5 million a day later when Zcash and TRON transfers from the same window were added.
- Seventy-seven percent of the haul was in assets nobody can freeze. XRP (102.98 million, $157 million), ETH, ZEC, TRX, BNB and AVAX are native assets without an issuer. The freezable 23% — USDT, USDC, USDT0 and Tether Gold, about $88 million — was swapped into ETH within ninety minutes, with the attacker overpaying by up to 5% for speed. Circle and Tether froze 99,990 USDC and 218,023 USDT: roughly $318,000, or 0.08% of the theft.
- The XRP Ledger was the attacker's best friend. Ripple can freeze tokens issued on the ledger but
not XRP itself. The 103 million XRP were split into five accounts, moved through cross-chain swap services and
THORChain toward Bitcoin over 26–27 September, and at least one account was then deleted from the
ledger (an
AccountDeleteat 14:14:30 UTC on 26 September, verified). THORChain declined Bitget's request to refuse the addresses, calling a selective freeze incompatible with its design. - North Korea is the likely author, on the evidence available; no government has said so yet. Bitget cites IP patterns matching a DPRK group's VPN choices; Elliptic ties the stolen XRP to ETH from an earlier DPRK-attributed theft and to Bybit laundering addresses; TRM Labs says the laundering network involved has only ever been seen working for TraderTraitor. The FBI named TraderTraitor for Bybit within six days; as of 29 September it has not spoken on Bitget.
- The exchange survived because it had pre-funded the loss. A 5,500-BTC User Protection Fund (~$464 million on the day) covers the $387.5 million; Bitget says it will restore the fund to at least $300 million within a week from corporate reserves above $1.4 billion. BGB fell about 4% and recovered. The cost that is not yet counted is the eight-day withdrawal freeze — something Bybit, with a loss four times larger, never imposed.
1. Background: the exchange, and the year it happened in
Bitget was founded in 2018 in Singapore, moved its headquarters to the Seychelles in December 2022, and has been run since 2024 by CEO Gracy Chen. It is one of the larger derivatives-first exchanges, with a native token (BGB) that since 2025 also serves as the gas token of the Morph chain. Two facts from its record matter for what follows. It had never had a security incident: its head of Greater China called this "the platform's first security crisis in its 8-year history". And it had spent that time building the visible apparatus of solvency — 45 consecutive monthly proof-of-reserves reports since December 2022, the latest (August 2026) showing a 122% reserve ratio, and a User Protection Fund established in 2022 and held as 5,500 BTC in publicly listed addresses, valued at an average of $382 million over August and at about $464 million on the day of the attack. Bitget describes its custody as a three-tier architecture: hot wallets for withdrawals, warm wallets that refill them, and cold storage for the bulk of assets.
The year matters as much as the exchange. 2025 had ended with the industry's worst theft on record — Bybit, 21 February 2025, about 400,000 ETH ($1.4–1.5 billion), executed by manipulating what the exchange's signers saw through a compromised Safe{Wallet} developer environment, and attributed by the FBI within six days to North Korea's TraderTraitor unit — and with Chainalysis counting $3.4 billion stolen in the year, $2.02 billion of it by DPRK actors. 2026 continued the pattern with a shift in target: away from smart-contract bugs and toward the institutions' plumbing. Drift Protocol lost $285 million on 1 April to a months-long social-engineering campaign against its security council; Kelp DAO lost $292 million on 18 April when a single LayerZero verifier node was compromised; AFX Bridge lost $24 million on 22 July to a fake recruiter targeting a developer; Coldcard hardware-wallet users lost 1,600–2,100 BTC to a firmware entropy flaw (our report); and on 6–7 September the Liquid Network saw 4,000 unbacked L-BTC (~$320 million) minted through an Elements bug, most of it later returned by self-described whitehats. Elliptic counts more than 51 DPRK-linked incidents in 2026 before Bitget; with Bitget, its tally of suspected North Korean theft for the year passes $1 billion.
2. Anatomy of the theft: the evening of 24 September, on-chain
Bitget's public statements give the skeleton; the chains give the flesh. The CEO's account, published on 28 September, is that the attacker first sent two small transfers at 18:31 UTC — 0.184 ETH from the Ethereum hot wallet and 193 TRX from the TRON hot wallet — both below risk-control thresholds, both silent. We can add a detail from the TRON chain: the attacker's TRX receiving address was created at 18:30:57 UTC, thirty-four seconds before Bitget's stated detection time, which tells us the "detection" in the first notice refers to the test transfers themselves, not to an alarm. The large transfers began at 18:58 with $34.75 million in USDT. Between then and 20:09 the CEO counts seventeen major transactions across eight blockchains totalling about $361 million. The heaviest single minute was 19:16, when about $185 million moved at once: 13,966 ETH on Ethereum, roughly 91.4 million XRP on the XRP Ledger and 20.6 million TRX on TRON.
The XRP Ledger, which is public and fast to query, lets us verify the XRP leg exactly. The attacker's consolidation account received three payments from Bitget accounts: 2,248,871.54 XRP at 19:01:32 UTC, 91,420,942.76 XRP at 19:16:20 UTC, and 9,306,865.80 XRP at 21:19:21 UTC — a total of 102,976,680 XRP, matching the "nearly 103 million" figure in press coverage. The third payment is the one that should trouble Bitget's incident reviewers: it landed two hours and fourteen minutes after the reconciliation system flagged the discrepancy at 19:05 and user withdrawals were blocked. Blocking user withdrawals does not stop forged internal commands; whatever the attacker's foothold was, it was still able to instruct a warm wallet at 21:19. Bitget's first public notice went out at about 21:30.
What was taken is known only approximately, because Bitget has not published a breakdown. The reconstruction below combines the analyses of Elliptic, TRM Labs and independent researchers and reconciles them against Bitget's two official totals: $351.6 million on 24 September, revised to $387.5 million at 14:05 UTC on 25 September "adding affected assets on Zcash and TRON". The TRON leg is well documented at 20.59 million TRX (~$7.07 million); the difference of $35.9 million between the two totals therefore implies about $28.8 million in ZEC, which at that day's price is about 18,700 ZEC — and 18,669.98 ZEC is exactly what the attacker's transparent Zcash address held when we queried it. Readers of our Zcash report will note the irony: the one asset in the haul with a shielded pool is still sitting, unshielded, on a public address five days later.
| Asset (chain) | Amount | Approx. USD | Share | Can an issuer freeze it? |
|---|---|---|---|---|
| XRP (XRP Ledger) | 102,976,680 | $157.5 M | 40.6% | No — native asset |
| ETH (Ethereum, L2s) | 31,890 | $85.8 M | 22.1% | No |
| ZEC (Zcash, transparent) | ~18,670 | ~$28.8 M | 7.4% | No (derived figure, see text) |
| USDT (Ethereum, TRON, BSC) | 34.75 M | $34.8 M | 9.0% | Yes — Tether |
| USDC (Ethereum, L2s) | 21.05 M | $21.1 M | 5.4% | Yes — Circle |
| USDT0 (Arbitrum) | 19.67 M | $19.7 M | 5.1% | Yes — swapped to ETH in 6 min |
| XAUt, Tether Gold | 3,000 | $12.8 M | 3.3% | Yes — Tether |
| BNB (BNB Chain) | 12,719 | $9.9 M | 2.5% | No |
| AVAX (Avalanche) | 821,012 | $8.4 M | 2.2% | No |
| TRX (TRON) | 20.59 M | $7.1 M | 1.8% | No |
3. The attack: valid credentials, forged commands, an obedient signer
Bitget's technical account has arrived in layers, each one more specific. The first notice (24 September) spoke of "unauthorized transfers from some of our hot wallets". The technical update of 00:43 UTC on 25 September ruled out private-key compromise: "The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out." By 28 September the CEO had named the entry point in kind if not in name: a zero-day vulnerability in a third-party security product used by Bitget, through which the attacker obtained "high-level internal credentials", reached an internal management system, and "inserted fraudulent withdrawal commands directly into wallet-related backend systems, causing them to be treated as legitimate". The attacker "used legitimate credentials", "disguised their activity as routine administrative operations while removing traces of their actions" — trace deletion, Chen said, was "the trickiest part". Bitget's remediation list confirms the shape: it notified the vendor, isolated the affected systems, revoked and reissued internal credentials, and switched off the affected functionality.
Put mechanically: an exchange's withdrawal pipeline is a chain of trust — a request is created, checked against risk rules (limits, whitelists, velocity), approved, handed to a signing service that holds the keys (an HSM or an MPC cluster), signed and broadcast. Every link trusts the link before it. The attacker did not break the last link; they wrote themselves into the middle with credentials the system recognised as its own, and the test transfers at 18:31 established which risk rules would fire. GoPlus lists the plausible mechanics — database tampering, forged internal service calls, message-queue injection, a swapped withdrawal-address map — and notes that none is confirmed; Bitget's root-cause report, promised for the week of 28 September, is the only thing that will settle it.
The distinction Bitget keeps drawing — "not a private-key leak" — is accurate and, for the victims of the last two years, increasingly familiar. At DMM Bitcoin (May 2024) and Bybit (February 2025) the attackers compromised a wallet vendor (Ginco, Safe{Wallet}) and altered what the exchange's human signers saw, so that people approved transactions they did not understand. At WazirX (July 2024) the multisig interface showed a benign transaction while the signers signed a malicious one. At Bitget there was no human in the loop to deceive: the forged data went into an automated pipeline and the machine signed. That is a step further down the same road, and the third-party component this time was not a wallet product but a security product — the tool meant to watch the perimeter became the door.
| Incident | Date | Loss | Where the deception happened | Third party involved |
|---|---|---|---|---|
| DMM Bitcoin | 31 May 2024 | ~$305 M (4,502 BTC) | Vendor's engineer compromised; transaction altered before signing | Ginco (wallet software) |
| WazirX | 18 Jul 2024 | ~$235 M | Signers approved a multisig transaction whose displayed payload had been changed | Liminal (custody interface) |
| Radiant Capital | 16 Oct 2024 | ~$50 M | Signers blind-signed malicious calls after malware on a developer device | — |
| Bybit | 21 Feb 2025 | ~$1.46 B | Safe{Wallet} front-end served a masked transaction to cold-wallet signers | Safe{Wallet} (developer machine) |
| Bitget | 24 Sep 2026 | $387.5 M | Forged withdrawal commands in the backend; automated signer executed them | Unnamed security product (zero-day) |
4. The response: pre-funded loss, phased reopening, a report still to come
Bitget's crisis communication followed a script the industry has learned from Bybit, with one large difference. The CEO's notice at ~21:30 UTC said user funds were safe and account balances accurate, that cold wallets were untouched, that deposits and trading continued, and that withdrawals were paused "out of an abundance of caution" — and it named the number that mattered: a User Protection Fund holding "over $464 million", enough to absorb the $351.6 million then known. Within twelve hours the technical update had ruled out key theft; by 07:10 UTC Mandiant (Google) and SlowMist were named as investigators; at 14:05 UTC on 25 September the loss was revised to $387.5 million and Bitget published the attacker addresses, an on-chain tracker and two bounties: 5% of any funds frozen through a party's direct efforts, and 5% of any recovered, excluding actions taken under court order or by law enforcement. On 26 September it published the reopening schedule; on 28 September it added the mechanism (the third-party zero-day, the test transfers) and the containment measures (restricted internal access, independent verification of withdrawals, heavier monitoring).
| Phase | Date (08:00 UTC) | Assets | Time since halt |
|---|---|---|---|
| 1 | 28 Sep 2026 | BTC on Bitcoin and BSC | 3 d 13 h |
| 2 | 29 Sep 2026 | ETH on Ethereum, BSC, Arbitrum, Base, Optimism | 4 d 13 h |
| 3 | 30 Sep 2026 | USDT on Ethereum, BSC, Solana, TRON | 5 d 13 h |
| 4 | 2 Oct 2026 | All remaining tokens, fiat withdrawals, P2P | 7 d 13 h |
The difference from Bybit is the freeze. Bybit lost four times as much and never stopped withdrawals; it processed a run of several billion dollars over the following days and replenished its ETH within 72 hours through loans from Galaxy Digital, FalconX and Wintermute. Bitget, whose loss was fully covered on paper from the first hour, nonetheless closed withdrawals for three and a half days for Bitcoin and eight days for everything else. The stated reason — a security review of a compromised backend whose foothold was still active at 21:19 on the first evening — is a good one; an exchange that cannot yet prove its withdrawal pipeline is clean should not run it. But the cost is real and not yet measured: users who could not move funds, market makers who could not rebalance, and a reputational ledger on which "first incident in eight years" and "eight-day freeze" now sit side by side.
The financial cushion held. The Protection Fund is 5,500 BTC in public addresses — about $464–465 million on 24–25 September, against an August average of $382 million — and Bitget says the loss is covered from it "after assessment", with the fund to be restored to a floor of $300 million within a week from corporate reserves it puts above $1.4 billion. The market took the exchange at its word: BGB closed 24 September at $2.04, dipped to $1.96 on the 25th (about 4% down, against a 2.9% intraday move reported at the time) and was back near $1.98–2.02 by the 27th; Bitcoin moved less than half a percent. That is the Bybit precedent working as designed — a large, visible, pre-funded reserve converts a solvency question into a liquidity inconvenience — and it is also why the exchanges without one should read this report twice.
5. Laundering and recovery: why 0.08% came back
The attacker's first hours followed the TraderTraitor playbook that Bybit made famous, adapted to this haul's composition. Anything an issuer could freeze was converted first. Of roughly $88 million in freezable assets — USDT, USDC, USDT0 and Tether Gold — about $80 million was swapped into ETH within ninety minutes of the first large transfer, on decentralised exchanges, at prices up to 5% worse than market: speed was worth more than the slippage. The USDT0 on Arbitrum became 7,111 ETH in six minutes and was bridged to Ethereum. TRM Labs puts the post-conversion position at about $100 million of newly acquired ETH on top of $85 million taken as ETH, with $157.5 million in XRP and $7 million in TRX unconverted. The ETH was then parked in round-number tranches — two wallets of 10,000 ETH each, one of ~4,596 ETH — and left alone for two and a half days before disbursement began on 27 September in 25–300 ETH pieces.
The freeze apparatus arrived on schedule and found almost nothing to freeze. At 05:00 UTC on 25 September Circle blacklisted an address Etherscan labels "Bitget Exploiter 8"; Tether followed. Between them they immobilised 99,990 USDC and 218,023 USDT — about $318,000, 0.36% of the freezable value and 0.08% of the theft. Circle was faster than in April, when critics including ZachXBT said it let $232 million of Drift's USDC cross to Ethereum over six hours; the speed did not matter, because the attacker had already been faster. The lesson generalises: issuer freezes work against slow thieves and against thieves who hold stablecoins. This thief was neither.
The XRP leg is the case study in unfreezability. The XRP Ledger lets issuers freeze the tokens they issue; that
power does not extend to XRP itself, and Ripple has no lever over it. The 102.98 million XRP were split into five
accounts (four of 20 million, one of ~23 million), seeded with "dust" payments, and from 26 September
moved through the Bridgers cross-chain swap service and THORChain with Bitcoin destinations. By 12:41 UTC on
26 September two of the 20-million accounts held 23 and 55 XRP; by the 27th the rest had followed. At
14:14:30 UTC on 26 September one of the five accounts was removed from the ledger with an
AccountDelete transaction, its reserve sent onward — we verified this directly. When we queried
the ledger on 29 September the consolidation account held 3.09 XRP and the four surviving split accounts
between 1.3 and 22.8 XRP. GoPlus estimated on the 28th that about $8.5 million in Bitcoin had exited
through THORChain with a further $43 million of XRP mid-swap.
THORChain became the flashpoint. Bitget formally asked the protocol to refuse service to the attacker addresses; Chen wrote that "decentralization is a design principle, not a shield for facilitating known stolen funds". THORChain declined, saying it can halt the whole network in an emergency but that "a halt is not a selective freeze of specific funds or an individual swap", and that it is permissionless in the same sense as the chains it connects. On the morning of 28 September, between 03:55 and 06:23 UTC, an attacker wallet completed 27 swaps of roughly 100 ETH each, converting about 2,390 ETH ($6.3 million) into 75.2 BTC. The Bitcoin side then entered Wasabi CoinJoin, where AMLBot traced about 4 BTC on 26 September. Bitget's tracker lists roughly a thousand Bitcoin addresses. On 28 September ZachXBT — who had said three days earlier he had no plans to work the case for an exchange that does not support his work — published five aliases he describes as Chinese over-the-counter launderers acting "on behalf of the alleged DPRK attackers", one of them previously seen laundering Kelp DAO proceeds.
| Asset | Stolen | Status at 29 Sep 2026 (our check unless noted) | Freezable |
|---|---|---|---|
| XRP | 102.98 M | Consolidation account 3.09 XRP; split accounts 1.3–22.8 XRP; one account deleted 26 Sep. Routed via Bridgers/THORChain to BTC | No |
| ETH (incl. swapped) | ~68,000 after swaps | One 10,000-ETH wallet emptied; another still holds 7,560 ETH (241 txs); the ~4,596-ETH wallet emptied; 2,390 ETH swapped to 75.2 BTC on THORChain 28 Sep | No |
| ZEC | ~18,670 | 18,669.98 ZEC still on the transparent address, cycled through ~9 self-transfers, last on 27 Sep 06:47 UTC; not shielded | No |
| TRX | 20.59 M | Receiving address emptied (0.40 TRX left, 54 txs) | No |
| USDT / USDC / USDT0 | $75.5 M | ~$80 M of all freezable assets swapped to ETH within 90 min; 218,023 USDT + 99,990 USDC frozen | Yes |
| XAUt | 3,000 | Included in the freezable pool; no freeze reported | Yes |
| BNB / AVAX | $18.3 M | Cross-chained to Ethereum early (Elliptic); no freeze possible | No |
6. Attribution: North Korea, likely; official, not yet
Bitget was careful and then less so. Its 25 September update said that "based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations", and the CEO added that investigators had identified IP addresses matching the VPN choices of a particular DPRK group, while declining to "formally speculate until the investigation is complete". By 28 September she was saying "it's still the same group of people that we suspect" and leaving the name to the forthcoming report. The independent evidence points the same way and is of the usual kind — behavioural and network-based, not forensic. Elliptic (25 September) reports connections between XRP from the Bitget exploit and ETH from a previous DPRK-attributed exploit, and between Bitget proceeds and addresses used to launder Bybit in 2025; it notes the laundering methodology — rapid conversion out of stablecoins into each chain's native asset, prompt cross-chaining of Arbitrum assets to Ethereum — matches prior DPRK operations. TRM Labs reports "multiple on-chain overlaps" with wallets used to launder Bybit and AFX Bridge, and says the laundering network involved has "not [been] seen working for any group other than TraderTraitor", while allowing that another actor carrying out the theft "remains technically possible".
| Evidence | Source | What it shows | What it does not show |
|---|---|---|---|
| IP addresses matching a DPRK group's VPN patterns | Bitget (CEO) | Network infrastructure overlap with a known actor | Who sat at the keyboard; VPN exits are shared |
| Stolen XRP linked to ETH from an earlier DPRK-attributed theft | Elliptic | Shared wallets or counterparties across incidents | Whether the link is the thief or a launderer both use |
| Bitget proceeds touch Bybit laundering addresses | Elliptic, TRM Labs | Same laundering network as Bybit (attributed by the FBI) | Laundering-for-hire networks serve more than one client |
| Laundering network exclusive to TraderTraitor to date | TRM Labs | Strong prior for the same operator | Exclusivity is an observation, not a guarantee |
| Method: rapid native-asset conversion, round tranches, THORChain to BTC | Elliptic, TRM Labs, GoPlus | Consistent with Bybit, Drift, AFX playbooks | Playbooks are copyable |
| Initial access via third-party vendor credentials | Bitget | Consistent with DMM, Bybit, AFX vector | Vendor and exploit unnamed; no malware/infrastructure overlap published |
| Government statement | — | None as of 29 Sep 2026 | FBI named TraderTraitor for Bybit in six days |
The pattern across 2026 is worth stating plainly, because it is the strategic context in which Bitget was hit. Chainalysis counted DPRK theft at $2.02 billion in 2025, 76% of all losses from compromised services, and warned that the challenge for 2026 was preventing "another Bybit-scale incident". Through April 2026, two attacks — Drift and Kelp DAO, $577 million between them — gave North Korea 76% of everything stolen in the year; AFX Bridge in July added $24 million via a fake recruiter; Bitget adds $387.5 million and takes the year's suspected DPRK total past $1 billion. Every one of those targets was reached through people and infrastructure — a security council, a verifier node, a developer, a vendor's security product — and not through a bug in a smart contract. The unit's comparative advantage is patience and access, and the exchanges' weakest surface is whatever they bought rather than built.
7. Discussion: three things this incident settles
First, "no private key was stolen" is true and beside the point. A key is only as good as the data it signs. In a pipeline that trusts its own backend, an attacker with backend credentials is the key holder in every sense that matters. The defensive consequence is unglamorous: the signer must be able to verify intent independently of the system that asks it to sign — reconstruct the withdrawal from a ledger of record it trusts, refuse mismatches, enforce destination whitelists, velocity caps and a human quorum inside the signing cluster rather than upstream of it. Bitget's post-incident "independent withdrawal verification" is a version of this. It is notable that the industry has now needed DMM, WazirX, Bybit and Bitget to converge on the principle.
Second, the vendor is tier zero. The compromised component was a security product — a category exchanges buy precisely so that they do not have to think about it. Bybit's lesson (a wallet vendor's developer laptop) was widely read as "audit your wallet provider". Bitget's is broader: any third-party software with credentials that can reach the wallet backend belongs in the same isolation, identity and change-control regime as the signer itself, and its vulnerability disclosures are your incident. Bitget says it will "comprehensively upgrade its monitoring and management standards for third-party components"; the whole industry's vendors should expect the same questionnaire.
Third, freezes are a rounding error against a competent adversary. Seventy-seven percent of this haul was structurally unfreezable, and the 23% that was not had been converted before any issuer acted. The $318,000 frozen is not a failure of Circle or Tether — they acted within eleven hours, faster than in April — it is a measurement of what issuer blacklists can do against an attacker who plans for them. The remaining policy levers are all upstream: exchanges that refuse tainted deposits, cross-chain protocols that can (or, like THORChain, will not) intervene, and the over-the-counter desks that ZachXBT is naming one alias at a time. Ripple's inability to freeze XRP, and THORChain's refusal to, are not bugs in those systems; they are the price of what those systems are, and Bitget is the second large exchange in two years to discover it at scale.
8. Limitations and open questions
- The vendor and the exploit are unnamed. Bitget's root-cause report, promised for the week of 28 September, had not been published when this report was compiled. Everything in §3 about mechanism is Bitget's characterisation or reasoned inference, and is labelled as such.
- The breakdown is reconstructed. Bitget has published two totals and four addresses, not a per-asset list. Our table reconciles to within ~$1.5 million of $387.5 million; the ZEC figure is derived from the difference between the two official totals and confirmed only by the address balance.
- Timelines disagree at the edges. Bitget's notice puts "detection" at 18:31, the CEO puts the reconciliation alert at 19:05, and the chain shows outflows until 21:19. We report all three and treat the last as the most important unanswered question for Bitget's reviewers.
- Our on-chain checks are snapshots taken on 29 September at about 02:50 UTC. Balances in the ETH and ZEC wallets will move; the XRPL deletions will not.
- Attribution is probabilistic and rests on laundering overlaps and infrastructure patterns. We have seen no published malware or infrastructure forensics.
- Recovery is undisclosed. Bitget says some assets beyond the $318,000 were frozen with industry help, without a figure. Bounty outcomes, the trace of the ZEC, and any exchange-side freezes of BTC exits are revision triggers.
- Loss figures vary by outlet ($387.5 million official; $388 million rounded; $390 million in one report). We use Bitget's.
Frequently asked questions
What happened in the Bitget hack of September 2026?
On 24 September 2026, starting at 18:31 UTC, an attacker used valid internal credentials obtained through a zero-day in a third-party security product to insert forged withdrawal commands into Bitget's wallet backend. Bitget's own signing system executed them, draining about $387.5 million from hot and warm wallets across nine blockchains in roughly two hours. Cold wallets were untouched and no private key was stolen.
How much was stolen from Bitget?
Bitget's official figure is $387.5 million, revised on 25 September from an initial $351.6 million after Zcash and TRON transfers from the same window were added. About 41% was XRP (102.98 million), 22% ETH, 19% stablecoins, 7% ZEC, plus Tether Gold, BNB, AVAX and TRX.
Are user funds on Bitget safe after the hack?
Bitget says account balances are unaffected and that its User Protection Fund, held as 5,500 BTC (about $464 million on the day), covers the full loss. Withdrawals were paused from 24 September and reopened in phases: BTC on 28 September, ETH on 29 September, USDT on 30 September and all other assets, fiat and P2P on 2 October.
Were Bitget's private keys stolen?
No, according to Bitget and every independent analysis published so far. The attacker spoofed the transaction data fed to the authorisation and signing process, so legitimate keys signed illegitimate transfers. This is the same class of attack as Bybit (2025), WazirX and DMM Bitcoin (2024), with the difference that at Bitget no human approver was in the loop.
Who was behind the Bitget hack?
Bitget says IP patterns and on-chain behaviour are highly consistent with North Korean groups. Elliptic and TRM Labs link the stolen funds to wallets used to launder the Bybit and AFX Bridge thefts, and TRM says that laundering network has only worked for TraderTraitor. As of 29 September 2026 no government has formally attributed the attack.
Has any of the stolen money been recovered?
Circle and Tether froze about 99,990 USDC and 218,023 USDT, roughly $318,000, or 0.08% of the theft. Bitget says some further assets were frozen with industry help but has not given a figure. Most of the haul was in XRP, ETH, ZEC and TRX, which no issuer can freeze, and the freezable stablecoins were swapped into ETH within ninety minutes.
Why couldn't Ripple freeze the stolen XRP?
The XRP Ledger lets issuers freeze tokens they issue on the ledger, but that power does not extend to XRP itself. The attacker split 102.98 million XRP across five accounts, moved it through cross-chain swap services and THORChain into Bitcoin, and deleted at least one account from the ledger afterwards.
How does the Bitget hack compare with the Bybit hack?
Bybit lost about $1.46 billion in February 2025, nearly four times more, through a compromised Safe{Wallet} developer environment that masked what its signers approved; Bybit never paused withdrawals and replenished reserves within 72 hours. Bitget lost $387.5 million through forged backend commands executed by an automated signer, covered it from a pre-funded Protection Fund, but paused withdrawals for three and a half to eight days.
What is Bitget's User Protection Fund?
A reserve Bitget established in 2022 and holds as 5,500 BTC in publicly listed addresses, valued at an August 2026 average of $382 million and about $464 million on 24 September. Bitget says the hack loss is covered from it and that it will restore the fund to at least $300 million within a week from corporate reserves above $1.4 billion.
Methodology and data sources
Compiled 29 September 2026. Official facts (times, totals, mechanism, remediation, schedule, bounty terms,
attacker addresses) from Bitget's support-centre notices of 24, 25 and 26 September and from CEO Gracy Chen's
statements as reported by CoinDesk, The Block, Cointelegraph and The Hacker News on 25–28 September,
cross-checked across at least two outlets. On-chain reconstruction from Elliptic's and TRM Labs' published
analyses, the GoPlus and CTI Academy write-ups and Halborn's explainer, reconciled against Bitget's totals. Our own
verification: XRP Ledger account_info and account_tx calls against the public JSON-RPC at
s1.ripple.com for the six attacker accounts (balances, inbound payments with ledger timestamps, the
AccountDelete); eth_getBalance and eth_getTransactionCount against a public
Ethereum RPC for four attacker addresses; Blockchair's Zcash address API for the transparent ZEC address; the
TRONSCAN account API for the TRX address. All made 29 September at about 02:50 UTC. Prices from CoinGecko
daily closes (BGB, BTC, ZEC, XRP). Historical comparisons (DMM Bitcoin, WazirX, Radiant, Bybit) from the public
record as of their dates. Statements about intent, attribution and future behaviour are analysis and are worded as
such.
References
- Bitget Support — Withdrawal Service Update, 24 September 2026 (phased resumption schedule) — https://www.bitget.com/support/articles/12560603896025
- Bitget Support — Security incident update: fund tracing and recovery bounty program (25 Sep 2026, 14:05 UTC) — https://www.bitget.com/support/articles/12560603896108
- Gracy Chen (Bitget CEO) on X — Security notice: Bitget hot wallet incident, 24 September 2026 — https://x.com/GracyBitget/status/2103235655879074084
- Bitget — Attacker fund tracker (addresses and flows) — https://trace.bgblockchain.xyz/v2#explorer
- CoinDesk — Crypto exchange Bitget says $352 million affected in a hack, claims user funds are safe (24 Sep 2026) — https://www.coindesk.com/markets/2026/09/24/crypto-exchange-bitget-loses-usd352-million-in-hack-claims-user-funds-are-safe
- CoinDesk — Bitget's hack happened via spoofed transfers, not private keys, CEO Gracy Chen says (25 Sep 2026) — https://www.coindesk.com/markets/2026/09/25/bitget-s-usd351-million-hack-happened-via-spoofed-transfers-not-private-keys-ceo-gray-chen-says
- CoinDesk — Circle and Tether step in to freeze hacker wallet after massive Bitget crypto heist (25 Sep 2026) — https://www.coindesk.com/markets/2026/09/25/circle-and-tether-step-in-to-freeze-hacker-wallet-after-massive-bitget-crypto-heist
- CoinDesk — Bitget hacker moves $83 million in stolen XRP beyond reach of freeze controls (26 Sep 2026) — https://www.coindesk.com/markets/2026/09/26/bitget-hacker-moves-usd83-million-in-stolen-xrp-that-ripple-cannot-freeze
- CoinDesk — THORChain rejects Bitget request to block hacker as $6 million moves to bitcoin (28 Sep 2026) — https://www.coindesk.com/tech/2026/09/28/thorchain-rejects-bitget-request-to-block-hacker-as-usd6-million-moves-to-bitcoin
- The Block — Bitget starts phased withdrawal resumption following $388 million exploit (28 Sep 2026) — https://www.theblock.co/news/business/2026-09-28-bitget-starts-phased-withdrawal-resumption-416965
- The Block — Bitget attacker tested risk controls with small transfers before $388 million theft, CEO says (28 Sep 2026) — https://www.theblock.co/news/regulation/2026-09-28-bitget-attacker-tested-risk-controls-small-transfers-388-million-theft-ceo-says-417045
- The Hacker News — Bitget says suspected North Korean hackers stole $351.6M after backend compromise — https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html
- The Hacker News — Bitget says attacker exploited third-party security product flaw to steal $388M — https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html
- Cointelegraph — Bitget reveals new details of $388M crypto hack (third-party security vulnerability) — https://cointelegraph.com/news/bitget-388m-hack-third-party-security-vulnerability
- Elliptic — Bitget attack pushes suspected North Korea crypto heists over $1 billion in 2026 (25 Sep 2026) — https://www.elliptic.co/insights/bitget-attack-pushes-suspected-north-korea-crypto-heists-over-1-billion-in-2026/
- TRM Labs — Bitget loses USD 351.6 million in hot wallet breach in likely North Korea attack — https://www.trmlabs.com/resources/blog/bitget-loses-usd-3516-million-in-hot-wallet-breach-in-likely-north-korea-attack
- Halborn — Explained: the Bitget hack (September 2026) — https://www.halborn.com/blog/post/explained-the-bitget-hack-september-2026
- CTI Academy — Bitget hack: how suspected Lazarus hackers took $387.5M (timeline, addresses, ATT&CK mapping) — https://ctiacademy.io/blog/bitget-hack-lazarus-group
- The Crypto Times — Bitget $387.5M hack: how attackers moved $185M in one minute without stealing private keys — https://www.cryptotimes.io/2026/09/28/bitget-387-5m-hack-how-attackers-moved-185m-in-one-minute-without-stealing-private-keys/
- The Crypto Times — ZachXBT exposes 5 launderers moving $387.5M Bitget hack funds for North Korea (28 Sep 2026) — https://www.cryptotimes.io/2026/09/28/zachxbt-exposes-5-launderers-moving-387-5m-bitget-hack-funds-for-north-korea/
- Fortune — North Korea accused of plundering Bitget for $387 million in year's biggest crypto attack (25 Sep 2026) — https://fortune.com/2026/09/25/north-korea-bitget-387-million-crypto-attack/
- PANews — Xie Jiayin responds to Bitget's first security incident in 8 years — https://panews.io/articles/01a0e721-ef79-7652-a133-20ca92ae5e9a
- Chainwire — Bitget publishes 45th consecutive monthly proof-of-reserves report at 122% reserve ratio (16 Sep 2026) — https://chainwire.org/2026/09/16/bitget-publishes-45th-consecutive-monthly-proof-of-reserves-report-at-122-reserve-ratio/
- Chainalysis — 2025 crypto theft reaches $3.4 billion; DPRK $2.02 billion (18 Dec 2025) — https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/
- Elliptic — Drift Protocol exploited for $286 million in suspected DPRK-linked attack (April 2026) — https://www.elliptic.co/insights/drift-protocol-exploited-for-286-million-in-suspected-dprk-linked-attack/
- CoinDesk — Kelp DAO exploited for $292 million with wrapped ether stranded across 20 chains (19 Apr 2026) — https://www.coindesk.com/tech/2026/04/19/2026-s-biggest-crypto-exploit-kelp-dao-hit-for-usd292-million-with-wrapped-ether-stranded-across-20-chains
- crypto.news — AFX schedules Aug. 3 goodwill plan following $24.15M bridge hack (TraderTraitor) — https://crypto.news/afx-schedules-aug-3-goodwill-plan-following-24-15m-bridge-hack/
- CoinDesk — $320 million bitcoin exploit hits Liquid Network; hacker makes conditional offer (7 Sep 2026) — https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys
- Wikipedia — Bybit (February 2025 hack: ~400,000 ETH, Safe{Wallet}, FBI attribution to TraderTraitor) — https://en.wikipedia.org/wiki/Bybit
- XRP Ledger — attacker consolidation account rwNhefsz1UQEusxhCvHip3RANinWi4CTck (public explorer) — https://xrpscan.com/account/rwNhefsz1UQEusxhCvHip3RANinWi4CTck
- Etherscan — Bitget Exploiter 1, 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee — https://etherscan.io/address/0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee
- Blockchair — attacker Zcash transparent address t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG — https://blockchair.com/zcash/address/t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG
Revision history
First publication, five days after the incident. Figures and on-chain balances as of 29 September 2026 ~02:50 UTC. Revision triggers: Bitget's root-cause report and the vendor's name; any government attribution; disclosed recovery or freeze totals; movement of the 18,670 ZEC or the remaining ETH; completion of the withdrawal reopening on 2 October.
Disclaimer. This research is published for information and education. It is not financial advice, not a recommendation to use or avoid any exchange, and not a recommendation to buy, sell or hold any asset. Santala Research holds no position in BGB and has no relationship with Bitget. Figures are snapshots at the dates stated and will change.