Attackers drained about $388 million from Bitget on September 24, and they got in through a zero-day flaw in a third-party security product, not through stolen private keys. That flaw handed them valid admin credentials, which they used to slip fake withdrawal commands into the exchange's wallet backend and then erase the evidence. The first count of $351.6M was revised to $387.5M after Zcash and TRON transfers turned up.

  • The entry point was a security vendor's zero-day. Bitget says private keys and cold wallets were never compromised.
  • Two tiny test transfers (0.184 ETH and 193 TRX) sat below risk-control thresholds and raised no alert.
  • The reconciliation system flagged a discrepancy at 19:05 UTC, yet the timeline shows theft transactions running until 20:09.
  • Elliptic calls a North Korea link highly likely, and the loss would eat about 83.5% of Bitget's protection fund.
How the Bitget attack unfolded A vendor zero-day gave the attacker admin credentials. Two tiny test transfers passed below risk thresholds, then 17 withdrawals across eight chains ran from 18:58 to 20:09 UTC. Detection came at 19:05, and stolen Ether was swapped to Bitcoin through THORChain. 01Vendor zero-dayThird-party security tool 02Valid admin credsInternal access, no keys 03 · 18:31 UTCTwo test transfers0.184 ETH, 193 TRX 04 · 18:58-20:0917 withdrawals8 chains, ~$361M 05 · 19:05 UTCDiscrepancy detectedUser withdrawals blocked 06 · afterTHORChain swapsETH converted to BTC Both probes sat below risk-control thresholds, so no alert fired genztech.blog
Fig 1 The attack path as described by Bitget's CEO. The attacker never touched private keys or cold wallets. Valid admin access from a vendor flaw was enough to inject withdrawal commands and delete the traces.

How did two tiny transfers open the door?

Per CEO Gracy Chen's interview with The Block, the first unauthorized moves came at 18:31 UTC. The attacker pulled 0.184 ETH from the Ethereum hot wallet and 193 TRX from the Tron hot wallet. Pocket change, and deliberately so. Both amounts fell under the exchange's risk-control thresholds, so nothing paged anyone.

RelatedBitMart winds down after nine years, BMX crashes 58%

That is the useful detail here. A threshold rule asks "is this transfer big enough to worry about?" An attacker with valid credentials can simply answer the question first, with a probe too small to matter, and learn that the controls stay quiet. From 18:58 to 20:09 the real theft ran: 17 transactions, roughly $361M, spread over Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism and Avalanche.

What does the timeline say about detection?

Bitget's reconciliation system caught a discrepancy at 19:05 UTC, and the risk system then blocked user withdrawals. That is a working control. But the attacker was not a user. The withdrawal commands came from inside the wallet backend, and the stated theft window runs until 20:09, about an hour after the alarm. We are reading that off the published timeline, and Bitget has not yet published its formal report, so how the last hour played out is still open.

  1. Sept 24Test transfers, then the drain. First probes at 18:31 UTC, main theft 18:58 to 20:09, detection at 19:05.
  2. Sept 25Protection fund reported at $465M. Against a loss later put at $387.5M.
  3. Sept 28CEO details the timeline; BTC withdrawals resume. More than 3,000 BTC left in the first hour.
  4. Sept 29ETH withdrawals reopen. Stolen Ether reported moving into Bitcoin via THORChain.
  5. Within a weekFund replenished to at least $300M. Bitget's stated promise.

Why does a security vendor keep becoming the weak link?

Because it sits in the trust path. A security product often runs with broad internal access so it can inspect and protect everything, which makes one flaw in it worth more than a flaw in any single application. Here the zero-day yielded high-level admin or internal credentials. From there, the attacker did not need to break cryptography. They needed the wallet backend to believe a withdrawal command was legitimate.

This is a familiar pattern. The February 2025 Bybit theft, about $1.5B and attributed to Lazarus, also came through a third-party supply chain, in that case a compromised Safe{Wallet} developer machine. Bitget's chief said the IP addresses used matched the VPN choices of a North Korea group, and Elliptic assessed the link as highly likely. Chen declined to name a group before the formal report, saying "It's still the same group of people that we suspect." Mandiant and SlowMist are assisting the investigation. For the wider context on how bad 2026 has been, see our look at the H1 2026 crypto hack numbers.

Can Bitget actually cover the hole?

On paper, yes. The User Protection Fund stood at $465M on September 25. Finance Magnates notes the stated commitment is $300M, held as about 5,500 BTC, and that August's average was $382M. Paying out the full $387.5M would take roughly 83.5% of it and leave around $76.5M, below that commitment. Bitget says it will replenish the fund to at least $300M within a week, and it cites corporate reserves above $1.4B. A 5% recovery bounty is on offer, and some assets have been frozen, though the amount is undisclosed.

Bitget protection fund versus the loss The User Protection Fund stood at 465 million dollars on September 25. The loss was 387.5 million, leaving about 76.5 million, well under the 300 million dollar commitment line. $300M commitment $465M$387.5M~$76.5M Fund, Sept 25StolenLeft after payout genztech.blog
Fig 2 · data Full reimbursement would consume about 83.5% of the fund and leave it roughly $223M under Bitget's stated $300M commitment. Bitget says it will top the fund back up to at least $300M within a week.

Recovery looks harder. Chen has said he doubts full recovery of the funds, per Cointelegraph, and the stolen Ether is already being swapped to Bitcoin through the THORChain cross-chain protocol. Chen framed the damage this way: "An incident like this scale is very serious. But serious doesn't mean existential." Users voted with their wallets anyway. PYMNTS reports about $463M in net outflows over 24 hours as withdrawals were restored, with BTC withdrawals back on September 28 and ETH on September 29.

RelatedBlockstream's Liquid Network Hacked for $320M, $47M Kept

What does it mean for the market?

The signal for investors is not the headline loss, since the fund and reserves cover it. It is how quickly customers pulled balances once the doors reopened. That outflow figure is the real stress test, and it applies to any exchange with a similar profile. The signal for holders of the exchange's BGB token is that its value leans on the exchange's credibility and on how the fund top-up lands. The competitive read is that rivals will market proof-of-reserves and cold-storage ratios hard for the next few weeks. Verify those claims rather than absorbing them. This is analysis, not advice to buy or sell anything.

What to watch · 2026
  • The formal report. Bitget has named neither the vendor nor the flaw. Watch for the vendor's identity and a patch timeline.
  • The fund top-up. The promise is at least $300M within a week. Check whether it shows up in Bitget's proof of reserves.
  • Control redesign. Expect scrutiny of sub-threshold probing, velocity limits across chains, and out-of-band approval for withdrawal commands.
  • Laundering trail. THORChain swaps into BTC are the next place the money can be tracked or frozen.

What should users do today?

Check the exchange's proof-of-reserves page and look at reserve ratios rather than slogans. Do not park long-term holdings on an exchange hot balance, because a hot wallet is exactly what got drained here. Turn on withdrawal address allowlists and any withdrawal delay your account offers. And keep the coins you plan to hold for years in self-custody, where an exchange's vendor stack is not in your threat model.

Our take

The cold-wallet claim is good news and also beside the point. Cold storage protects what it holds. It does nothing for the hot and warm balances an exchange keeps running to serve withdrawals, and those were the target. What failed was the assumption that a check built around transfer size can stop someone who already holds the keys to the admin door. Sub-threshold probes are cheap, and any exchange with static limits should assume they are being tried. Bitget will very likely survive this: the fund, the reserves and the fast reopening of withdrawals point that way. The harder question is whether the industry finally treats its security vendors as part of the attack surface, since the last two giant heists both entered through someone else's software.

Primary sources

Original analysis by GenZTech, based on The Block and exchange disclosures.