$388M Stolen in Bitget Hack: What Happened?

By Venga
5 min read

Table of Contents

If you’ve been around crypto for a while, you’ve probably heard of Bitget, one of the world’s major crypto exchanges. And well... last week, it found itself facing the biggest crypto hack of the year, with around $388 million stolen from part of its hot and warm wallets.

While Bitget was quick to respond and assured that user balances were unaffected, investigators have since uncovered more details about how the attack unfolded, with signs that this attack's seeds have been planted inside the infrastructure weeks before making the big move.

So, let’s see what investigators found out.

The attack may have started weeks before

September 24 may have been the day everyone noticed the attack, but according to an investigation by security firm SlowMist, the earliest known activity linked to this incident dates back to August 31.

Investigators believe the attacker exploited a zero-day vulnerability in a third-party security product and later gained access to other security systems. The investigation also uncovered activity involving another security product and a wallet application host, suggesting that the attacker may have spent considerable time moving through Bitget’s infrastructure before attempting to steal the funds.

Things get even more interesting when you look at the tools involved. SlowMist says it recovered a deleted, highly customised tool designed specifically to manipulate Bitget’s withdrawal process, allowing to forge risk-control information, construct withdrawal requests and trigger the withdrawal process.

In other words, this wasn’t someone simply finding an exposed wallet and simply moving funds. It rather seems that the attacker have carefully worked their way through the infrastructure before the real deal.

The heist’s kickoff and emergency mode

Bitget has been pretty transparent about what happened, and its systems quickly reacted to the attack. That’s what years of operating seriously in the crypto ecosystem can bring.

Initial events timeline after the first unauthorised transfer - Bitget
Initial events timeline after the first unauthorised transfers - Bitget

The first unauthorised transfers occurred at 18:31 UTC on September 24, involving assets held across part of Bitget’s hot and warm wallet infrastructure. And just 34 minutes later, Bitget’s reconciliation system detected a major discrepancy and automatically blocked withdrawals across the platform.

At 19:14, its highest-level emergency response was activated, followed by the isolation of affected systems and the shutdown of withdrawal-related services, while the company began moving funds to cold wallets as a precaution and investigated whether private keys could have been compromised.

By the next morning, Bitget said it had identified the attack path and started fixing the underlying vulnerability. The exchange platform then began gradually restoring withdrawals from September 28, starting with BTC and subsequently reopening other assets and networks following additional security checks.

According to Bitget, the incident was limited to a portion of its hot and warm wallet infrastructure and no cold wallets were affected, private-key compromise was ruled out based on the investigation, and user account balances remained unaffected.

The company also said that the financial impact was covered by its Protection Fund. And yeah, $388 million is certainly not a small amount to cover, but they did.

Who’s behind it?

This part is still a “case open” situation. Bitget and several blockchain investigators have pointed to a possible North Korean connection, based on infrastructure, IP addresses and patterns resembling previous attacks attributed to North Korean hacking groups like the Lazarus Group.

The potential connection is particularly notable because North Korean-linked groups have previously been associated with some of the largest crypto thefts in the industry. However, that doesn’t mean this Bitget attack is their work.

At this stage, the connection has not been officially confirmed by a government, and Bitget says it won’t speculate on attribution until the investigation is complete. Independent investigations by firms including SlowMist and Mandiant are helping piece together what happened, but the full picture is still to be assembled.

Where is the money now?

As you can imagine, the attacker hasn’t left the $388 million sitting in one wallet waiting for someone to find it.

More than half of Bitget's stolen XRP has already moved on - CoinDesk
More than half of Bitget's stolen XRP has already moved on - CoinDesk

Once the funds were stolen, they began moving across different blockchains and through cross-chain swap services to make them difficult to trace and recover. Investigators managed to track back some assets moving through services including THORChain and other cross-chain infrastructure, with the attacker splitting funds into different wallets and converting some assets along the way.

Not every attempt has worked, though. Near Intents says it rejected more than $50 million in attempted swaps linked to the attack, while some funds have also been frozen through cooperation between different players in the crypto ecosystem. Bitget can certainly thank them.

More recently, the attacker took another route. Around $3.9 million in stolen Zcash was moved into Zcash’s privacy-focused Ironwood pool, where transactions are designed to hide the sender, recipient and amount from the public. That makes the funds even harder for investigators to follow while they remain inside the shielded pool.

Bitget hacker shields $3.9M in stolen ZEC - CoinDesk
Bitget hacker shields $3.9M in stolen ZEC - CoinDesk

Blockchain transactions may be public, but following stolen funds across multiple networks, wallets, swaps and privacy systems is a very different challenge. Bitget is working with exchanges, blockchain projects, security firms and law enforcement to track and recover the assets.

The company has also launched a 5% recovery bounty for eligible funds that are frozen or recovered, giving the wider crypto industry an extra incentive to help bring the stolen assets back to Bitget. So, if you’re ready for some hacker hunting, feel free to put on your bounty hunter hat. Yeehaw!

On a side note, after investigating Bybit's $1.5B hack from last year, ZachXBT might have a lead on this Bitget one. Let's keep an eye out for next updates.


Disclaimer: The content provided in this article is for educational and informational purposes only and should not be considered financial or investment advice. Interacting with blockchain, crypto assets, and Web3 applications involves risks, including the potential loss of funds. Venga encourages readers to conduct thorough research and understand the risks before engaging with any crypto assets or blockchain technologies. For more details, please refer to our terms of service.

Tagged in:

News

Last Update: October 08, 2026