Bitget Exchange Backend Breach
Attackers compromised Bitget's wallet backend to spoof withdrawals and drain roughly $387.5 million across eight blockchains, in 2026's largest crypto theft.
- Date
- Victim
- Bitget
- Chain(s)
- Status
- Funds Stolen
On September 24, 2026, cryptocurrency exchange Bitget was drained of roughly $351.6 million — a figure later put at approximately $387.5 million — after attackers compromised the backend of its wallet infrastructure and spoofed withdrawal transactions across eight blockchains, in what became the largest crypto theft of 2026.
What happened
Bitget's security systems flagged unauthorized transfers from several of its hot wallets at 18:31 UTC on September 24. Rather than stealing private keys or breaking the exchange's encryption, the attacker exploited a vulnerability in a third-party security product to obtain high-level credentials for Bitget's internal network, then used that access to forge transaction data that passed through the platform's legitimate authorization pipeline and was approved automatically without raising alerts. The fraudulent withdrawals left in two timed bursts and began with deliberately small test transactions — a 0.184 ETH transfer from an Ethereum hot wallet and 193 TRX from a Tron hot wallet — each sized below the exchange's risk-control thresholds. CEO Gracy Chen said hot and warm wallets were affected while offline cold storage remained secure. Investigators tied the intrusion to North Korea's Lazarus Group, citing IP addresses linked to VPN services previously used by the group, wallet clusters connected to earlier thefts, and the rapid asset-conversion pattern that followed; no government has formally confirmed the attribution.
Aftermath
Bitget said all user funds were covered 1:1 by its $464 million User Protection Fund plus more than $1 billion in company assets, and it kept deposits and trading running while pausing withdrawals to harden the affected systems. Withdrawals resumed in phases four days later, beginning with bitcoin on September 28. The stolen funds proved hard to claw back: the attacker converted roughly $100 million into ETH and moved about $83 million of XRP beyond reach — because XRP is the XRP Ledger's native asset, Ripple cannot freeze it, unlike the issuer-controlled stablecoins that Tether and Circle were able to blacklist. Chen publicly urged THORChain to reject transactions tied to the attacker's addresses, arguing "decentralization is a design principle, not a shield for facilitating known stolen funds," but the network declined and several million dollars flowed through it into bitcoin. Bitget offered a 5% bounty for freezing stolen funds and a further 5% for their recovery. Customer outflows meanwhile drove the protection fund below $200 million.
Why it matters
Bitget joins a grim lineage of centralized-exchange breaches — from Bybit and WazirX to DMM Bitcoin and Phemex — where the weak point was never the blockchain but the operational plumbing around it. The attack underscores a defining theme of 2026: the biggest losses increasingly come not from smart-contract bugs but from compromised infrastructure and credentials, the same class of failure implicated in the Coldcard seed-generation exploit weeks earlier. It also reignited the debate over whether "unstoppable" venues like THORChain and permissionless assets like XRP should — or even can — intervene when stolen money moves through them.
Sources & on-chain evidence
- [01]coindesk.comhttps://www.coindesk.com/markets/2026/09/24/crypto-exchange-bitget-loses-usd352-million-in-hack-claims-user-funds-are-safe
- [02]coindesk.comhttps://www.coindesk.com/markets/2026/09/25/bitget-s-usd351-million-hack-happened-via-spoofed-transfers-not-private-keys-ceo-gray-chen-says
- [03]cnbc.comhttps://www.cnbc.com/2026/09/25/crypto-platform-bitget-suspects-north-korea-in-352-million-hack.html
- [04]techcrunch.comhttps://techcrunch.com/2026/09/25/north-korean-hackers-suspected-in-351m-crypto-theft-the-largest-so-far-this-year/
- [05]fortune.comhttps://fortune.com/2026/09/25/north-korea-bitget-387-million-crypto-attack/
- [06]coindesk.comhttps://www.coindesk.com/markets/2026/09/26/bitget-hacker-moves-usd83-million-in-stolen-xrp-that-ripple-cannot-freeze
- [07]news.bitcoin.comhttps://news.bitcoin.com/exchanges/bitget-restarts-bitcoin-withdrawals-388m-hack-investigation-widens/
- [08]cryptotimes.iohttps://www.cryptotimes.io/2026/09/25/bitget-hacked-for-351-6m-withdrawals-frozen-as-ceo-points-to-north-korea/
- [09]claimsjournal.comhttps://www.claimsjournal.com/news/national/2026/09/29/340433.htm
- [10]bitquery.iohttps://bitquery.io/investigations/bitget-hack