Bitget Confirms $351.6 Million Cryptocurrency Heist

Bitget cryptocurrency exchange logo and abstract blockchain transaction visualization

The prominent cryptocurrency exchange Bitget has officially confirmed a catastrophic security breach, resulting in the theft of approximately $351.6 million following unauthorized transfers originating from a segment of its hot wallet infrastructure. The attack commenced on September 24, prompting the exchange to immediately suspend all withdrawal operations. Meanwhile, the malicious actors have already aggressively converted a substantial portion of the pilfered assets into Ethereum.

Bitget’s internal security perimeter detected anomalous transactions beginning precisely at 18:31 UTC. Based upon the company’s preliminary assessment, the incident inflicted approximately $351.6 million in total damages, crucially compromising only a specific subset of the hot and intermediate wallet tiers. Bitget emphatically asserts that its cold storage wallets—where exchanges traditionally secure the vast majority of their reserve assets entirely disconnected from internet-facing infrastructure—remain completely intact and uncompromised.

Tracing the Exfiltrated Cryptocurrency

Blockchain forensics specialists at Lookonchain meticulously traced the subsequent trajectory of the stolen cryptocurrency. Their analysis revealed that the attacker swiftly swapped the majority of assets pilfered across EVM-compatible networks into precisely 67,982 ETH. At the exact moment of this forensic analysis, that volume of Ethereum possessed an estimated market valuation of $183 million.

The complete inventory of the exfiltrated assets proved significantly broader than Ethereum alone. A subsequent, more granular transaction analysis conducted by Lookonchain calculated staggering losses: approximately 102.93 million XRP (valued at $157.48 million), 31,890 ETH ($85.75 million), 34.75 million USDT, 21.05 million USDC, 19.67 million USDT0, 3,000 XAUT, 12,719 BNB, 821,012 AVAX, and 20.59 million TRX. Aggregating the analysts’ valuations for these individual assets yields a cumulative sum slightly exceeding Bitget’s official $351.6 million declaration. This minor discrepancy is easily attributable to fluctuating market valuations and the precise timing of the respective assessments.

Initial loss estimates were considerably more conservative. Shortly after the suspicious transfers commenced, Bubblemaps calculated that approximately $192 million had drained from Bitget-affiliated addresses across multiple networks. Subsequently, analysts identified additional exfiltration routes, including a massive XRP transfer, after which Bitget finally articulated the true, devastating scale of the incident.

The Strategy Behind Ethereum Conversion

The attacker’s rapid conversion of stablecoins and various other tokens into Ethereum represents a highly pragmatic evasion strategy. Centralized stablecoin issuers, such as the entities governing USDT and USDC, possess the inherent capability to freeze funds residing within specific wallet addresses. Conversely, the native Ethereum network lacks a centralized issuing authority capable of unilaterally freezing specific coins. While the transfers remain irrevocably visible on the public blockchain and continuously monitored by forensic analysts, the funds themselves become significantly harder to seize.

Bitget’s Response and Ongoing Investigation

Bitget decisively suspended all cryptocurrency withdrawals to facilitate a comprehensive security audit. However, the exchange maintains that standard deposits and trading activities remain fully operational, although the specialized Bitget Onchain service was also temporarily disabled. The corporation announced that it has formally transmitted all suspicious wallet addresses to relevant law enforcement agencies and specialized blockchain analysis firms.

The exchange staunchly maintains that all client funds remain absolutely secure, asserting that the catastrophic losses are entirely covered by its dedicated User Protection Fund. At the exact moment of the incident, Bitget valued this specific fund at over $464 million. Furthermore, shortly before the devastating attack, the company had proactively published its September Proof of Reserves, boasting a robust aggregate reserve ratio of 135% across all tracked assets. Currently, however, the industry must rely entirely upon Bitget’s internal declarations, as no independent audit verifying the post-hack financial reality has yet concluded.

Officially, the company has not yet definitively established the precise vector of compromise. During a public broadcast, Bitget CEO Gracy Chen articulated a preliminary hypothesis suggesting that the attackers might have successfully compromised a third-party tool intrinsically linked to the server-side wallet infrastructure. According to Chen, this compromised service could have covertly manipulated transaction data before transmitting it directly to the automated signature system. While the company observes no overt indications of compromised private keys at this preliminary stage, Chen explicitly emphasized that the final attack scenario still requires rigorous forensic corroboration.

Bitget has pledged to publish an exhaustive incident report detailing the precise root cause of the breach and outlining enhanced defensive countermeasures within 24 hours of the incident’s initial discovery. Until this definitive technical report is published, the supply chain compromise theory remains strictly preliminary, and the exact mechanism by which a malicious actor managed to siphon hundreds of millions of dollars from the exchange’s wallet infrastructure remains dangerously unresolved.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply