Bitget hacked: $228 million stolen in just 18 minutes
Summarize this article with:

The Bitget hack ultimately affected approximately $387.5 million in assets, compared to an initial on-chain estimate of $228 million. The platform claims to have contained the attack, but is keeping withdrawals suspended during its security checks.

A hacker carries out a crypto heist on several exchanges including Bitget.

In brief

  • Bitget hack ultimately reaches $387.5 million.
  • Withdrawals remain suspended during security checks.
  • The attack allegedly exploited a critical backend system, without theft of private keys.
  • Bitget’s protection fund must be used to cover losses.
  • A portion of the stolen assets has already been converted into ETH.

Bitget hack exceeds initial estimates

Early alerts released by Arkham and other analysts about the hack reported approximately $228 million transferred in just 18 minutes. This data focused mainly on immediately identifiable movements across seven networks.

Bitget first announced losses of $351.6 million. On September 25, the platform raised this amount to $387.5 million after integrating transfers made on Zcash and Tron. This revision does not correspond to new fraudulent withdrawals, according to the company.

Your first cryptos with Bitget
This link uses an affiliate program

The main confirmed elements show the scale of the incident:

  • The unauthorized transfers began on September 24;
  • The total amount now reaches approximately $387.5 million;
  • The first analyzes followed seven blockchains, to which were added Zcash and Tron;
  • Affected assets include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX;
  • The platform’s cold wallets would not have been affected.

The new balance sheet may still evolve as transactions are classified. Bitget specifies, however, that no new unauthorized movements have been recorded since the incident was contained.

An internal system would have validated false transfers

According to Gracy Chen, CEO of Bitget, the hacker compromised a critical component of the system responsible for managing the exchange’s wallets. He then allegedly falsified transaction data to trigger the internal authorization process.

“The hacker compromised a critical backend system and triggered our authorization process to move funds”has declared Grace Chen. The investigation is still determining how the initial intrusion was carried out.

Bitget claims that the private keys have not been compromised. This clarification suggests that the attack does not directly result from the theft of a key allowing transactions to be freely signed. Rather, it would have exploited the infrastructure responsible for preparing and approving transfers.

The platform had distributed the funds between hot, warm and cold wallets. This hack would have affected part of the first two categories, regularly connected to the exchange’s services. The separate Bitget Wallet product, which operates in self-custody on another infrastructure, was not affected.

The protection fund must cover losses

Bitget ensures that balances displayed on accounts remain accurate. Deposits and trading operations are still functioning, but withdrawals remain suspended until checks are completed.

The platform claims that its protection fund exceeds $464 million. This reserve would exceed the currently identified amount by approximately $76.5 million, a margin close to 20%. Its value may vary, however, since a significant portion of the fund is held in bitcoin.

This cover remains a statement by Bitget. It means that the company plans to absorb the losses without passing them on to its customers, but the actual reimbursement will depend on the final balance sheet and the available liquidity.

The hacker has already converted part of the assets from networks compatible with Ethereum. Lookonchain estimates that 67,982 ETH, valued at around $183 million, were obtained after several exchanges. These conversions complicate the freezing of tokens, without making their on-chain tracking impossible.

Bitget launches bounty to recover assets

Bitget works with Mandiant, SlowMist, authorities and several ecosystem players. Some assets have reportedly already been frozen with the help of platforms, stablecoin issuers and blockchain projects.

The exchange offers a bonus equivalent to 5% of funds frozen or recovered through an eligible voluntary intervention. It also provides a tracking table for addresses controlled by the hacker.

The company must announce the schedule for resuming withdrawals no later than September 26. The vulnerability has reportedly been fixed, but teams are continuing testing before reopening the service.

Gracy Chen tentatively attributes the operation to North Korean hackers, based on the IP addresses and methods observed. This attribution remains Bitget’s and has not yet been publicly confirmed by an independent authority.

Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.

Similar Posts