Bitget has confirmed that attackers stole $387.5 million from its exchange wallets on September 24. Withdrawals still remain suspended, while the company says its protection fund covers the loss.
Mandiant and SlowMist are investigating. CEO Gracy Chen suspects North Korean involvement, although the initial entry point remains undisclosed.
So, how did the hack potentially take place? BeInCrypto has structured a timeline based on publicly available info.
Bitget says its security systems detected the transfers at 18:31 UTC and activated emergency procedures within minutes.
The breach affected parts of its hot and warm wallets, which support exchange operations. Its offline cold wallets remained secure, according to the company. The detection time does not establish when attackers first gained access.
最新的进展同步一下:我们正在与独立第三方专家 @Mandiant 和 @SlowMist_Team 合作,对此次事件进行全面调查。 其他几点都是说过的,我再强调一下:-我们的首要任务是保障用户。用户余额保持完整,Bitget 用户保护基金将覆盖此次平台层面事件造成的影响。 -Bitget Wallet 为自托管钱包,运行于与… https://t.co/pZM4XzFolp
— Gracy Chen @Bitget (@GracyBitget) September 25, 2026
At 19:57, analyst DCF GOD flagged a fresh wallet spending $19.67 million in USDT0 to buy 7,111 ETH in six minutes. It reportedly paid up to 5% above market prices.
The behaviour suggested someone prioritized moving funds quickly. Their motive was still unclear.
By 21:06, Bubblemaps reported roughly $180 million moving from Bitget wallets to a common receiving address, then splitting into several wallets.
Chen’s security notice put the initial loss at $351.6 million and confirmed that withdrawals were paused.
The notice came almost three hours after Bitget’s stated detection time. That gap leaves questions about its response, but does not prove funds kept leaving throughout that period.
Chen said attackers compromised a critical backend system, meaning software that manages wallet operations behind the scenes.
They supplied false transaction data and triggered Bitget’s authorization process. In simple terms, its own system approved fraudulent transfers.
Chen said private-key theft had been ruled out. How attackers entered the backend, and which checks failed, still requires a detailed public explanation.
Tough day for Bitget. I expect and know @Binance, the @BNBCHAIN ecosystem, and the community will do everything we can to help.Stay SAFU! 🙏 pic.twitter.com/cyAEHdSi1S
— CZ 🔶 BNB (@cz_binance) September 25, 2026
Bitget revised its estimate after including affected Zcash and TRON assets. It said the increase reflected a fuller accounting of the original theft.
The company says the vulnerability has been fixed. It promised a withdrawal-plan announcement by September 26 at 04:00 UTC, without committing to reopening withdrawals then.
Chen cited IP behaviour and blockchain activity consistent with North Korean groups. Several features resemble the February 2025 Bybit theft, which the FBI attributed to North Korea.
These parallels support further investigation. They do not independently identify Bitget’s attackers.