BLOCKCHAIN AI.NEWS

Security

Bitget's Own Approval System Signed Off on $387.5 Million

The exchange says nobody stole a private key. Someone got inside a backend system in its wallet infrastructure, fed it false transfer data, and let Bitget's authorization process move the money. The loss figure has risen twice in a day.

Editorial illustration: a sealed chrome vault door stays shut while a glowing gold approval stamp presses on glass slips streaming out through a side hatch
✓ Outflows flagged on-chain by DCF GOD and Arkham analyst Emmett Gallic, first reported by Decrypt and CoinDesk on Sep 24 · Confirmed in Bitget's security notice · Attack route per CEO Gracy Chen, via CoinDesk and Bloomingbit · Revised tally and bounty terms via Fortune, PANews and The Crypto Times

At 18:31 UTC on September 24, according to Bitget's security notice, the exchange's monitoring picked up unauthorized transfers leaving some of its hot wallets. By the next day its chief executive, Gracy Chen, was saying something unusual for an exchange that had just lost hundreds of millions of dollars: the keys were never taken.

"The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out," Chen said, as quoted by CoinDesk. Decrypt quotes her more directly still: "They did not forge user withdrawal requests, nor did they obtain our private keys." In other words, Bitget's own signing process approved the transfers, because the system that feeds it had been told to ask.

Fortune calls it the largest crypto theft of the year to date, ahead of Liquid's roughly $320 million peg-out in early September.

Three numbers in a day

The public figure has moved twice. On-chain researchers saw it first. Decrypt names the pseudonymous researcher DCF GOD as among the first to post, and counts about $183 million moving from Bitget-labeled wallets into a single address, 0x770b…63Ee, over roughly an hour. CoinDesk credits Arkham Intelligence analyst Emmett Gallic, whose estimate went from about $183 million to $178 million.

Bitget's notice then put the figure at approximately $351.6 million. On September 25, during what Fortune describes as a three-hour livestream on X, Chen raised it to $387.5 million. According to PANews, the revision adds Zcash and TRON assets "that were not fully counted previously" and "does not represent newly stolen funds." That explanation is plausible, since outflows across several chains are slower to total than a single Ethereum address. It also means the exchange's first official number left out about $36 million of its own losses.

How the Bitget figure moved, Sep 24–25 ($ millions)

First on-chain count~183
Bitget notice351.6
Revised, Sep 25387.5
User Protection Fund464+
Sources: on-chain estimate via Decrypt; $351.6M and fund size from Bitget's notice; $387.5M revision via PANews. The fund figure is Bitget's own claim of "over $464 million."

The affected assets listed by The Crypto Times are XRP, ETH, USDT, Zcash, USDC, USDT0, XAUt, BNB, AVAX and TRX. Decrypt puts the XRP portion at roughly 103 million tokens, about $157 million, making it the single biggest piece. Bitget has not published a per-asset breakdown.

The cold-wallet question

Bitget's notice is emphatic: "Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers." CoinDesk's first report, however, describes Gallic's early findings as involving "three Bitget hot wallets and one cold wallet across multiple blockchains."

Those two statements can both be true. Labels on blockchain analytics platforms are inferences from observed behavior, and a wallet one firm tags as cold may be what the exchange internally calls warm. But nobody has reconciled them publicly, and Bitget's three-tier explanation relies on the difference between warm and cold, which only the exchange can define. It is the first thing the promised incident report should settle.

Six minutes on Arbitrum

The laundering started quickly. According to Decrypt, a newly created wallet spent $19.67 million in USDT0 on 7,111 ETH on Arbitrum in about six minutes, routed through UniswapX and 1inch Fusion at roughly 5 percent above market price. Paying that premium suggests speed mattered more than price. Stablecoins can be frozen by their issuers; ETH cannot.

Bitget's response is aimed at the same window. Per PANews, it has published a real-time tracking dashboard, an information submission portal and an attacker-address API, and is accepting reports through Bybit's LazarusBounty platform. Its Recovery Bounty Program pays 5 percent of funds a party voluntarily helps freeze and, per The Crypto Times, a further 5 percent of funds it directly helps recover. Freezes carried out under court orders, law-enforcement requests or other legal process do not qualify, and Bitget keeps discretion over payouts. The Crypto Times reports that Mandiant and SlowMist are investigating.

Why North Korea keeps coming up

Chen said that VPN and IP addresses and on-chain signing patterns resemble those of North Korea's state-linked hackers, according to Decrypt, and added that she had "personally been targeted by the same group before, losing about $80,000." She also said the attacker's identity "hasn't been confirmed." No government agency has attributed the theft.

The precedent people are reaching for is Bybit. In February 2025 the FBI said North Korea was responsible for stealing about $1.5 billion from that exchange, naming the activity TraderTraitor. Decrypt draws the same comparison. Resemblance in tooling is not attribution, and until investigators or a government say more, the North Korea link rests on Bitget's own reading of its logs.

What customers have been told

Deposits and trading stayed open. Withdrawals have been paused since the incident. Bitget says account balances are accurate and the loss "falls within the coverage" of its User Protection Fund, which it says holds more than $464 million. Fortune reports that Bitget Wallet, the company's self-custodial app, was not affected.

On timing, the messages have shifted. CoinDesk's September 24 report says Bitget promised an incident report within 24 hours. By September 25, Bloomingbit reported Chen saying technical verification of how the attacker got in was still under way, that full findings would come in a later report, and that she would not "promise a timetable it cannot keep." PANews reports that Bitget will announce its withdrawal plan before 04:00 UTC on September 26.

The Take

"No private keys were compromised" is being offered as reassurance. It should be read as the more worrying finding. A stolen key is a clear failure with a clear fix: rotate it. A signing system that approves whatever a trusted backend tells it to approve has done its job correctly and still paid out $387.5 million. That makes the control that failed the pipeline, not the vault, and every exchange that has spent its security budget on key custody should be asking what its own signer checks independently before it signs. Bitget deserves credit for the fund, the fast public numbers and the bounty terms. What it now owes is the report it said would take 24 hours: which backend, what the signer was shown, why an hour of outflows to a single address did not trip anything sooner, and what exactly counts as "warm."

More on the subject