Attackers drained about $388 million from Bitget on September 24, and they got in through a zero-day flaw in a third-party security product, not through stolen private keys. That flaw handed them valid admin credentials, which they used to slip fake withdrawal commands into the exchange's wallet backend and then erase the evidence. The first count of $351.6M was revised to $387.5M after Zcash and TRON transfers turned up.
- The entry point was a security vendor's zero-day. Bitget says private keys and cold wallets were never compromised.
- Two tiny test transfers (0.184 ETH and 193 TRX) sat below risk-control thresholds and raised no alert.
- The reconciliation system flagged a discrepancy at 19:05 UTC, yet the timeline shows theft transactions running until 20:09.
- Elliptic calls a North Korea link highly likely, and the loss would eat about 83.5% of Bitget's protection fund.
How did two tiny transfers open the door?
Per CEO Gracy Chen's interview with The Block, the first unauthorized moves came at 18:31 UTC. The attacker pulled 0.184 ETH from the Ethereum hot wallet and 193 TRX from the Tron hot wallet. Pocket change, and deliberately so. Both amounts fell under the exchange's risk-control thresholds, so nothing paged anyone.
RelatedBitMart winds down after nine years, BMX crashes 58%
That is the useful detail here. A threshold rule asks "is this transfer big enough to worry about?" An attacker with valid credentials can simply answer the question first, with a probe too small to matter, and learn that the controls stay quiet. From 18:58 to 20:09 the real theft ran: 17 transactions, roughly $361M, spread over Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism and Avalanche.
What does the timeline say about detection?
Bitget's reconciliation system caught a discrepancy at 19:05 UTC, and the risk system then blocked user withdrawals. That is a working control. But the attacker was not a user. The withdrawal commands came from inside the wallet backend, and the stated theft window runs until 20:09, about an hour after the alarm. We are reading that off the published timeline, and Bitget has not yet published its formal report, so how the last hour played out is still open.
- Sept 24Test transfers, then the drain. First probes at 18:31 UTC, main theft 18:58 to 20:09, detection at 19:05.
- Sept 25Protection fund reported at $465M. Against a loss later put at $387.5M.
- Sept 28CEO details the timeline; BTC withdrawals resume. More than 3,000 BTC left in the first hour.
- Sept 29ETH withdrawals reopen. Stolen Ether reported moving into Bitcoin via THORChain.
- Within a weekFund replenished to at least $300M. Bitget's stated promise.
Why does a security vendor keep becoming the weak link?
Because it sits in the trust path. A security product often runs with broad internal access so it can inspect and protect everything, which makes one flaw in it worth more than a flaw in any single application. Here the zero-day yielded high-level admin or internal credentials. From there, the attacker did not need to break cryptography. They needed the wallet backend to believe a withdrawal command was legitimate.
This is a familiar pattern. The February 2025 Bybit theft, about $1.5B and attributed to Lazarus, also came through a third-party supply chain, in that case a compromised Safe{Wallet} developer machine. Bitget's chief said the IP addresses used matched the VPN choices of a North Korea group, and Elliptic assessed the link as highly likely. Chen declined to name a group before the formal report, saying "It's still the same group of people that we suspect." Mandiant and SlowMist are assisting the investigation. For the wider context on how bad 2026 has been, see our look at the H1 2026 crypto hack numbers.
Can Bitget actually cover the hole?
On paper, yes. The User Protection Fund stood at $465M on September 25. Finance Magnates notes the stated commitment is $300M, held as about 5,500 BTC, and that August's average was $382M. Paying out the full $387.5M would take roughly 83.5% of it and leave around $76.5M, below that commitment. Bitget says it will replenish the fund to at least $300M within a week, and it cites corporate reserves above $1.4B. A 5% recovery bounty is on offer, and some assets have been frozen, though the amount is undisclosed.
Recovery looks harder. Chen has said he doubts full recovery of the funds, per Cointelegraph, and the stolen Ether is already being swapped to Bitcoin through the THORChain cross-chain protocol. Chen framed the damage this way: "An incident like this scale is very serious. But serious doesn't mean existential." Users voted with their wallets anyway. PYMNTS reports about $463M in net outflows over 24 hours as withdrawals were restored, with BTC withdrawals back on September 28 and ETH on September 29.
RelatedBlockstream's Liquid Network Hacked for $320M, $47M Kept
What does it mean for the market?
The signal for investors is not the headline loss, since the fund and reserves cover it. It is how quickly customers pulled balances once the doors reopened. That outflow figure is the real stress test, and it applies to any exchange with a similar profile. The signal for holders of the exchange's BGB token is that its value leans on the exchange's credibility and on how the fund top-up lands. The competitive read is that rivals will market proof-of-reserves and cold-storage ratios hard for the next few weeks. Verify those claims rather than absorbing them. This is analysis, not advice to buy or sell anything.
- The formal report. Bitget has named neither the vendor nor the flaw. Watch for the vendor's identity and a patch timeline.
- The fund top-up. The promise is at least $300M within a week. Check whether it shows up in Bitget's proof of reserves.
- Control redesign. Expect scrutiny of sub-threshold probing, velocity limits across chains, and out-of-band approval for withdrawal commands.
- Laundering trail. THORChain swaps into BTC are the next place the money can be tracked or frozen.
What should users do today?
Check the exchange's proof-of-reserves page and look at reserve ratios rather than slogans. Do not park long-term holdings on an exchange hot balance, because a hot wallet is exactly what got drained here. Turn on withdrawal address allowlists and any withdrawal delay your account offers. And keep the coins you plan to hold for years in self-custody, where an exchange's vendor stack is not in your threat model.
Our take
The cold-wallet claim is good news and also beside the point. Cold storage protects what it holds. It does nothing for the hot and warm balances an exchange keeps running to serve withdrawals, and those were the target. What failed was the assumption that a check built around transfer size can stop someone who already holds the keys to the admin door. Sub-threshold probes are cheap, and any exchange with static limits should assume they are being tried. Bitget will very likely survive this: the fund, the reserves and the fast reopening of withdrawals point that way. The harder question is whether the industry finally treats its security vendors as part of the attack surface, since the last two giant heists both entered through someone else's software.
- ReportThe Block, attacker tested risk controls CEO interview and UTC timeline
- ReportCointelegraph, third-party vulnerability attack method and recovery outlook
- ReportFinance Magnates, protection fund fund size and commitment math
- ReportGizmodo, North Korea link Elliptic attribution
- ReportPYMNTS, outflows $463M net outflows after reopening
- OfficialBitget proof of reserves exchange reserve disclosures
Original analysis by GenZTech, based on The Block and exchange disclosures.
