Bitget Says Backend Compromise Triggered $387.5M Fraudulent Wallet Drain

Daily Feed
Bitget Says Backend Compromise Triggered $387.5M Fraudulent Wallet Drain

Bitget says attackers used fraudulent approvals to drain hundreds of millions from exchange wallets

Bitget says it detected unauthorized transfers on September 24 after attackers compromised a critical backend system and used fake transaction data to push fraudulent approvals through its wallet operations. The exchange first estimated the loss at $351.6 million, then later raised it to $387.5 million after including additional Zcash and TRON assets.

  • Bitget says hot and warm wallets were affected, while cold wallets stayed secure.
  • The exchange says withdrawals were paused after suspicious activity was detected at 18:31 UTC.
  • Mandiant and SlowMist are investigating.
  • North Korean involvement has been raised as a possibility, but it has not been proven.

The part that should make exchange operators sweat is not just the size of the loss. Bitget says this was not a simple private-key theft. According to the company, attackers compromised a backend system that manages wallet operations and triggered the exchange’s own authorization process to approve fraudulent transfers. In plain English: the thieves allegedly didn’t just break in, they got the system to hand them the keys for a moment and smile for the camera. For more on the mechanics of that kind of exploit, see the breakdown of how fraudulent approvals enabled $387M.

Bitget says it detected unauthorized transfers at 18:31 UTC on September 24 and activated emergency procedures within minutes. The exchange later confirmed that withdrawals had been suspended, a move echoed in reports like Bitget hit by $351M hack, withdrawals frozen as probe begins. It also said offline cold wallets remained secure. That distinction matters. Hot wallets are online and used for active transfers, warm wallets are operational but less exposed, and cold wallets are kept offline for long-term storage. In other words, this appears to have hit the exchange’s working infrastructure, not its offline vaults.

By 21:30 UTC, Bitget CEO Gracy Chen had issued a security notice putting the initial loss estimate at $351.6 million. On September 25 at 00:43 UTC, Chen said the attackers had compromised a critical backend system and, by feeding in false transaction data, effectively caused Bitget’s own systems to approve fraudulent transfers. Bitget later said the vulnerability had been fixed.

At 14:03 UTC on September 25, Bitget revised its estimate to $387.5 million after adding Zcash and TRON assets to the tally. That figure is Bitget’s later estimate, not an independently verified final loss number. The company also said it would announce a withdrawal plan by September 26 at 04:00 UTC, though that was not a promise that withdrawals would immediately reopen. Reuters also reported on the shutdown in its coverage of the crypto exchange Bitget pausing withdrawals after the $350 million stolen hack.

The exchange says its protection fund is large enough to cover the loss. Bitget has described that reserve as a backstop for this kind of event, and that is useful, but it is not magic. A protection fund can absorb a hit on paper. It does not erase the operational mess, the reputational damage, or the question every user asks after a breach: can I still trust this place with my money?

That trust question is the real wound here. Centralized exchanges depend on internal controls, transaction validation, and approval workflows working exactly as intended. If attackers can subvert those systems from the backend, the failure is bigger than a wallet compromise. It becomes a failure of the machinery that is supposed to say “no” when a transfer is fake. Bitget’s own account of the incident is summarized in its $351M unauthorized transfer report.

There were also signs of rapid asset movement around the incident. At 19:57 UTC, analyst DCF GOD flagged a fresh wallet spending $19.67 million in USDT0 to buy 7, 111 ETH in six minutes, reportedly paying up to 5% above market prices. At 21:06 UTC, Bubblemaps reported about $180 million moving from Bitget wallets to a common receiving address before being split across several wallets.

Those moves fit a familiar post-theft playbook: convert quickly, split funds, and make tracing harder. That does not prove who was behind it, but it does show the usual laundering instincts at work. Criminals rarely innovate when old habits still annoy investigators. The same kind of asset-hopping nonsense has shown up in other exchange incidents, including the ugly fallout from the DOJ’s watchful eye on Tether’s asset struggles.

Chen has also raised the possibility of North Korean involvement, but that remains suspicion, not proof. Onchain patterns can point to a familiar operational style, yet they do not identify a culprit by themselves. Wallet splitting, cross-chain movement, and asset swapping are evidence of obfuscation, not a signed confession.

Mandiant and SlowMist are investigating, and the biggest unanswered question remains how the attackers reached Bitget’s backend in the first place and bypassed the authorization controls. That is the sort of detail that determines whether this was a one-off failure, a design flaw, or something worse.

There is also a comparison being made to the February 2025 Bybit theft, where manipulated approvals, rapid asset conversion, wallet splitting, and use of THORChain showed up in the reporting. The resemblance is worth watching, but it should be treated as an analogy unless and until investigators can show the same attack chain was used here. Similar tactics do not automatically mean the same crew, the same infrastructure, or the same playbook.

The good news, such as it is, is that Bitget says its cold wallets were untouched. If that holds up, the damage was severe but not total. A backend compromise is still ugly as hell, but it is different from losing control of offline reserves. One is an operational catastrophe. The other is the kind of nightmare that keeps exchange teams awake for a very long time.

For readers trying to make sense of the jargon, even the word 改竄(カイザン)とは basically means tampering or falsifying data, which is exactly the kind of sleight of hand suspected here. And if you want a non-crypto example of how online infrastructure is supposed to stay resilient, the HOT Website is a good reminder that critical systems only work when the underlying trust model holds up under pressure. Apple’s own Wallet features and user experiences page is another useful contrast: convenience is nice, but the moment the approvals layer gets spoofed, convenience turns into a liability.

Bitget has also been busy elsewhere, pushing its AI-native universal exchange model and riding the broader tokenized stocks boom. Fine. Growth narratives are easy. Security is the adult in the room, and it has no patience for marketing fluff. Exchanges can chase every shiny new vertical they want, but if the backend is porous, all that innovation is just a prettier way to lose user funds.

Key questions and takeaways

  • Did Bitget confirm a breach?
    Yes. Bitget says it detected unauthorized transfers on September 24 and moved into emergency procedures within minutes.
  • How much was stolen?
    Bitget first estimated the loss at $351.6 million and later revised it to $387.5 million after including Zcash and TRON assets. Those are Bitget’s figures.
  • Were private keys stolen?
    Bitget says no. The company says the incident involved a backend compromise and fraudulent transfer approvals, not private-key theft.
  • Were cold wallets affected?
    Bitget says its cold wallets remained secure. The affected infrastructure was tied to hot and warm wallet operations.
  • Is North Korean involvement proven?
    No. It has been raised as a possibility, but it has not been independently identified or proven.
  • Can Bitget cover the loss?
    Bitget says its protection fund is large enough to cover the estimated damage. That is the company’s claim, not an independently verified guarantee.
  • What remains unknown?
    The exact entry point into the backend, which controls failed, who carried out the attack, and whether any of the funds can be recovered.

For users, the practical takeaway is simple: this was not just a wallet drain. It was a failure in the internal trust layer that governs how an exchange moves funds. That is a reminder that in crypto, security is not only about keys and chains. Sometimes the weakest link is the software that decides which transfers are “legitimate” in the first place.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog