AltcoinBuzzAltcoinBuzz
Subscribe
  • Crypto News
  • Crypto Research
  • Technical Analysis
AltcoinBuzzAltcoinBuzz

An independent digital media outlet delivering crypto research, news, and technical analysis to a community of 600,000+ users.

Follow us on:

Discover

  • Crypto Research
  • Crypto News
  • Technical Analysis
  • Key Opinions
  • Upcoming Launches

Categories

  • Bitcoin BTC
  • RWA
  • Technology
  • Altcoins
  • Regulation

Company

  • Affiliates
  • Partners & Sponsors
  • Careers
  • Contact
  • Terms of Use
  • Subscription Terms
  • About the ALTCOIN BUZZ
  • Privacy Policy
  • Contact ALTCOIN BUZZ
  • Advertise with us

Copyright 2026 ALTCOIN BUZZ. All rights reserved.Something is buzzzzzzzing.
HomeCrypto NewsBitget Users Lost $387.5M in Wallet Attack
Crypto NewsTechnology

Bitget Users Lost $387.5M in Wallet Attack

Bitget says a third-party security vulnerability enabled a $387.5M theft, while investigators still lack a full account of the attack.

AAnmol Billa•Sep 30, 2026
A pop-art Bitget wallet is breached as an exposed signing system sends Bitcoin and other cryptocurrency away across several blockchains.

Bitget users lost access to funds after attackers moved about $387.5 million from the exchange’s hot and warm wallets. The theft was not a sudden compromise: SlowMist traced malicious activity to an undisclosed third-party security product on Aug. 31, weeks before the transfers began on Sept. 24 UTC.

The attack began before the theft

SlowMist found activity involving two unidentified third-party security products and a wallet application host. Its earliest logged malicious activity connected to the theft occurred on Aug. 31, when an attacker exploited a zero-day vulnerability in one of those products.

That gap matters because the firms have not explained how long the attacker maintained access, or whether the activity on Aug. 31 was directly connected to every later action reported by investigators. SlowMist and Mandiant have both described their findings as interim reports, which means the current account of the attack is not yet complete.

The attacker used a hidden script to reach the database of what SlowMist called “Product A,” after retrieving its password from an environment variable. Similar activity was detected on two other nodes on Sept. 23 and Sept. 25, suggesting that the attacker was still probing the systems shortly before the transfers began.

Bitget’s signing system approved withdrawals

On Sept. 24, the attacker accessed the management platform for a second product, called “Product B,” using an internal employee’s identity. SlowMist said the attacker then tried to inject system commands, change server configurations and upload malicious files, all actions that could give the attacker control over systems connected to the exchange.

GoPlus Security concluded that Bitget’s own signing system approved the transfers. The largest wave, about $185 million, moved in roughly one minute at 19:16 UTC on Sept. 24, which is significant because the approval process that should have stopped suspicious withdrawals instead treated the transfers as valid.

SlowMist recovered a deleted, heavily customized tool that forged risk-control parameters, built withdrawal requests and invoked the withdrawal process. Two fabricated Bitcoin withdrawal orders entered processing but returned errors, while logs showed the attacker checking order records and retrying, according to the security researchers.

Transfers lasted nearly three hours

The first verified on-chain outflow was 93 TRX at 2:31 am UTC+8 on Sept. 25, followed 11 seconds later by 0.84 ETH on Ethereum. The compiled transfer records covered about two hours and 52 minutes, ending at 5:23 am UTC+8.

The first transfers began at 18:31 UTC on Sept. 24, which is 2:31 am UTC+8 on Sept. 25. That timing matches the minute Bitget said it detected unauthorized transfers, and the differing date labels in published accounts come from the time zones used.

Bitget has said the incident did not compromise its private keys or cold wallets. It also said the separately operated Bitget Wallet self-custody product was not affected, though that does not mean all user exposure was limited to the exchange’s own systems, because the funds were taken from hot and warm wallets and sent across several blockchains.

What Bitget has confirmed

Bitget first estimated the loss at $351.6 million. On Sept. 25, it raised the figure to about $387.5 million after adding Zcash and TRON transfers from the same attack window, and the exchange said the revision was not a second breach. It also launched a 5% bounty for frozen funds.

The exchange has said its User Protection Fund, which held more than $464 million at the time, would cover the loss. It reopened Bitcoin withdrawals on Sept. 28, while its wider schedule put USDT withdrawals at Sept. 30, with remaining tokens, fiat and P2P transactions due Oct. 2.

Bitget reopened Bitcoin withdrawals after the incident, but the underlying cause remains only partly identified. Bitget CEO Gracy Chen has said a vulnerability in a third-party security product gave the attacker high-level internal credentials, which were then used to issue fraudulent withdrawal commands.

Recovery and remaining unknowns

Chen has said she is not very optimistic about fully recovering the roughly $388 million. SlowMist’s MistTrack has identified suspected laundering routes through CoW Protocol orders, Chainflip contracts, bridges to Bitcoin and CoinJoin, according to the researchers’ analysis of the transfers.

SlowMist said Chainflip has tried to block some flows, but automated splitting across bridges is outpacing AML and KYT checks. In practical terms, that means the stolen assets may continue moving even after some routes are blocked, and investigators have not yet provided a complete recovery picture.

Attribution to North Korea remains a theory from Bitget, Elliptic and on-chain investigators, not a confirmed government finding. No government has formally attributed the attack.

SlowMist and Mandiant have not named the vendors behind Product A or Product B. They also have not identified who built the zero-day, or how the internal employee identity was obtained or forged, and Bitget expects to publish a fuller security report, but until those gaps are filled, the central claim remains that a vulnerable third-party security product opened a path into Bitget’s wallet environment.

The information discussed by Altcoin Buzz is not financial advice. This is for educational, entertainment, and informational purposes only. Any information or strategies are thoughts and opinions relevant to the accepted levels of risk tolerance of the writer/reviewers and their risk tolerance may be different than yours. We are not responsible for any losses that you may incur as a result of any investments directly or indirectly related to the information provided. Bitcoin and other cryptocurrencies are high-risk investments so please do your due diligence.

Copyright Altcoin Buzz Pte Ltd.

Related

A comic-style smartphone uses Binance Pay to scan a PayPay QR code at a Japanese merchant, linking crypto payment with a local yen purchase.
StablecoinsTechnology
Sep 30, 2026

Binance Pay Brings Crypto Payments to PayPay Merchants in Japan

Eligible overseas Binance users can pay at most PayPay merchants in Japan with crypto. Local residents are excluded, and launch fees are unclear.

Anmol Billa
A comic-style SEC shield confronts a broken trading bot and false certificate beside a $15.3M badge.
RegulationAI
Sep 30, 2026

SEC Sues Cryptoaiml and TSAI Over Alleged $15M AI Trading Fraud

The SEC alleges Cryptoaiml and TSAI misappropriated $15.3 million through false AI trading claims and fictitious SEC regulation.

Bikash Deka
A comic cover shows HSBC RedCoin moving from a smartphone into a Hong Kong payment scene, with a 1:1 Hong Kong dollar peg badge and a shield for reserve backing.
StablecoinsUpcoming Launches
Sep 30, 2026

HSBC Unveils RedCoin, Its Hong Kong Dollar Stablecoin, for 2026

HSBC plans to launch RedCoin through PayMe in 2026. Its first test is whether consumer payments can outgrow the bank's own apps.

Pallavi Malviya Gupta