Bitget Lost $388 Million Without Losing a Single Private Key
Attackers forged withdrawal orders inside the exchange's wallet backend, then ran the proceeds through a protocol that refused to stop them.
At 18:31 UTC on Thursday, September 24, Bitget's monitoring systems flagged a cluster of unauthorized transfers leaving its hot and warm wallets. By the time the exchange froze withdrawals, $351.6 million had moved to attacker-controlled addresses across Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain, and Base, according to BleepingComputer and CoinDesk. Two days later Bitget raised the figure to roughly $387.5 million once Zcash and TRON assets were counted, per crypto.news.
The size alone makes this one of the largest exchange thefts since the roughly $1.5 billion Bybit breach in February 2025. What makes it instructive is how it happened. Nobody stole a key.
Forged slips at the teller window
CEO Gracy Chen said the attacker compromised a critical backend system inside the wallet infrastructure, used it to spoof transaction data, and then let Bitget's own authorization process approve the transfers, according to CoinDesk. She compared it to forged withdrawal slips handed through a bank teller's window, and said private key compromise had been ruled out. Crypto Times, citing the exchange's later update, reports the entry point was a vulnerability in a third-party security product Bitget used, which gave the attacker high-level internal credentials to issue fraudulent withdrawal commands that bypassed risk controls. Bitget's own support notice says only that the vulnerability has been identified and remediated.
That detail should worry every custodian. The industry has spent a decade hardening key storage with hardware modules, multiparty computation, and cold storage. Bitget's cold wallets were untouched. But the signing machinery will sign whatever the system upstream tells it is legitimate, and the attacker owned the upstream. Crypto Times reports $185 million moved in a single minute. The same pattern of subverting the approval flow rather than the keys was at the center of the Bybit incident, and Bitget has preliminarily linked this one to North Korean state-backed groups based on IP behavior and on-chain analysis, per BleepingComputer. That attribution remains preliminary.
What was taken, and what can be clawed back
Lookonchain's breakdown, reported by Bitcoin.com News, shows how deliberately the haul was assembled: about 102.93 million XRP worth roughly $157.5 million, the largest single-chain loss, plus about 31,890 ETH, roughly $34.75 million in USDT, $21.05 million in USDC, $19.67 million in USDT0, 3,000 XAUt tokenized gold, and smaller amounts of BNB, AVAX, and TRX.
The asset mix determines recovery odds. Centrally issued stablecoins can in principle be frozen by Tether or Circle, which is why the attacker converted quickly. Security researchers traced stolen USDC being swapped into ETH, and bitcoin being routed through Wasabi's CoinJoin mixer, according to crypto.news. Bitcoin.com News reports that more than 99% of the stolen XRP sat untouched in fresh wallets, with no issuer able to freeze it.
THORChain says no, again
On Saturday, September 26, Chen publicly asked THORChain, the cross-chain swap protocol, to refuse service to the listed attacker addresses. The protocol declined on September 28, crypto.news reports, drawing a distinction between an emergency network halt, which it treats as a security tool, and selectively freezing specific funds, which it says it does not do. Security executive Michael Perklin argued that node operators run automated processes rather than approving individual swaps, and that switching infrastructure off would stop legitimate and criminal traffic alike.
The amounts involved this time appear small: crypto.news traced roughly 4 BTC through THORChain before it reached Wasabi. The precedent is not small. The same outlet notes THORChain processed $2.91 billion in volume from Bybit hack conversions and earned about $3 million in fees on it, and a core developer left after a proposal to block the Bybit attacker failed to win node operator support. Each major theft now forces the same argument about whether permissionless infrastructure can stay neutral when its fee revenue comes from laundering state-sponsored thefts. Regulators writing rules for DeFi front ends and cross-chain bridges are watching that argument closely.
Customers are whole, for now
Bitget, a Seychelles-headquartered exchange that CoinDesk ranks among the top ten by volume with more than 125 million users, says its User Protection Fund will absorb the entire loss. The fund holds about 5,500 BTC, valued near $464 million at the time of the breach, according to BleepingComputer. By Flux's math, the revised $387.5 million loss leaves a cushion of roughly $76 million, much thinner than the $112 million gap cited when the loss was still $351.6 million, and a figure that moves with the bitcoin price.
Trading and deposits never stopped. Withdrawals are reopening in phases, per the company's support notice: bitcoin at 08:00 UTC on September 28, ETH on Ethereum and major layer-2 networks on September 29, USDT on September 30, and remaining tokens, fiat, and peer-to-peer services on October 2. Mandiant and SlowMist are assisting the investigation.
Why it matters beyond one exchange
The protection-fund model worked as advertised this week, which is good news for users and a quiet argument for the reserve requirements regulators keep proposing. But the lesson for the industry is architectural. A signing system is only as trustworthy as every piece of software allowed to feed it instructions, including vendor security products meant to protect it. Bitget's keys were safe the entire time. Its money still left in a minute.
As exchanges connect more automation, and increasingly AI agents, to their withdrawal pipelines, the attack surface is shifting from the vault to the paperwork. Expect auditors and insurers to start asking custodians not just where the keys live, but who is allowed to write the withdrawal slip.
