Deep Dive - The Bitget Breach: How Forged Instructions Moved $228M in 18 Minutes
1. What Happened: The Whole Story in One Evening
Here is the entire incident as one story, before any tables. At about 18:31 UTC on September 24, 2026, Bitget's security system detected unauthorized transfers from exchange wallets, and CEO Gracy Chen confirmed a breach publicly within hours. The first on-chain trace was a brand-new address that converted $19.67M of USDT0 into 7,111 ETH within six minutes via UniswapX and 1inch Fusion, paying a market premium reported at up to 5%: speed over price, deliberately. Over the next three hours, assets from multiple Bitget-tagged hot and warm wallets were swept into attacker addresses across seven chains - XRP Ledger, Ethereum, Arbitrum, Optimism, BNB Chain, Avalanche and Base - while the exchange worked to pause withdrawals. Arkham Intelligence later traced about $350M leaving five wallets, with $228M of it compressed into an 18-minute burst between 18:58 and 19:16 UTC.
The scale settled in two steps rather than one. Bitget first confirmed $351.6M stolen; on September 25 it raised the figure to $387.5M - an increase of about $35.9M, or 10.2% - after identifying additional Zcash and TRON transfers. The company was explicit that the revision reflected fuller accounting of the same incident, not new theft, and that no further unauthorized transfers had occurred after containment. XRP was the largest single component at roughly $157M (about 103M tokens) at the September 25 accounting, and the attacker's ETH holdings grew past 63,000 ETH as stolen stablecoins were converted. The sweep drained only part of the hot and warm wallet layers - Bitget said the incident affected a portion of those layers while cold wallets stayed untouched - though why it stopped where it did is unresolved.
What happened next is the response architecture every exchange now assembles under pressure: withdrawals paused, with a phased restoration schedule announced September 26 (Bitcoin from September 28, ETH September 29, USDT September 30, everything else October 2); forensics handed to Mandiant and SlowMist; a 5% recovery bounty posted; law enforcement notified; and the exchange's $464M user protection fund named as the coverage source for user losses. By September 27, both stablecoin issuers had acted - Circle and Tether froze a hacker-linked wallet holding about $318,000 in USDT and USDC combined - while PeckShield and EmberCN reported that the larger share of funds had moved to a wallet linked to market maker Wintermute, with neither a sale nor the purpose confirmed.
Source: Bitget statements by CEO Gracy Chen; Arkham Intelligence; Coin360 incident accounting, September 25; PeckShield and EmberCN; SlowMist and Mandiant engagement; BlockchainReporter, September 27.
2. The Numbers, Reconciled
Five figures circulate in this incident, and they measure five different things. Collapsing them into one headline number is exactly the reporting error this column exists to prevent - and in this case the difference between the biggest and smallest figure is a factor of more than a thousand.
| Figure | What it measures | Status |
|---|---|---|
| $387.5M | Assets moved to attacker-controlled addresses, per Bitget's fuller accounting (Zcash and TRON transfers added) | Revised Sep 25 from $351.6M; not new theft |
| ~$350M | What Arkham Intelligence independently traced from five wallets across seven chains | Investigator trace; subset with $228M in an 18-minute burst |
| $174-183M | What early real-time tracing showed (Arkham's Emmett Gallic) before the official accounting | About half the final figure; an on-chain estimate, not exchange accounting |
| $464M | Bitget user protection fund held before the incident | Coverage claim; compensation execution pending |
| $318K | USDT frozen by Tether and Circle in a hacker-linked wallet | About 0.08% of the total moved; freeze tooling worked |
Two classification disagreements are part of the record rather than noise. Arkham characterized the ~103M XRP - about $157M - as sourced from a Bitget cold wallet, while Bitget said cold wallets remained secure and affected funds came from hot and warm infrastructure. And the early public estimates climbed from $174M to $183M before the official $351.6M: the number to quote is the accounting the exchange itself settled on, with the label moved-to-attacker-addresses, not stolen.
3. The Mechanism: A Supply-Chain Attack, Not a Key Compromise
The mechanism is the part payment teams should study, because it defeats the standard security advice. Bitget's keys were not stolen, leaked or phished. Instead, a third-party tool the exchange used in its wallet operations was breached, and the compromised tool forged transfer instructions that were then fed to Bitget's signing machines - the hardened devices whose entire job is to approve what the process hands them. The signing machines did exactly what they were designed to do: they executed instructions from a trusted upstream system. CEO Chen stated the attack vector in those terms, said current investigations suggest insider involvement is unlikely, and drew the comparison to the February 2025 Bybit heist, which combined a supply-chain compromise of the Safe multisig interface with signature manipulation.
The design lesson generalizes. Every custody architecture, from a single hot wallet to an 11-of-15 federation, trusts some upstream layer to decide what deserves a signature. That layer - the vendor software, the transaction-builder, the instruction queue - is now the primary target, because it is the one component that can move funds without ever touching a private key. This was not a blockchain failure and not a cryptography failure: every one of the swept transactions was validly signed and correctly settled. What failed was the trust boundary around the signing process, and it failed on the largest scale of the year.
4. Why the Attacker Swapped Stablecoins to ETH First
The first six minutes of the attack were spent converting stablecoins into ETH at a premium of up to 5%, and the reason is the freeze function. Tether can blacklist USDT addresses and Circle can blacklist USDC addresses - both issuers have used the power this very week, freezing a hacker-linked wallet holding about $318,000. ETH carries no such brake. Converting the freezable share of the haul into a non-freezable asset before issuers react is now standard attacker behaviour; the same sequencing was observed in the Bybit theft of February 2025.
The freeze did work exactly as designed - a wallet holding $318,000 was locked. But set that against the numbers: $318,000 frozen against $387.5M moved is a recovery rate of about 0.08% on the incident, and the freezable share of the haul was small to begin with because the attacker converted early and fast. The freeze function is a brake, not a recovery mechanism. Its real effect is on pricing: it makes stablecoins marginally safer to hold than native assets against custody failure, and it makes the first minutes after a breach - before issuers can react - the window that decides outcomes.
5. The Same Day, Three More Failures: The Pattern Is Operational
The reason this incident deserves a deep dive this particular week is its company. September 24 was the single worst day of the quarter for the trust layer, and the failures packed around it - three on the day itself, plus the FomoPeek iOS theft disclosed September 19 and escalated by Binance's advisory on September 21 - show the same root-cause diversity no single incident displays.
| Incident | Date | Root cause | What failed | Figure (as reported) |
|---|---|---|---|---|
| Bitget | Sep 24 | Supply chain: compromised vendor tool, forged instructions | The trust boundary around signing machines | $387.5M moved to attacker addresses |
| Payy Network | Sep 24 | Undisclosed bridge exploit | The Ethereum bridge, drained of its entire balance | $1.8M; USDC swapped to ETH |
| Duelbits | Sep 24 | Suspected private-key compromise | Hot wallet keys across BTC, Solana and TRON | ~$7M per co-founder; estimates climbed from $4.3M |
| Meter | Sep 24 | Block validation flaw: unbacked mint | Validation state, the same minting class as Symbiosis (Sep 15) | ~$2.3M minted and dumped; MTR down ~80% |
| FomoPeek (iOS wallet) | Disclosed Sep 19; Binance advisory Sep 21 | Malicious app modules with kernel exploits | iOS sandboxing and Keychain custody of seed data | Loss not fully tallied; funds traced through FixedFloat and KuCoin |
Five incidents, five different failure classes: vendor software, bridge logic, key custody, validation state, and app-store supply chain. Not one involves a blockchain's consensus. An organization that audits smart contracts has addressed one of the five; one that rotates keys has addressed another; one that vets its vendors has addressed a third. Operational security is not a discipline - it is five, and attackers only need the one you skipped.
6. Historical Precedent: The Genre, and the Escalation
The closest precedent is Bybit in February 2025 - roughly $1.5B, still the largest single exchange theft - where a supply-chain compromise of the Safe interface combined with manipulated signatures, and the attacker likewise converted to ETH early. The 2025 Liquid Federation peg-out moved the failure onto a sidechain's software layer; the Symbiosis exploit two weeks ago showed a $0.25 deposit minting 46 billion fake tokens through two application bugs. The 2026 aggregate makes the trend legible: DefiLlama-cited data puts the year at 281 security incidents and about $2.2B in losses, with Bitget alone accounting for roughly 16% - and September now the heaviest-loss month of 2026, surpassing April's $648M. Attribution for the Bitget breach remains unconfirmed, but Chen said identified IP addresses matched VPN choices associated with a North Korean organization, and on-chain analysts linked the bridging path of the stolen XRP to funds from the earlier AFX Trade exploit attributed to Lazarus' TraderTraitor unit; TRM Labs reported North Korean groups responsible for 76% of crypto hacking losses in the first four months of 2026.
Source: Bitget statements; Arkham Intelligence; TRM Labs; DefiLlama-cited aggregate data; Liquid and Symbiosis reporting as covered in this column on September 13 and 20.
7. Risk Points: What Would Have Made This Worse
Four conditions limited the damage, and each is a checklist item for anyone whose funds touch an exchange.
- The protection fund existed and was large enough. Bitget's $464M fund covers the loss on paper; exchanges without funded coverage would have passed a $387.5M hole to users. Fund size is now a counterparty-risk variable, not marketing.
- The sweep stopped within part of the hot and warm wallet layers rather than draining them. Whether containment, operational friction or choice limited it is unresolved; the same tooling against a smaller fund would have been fatal to users.
- The freeze function caught a sliver. Issuers locked $318K within days. It is 0.08% - but the freezable design also meant the attacker had to pay a premium to escape it, which is a real tax on exactly this attack path.
- Multi-chain spread fragmented the exit. Sweeping seven chains forced the attacker through seven sets of off-ramps and monitoring. Concentrated funds in one asset on one chain are easier to both steal and recover.
8. What to Watch
- Bitget's full forensic report: the vendor's name, the exact instruction-forging path, and whether the signing-machine trust model changes industry-wide as Safe did after Bybit.
- Withdrawal resumption against the phased schedule announced September 26 - BTC September 28, ETH September 29, USDT September 30, the rest October 2 - and whether users respond with a self-custody wave that shows up in exchange balances.
- The compensation execution from the $464M fund - on what timeline, and whether any user is left short.
- The Wintermute-linked wallet: whether the bulk of the funds sells, moves to mixers, or is negotiated back - and whether the 5% bounty produces recovered funds.
- Attribution: whether Mandiant, SlowMist or law enforcement confirms the DPRK linkage that the IP evidence and the AFX Trade fund-path overlap suggest.
- Whether the GENIUS Act rulemaking and the MiCA revision debate absorb the custody lesson - reserve rules are this quarter's story, but the same month produced the year's largest custody failure.
9. Our Read
The Bitget breach is the year's cleanest demonstration that the weakest link in digital-asset custody is not cryptography, chain consensus, or even key management - it is the trusted software that tells keys what to do. Every prior failure mode this column has covered this month, from Liquid's software flaw to Symbiosis' two bugs to Meter's validation error, lives in the same layer: the operational machinery between intent and settlement. And the response this week - issuer freezes within days, a funded protection fund, named forensic firms, a recovery bounty - is the most mature of 2026, which is exactly why the incident is survivable for Bitget's users where an unfunded exchange would not have been.
For anyone routing value across chains, the practical conclusions are unglamorous. Size exchange exposure as a counterparty risk, not a custody convenience - the fund's size is now part of the decision. Expect stablecoins to convert to native assets in the first minutes of any breach, and price the freeze function accordingly: it is a brake, not insurance. And treat vendor and signing infrastructure as part of the attack surface when you evaluate any custody arrangement, including your own. The fee table says crossing chains costs $1-8. This week showed what it costs when the instruction layer itself is broken: $228M in 18 minutes.
Glossary
| Signing machine | A hardened device that approves transactions for exchange wallets; it enforces key custody but only as far as the instructions it receives are honest. |
| Supply-chain attack | Compromising a vendor or tool a target depends on, so the intrusion arrives inside trusted software or instructions. |
| Warm wallet | A partially connected exchange wallet used for routine processing - between hot and cold exposure. |
| Freeze function | An issuer's ability to blacklist token contract addresses; Tether and Circle both exercised theirs against Bitget-related funds this week. |
| USDT0 | Tether's omnichain USDT representation, used by the attacker for the first conversion step. |
| Recovery bounty | A posted reward, here 5%, for information or action leading to the return of stolen funds. |
Common Myths About Exchange Breaches
$387.5M was stolen from users.
Not settled yet. $387.5M is what moved to attacker-controlled addresses; Bitget says its $464M user protection fund covers user losses, and compensation execution is pending. The realized loss depends on that execution and on recovery outcomes.
Cold wallets would have prevented this.
Only partly. Cold storage was reportedly untouched, and the cold-versus-warm classification of the XRP stash is itself disputed. But the attack vector - forged instructions to signing machines - can be aimed at any custody model whose signing layer trusts an upstream tool.
The freeze function failed because only $318K was caught.
The freeze worked as designed. The attacker anticipated it, converting stablecoins to ETH within six minutes at a premium of up to 5%. The small freeze total measures how fast attackers now are, not how slow issuers are.
Key Takeaways
- A compromised third-party tool fed forged instructions to Bitget's signing machines; keys were never compromised, and every swept transaction was validly signed.
- About $350M left five wallets across seven chains, $228M of it in an 18-minute burst; Bitget's accounting moved from $351.6M to $387.5M on September 25.
- Five loss figures circulate and measure different things - moved, traced, first-read, covered, frozen - and conflating them is the reporting error this report exists to prevent.
- The attacker converted stablecoins to ETH within six minutes, paying up to a 5% premium to escape issuer freezes; $318K was ultimately frozen, about 0.08% of the total.
- September 24 also carried Payy ($1.8M), Duelbits (~$7M) and Meter (~$2.3M), with FomoPeek's iOS seed theft disclosed days earlier - five incidents, five root causes, zero chain-consensus failures.
- The practical rule: size exchange exposure as counterparty risk, treat vendor and signing infrastructure as attack surface, and remember the freeze function is a brake, not insurance.
Frequently Asked Questions
When did the Bitget breach happen, and how much was taken?
Bitget's security system detected unauthorized transfers at about 18:31 UTC on September 24, 2026, with the drain continuing for nearly three hours before withdrawals were paused. Bitget first confirmed $351.6M and revised the total to $387.5M on September 25 after fuller accounting added Zcash and TRON transfers; Arkham independently traced about $350M, including $228M in an 18-minute burst.
Were private keys stolen?
No. CEO Gracy Chen said a third-party tool used in Bitget's wallet infrastructure was breached and forged transfer instructions were fed to the signing machines - a supply-chain attack on the process around the keys. Cold wallets were reported secure, though Arkham and Bitget disagree on the classification of the affected XRP stash.
Who is behind the attack?
Unconfirmed. Chen said identified IP addresses matched VPN choices associated with a North Korean organization, and analysts linked the XRP bridging path to funds from the earlier AFX Trade exploit attributed to Lazarus' TraderTraitor unit. TRM Labs reported North Korean groups accounted for 76% of crypto hacking losses in the first four months of 2026. Attribution remains open.
Will Bitget users be made whole?
The exchange says its $464M user protection fund fully covers the losses, and compensation execution is pending alongside the phased withdrawal resumption announced September 26, starting September 28. Whether any user is left short depends on that execution - which is why the fund's existence and size are now counterparty-risk variables in their own right.
Is this report financial advice?
No. CryptoScanin publishes independent research; nothing here is financial advice.
Sources & Methodology
This report is compiled from public on-chain data, official announcements and a curated source whitelist. Figures are cross-checked where possible; estimated or reference values are labelled as such. Nothing in this report is financial advice.
- Official project documentation, blog posts and GitHub repositories
- On-chain data from public explorers and analytics dashboards
- Primary announcements from the parties involved
- Cross-checked industry media coverage
Last reviewed: 2026-09-27.