Skip to content

Invest1 publisher3 min readPublished

Bitget's attacker pulls $1.23 million out of Binance into a wallet linked to the hack

Bitget's attacker withdrew $1.23 million from Binance into a wallet linked to a breach now put at up to $387.5 million. For Bitget customers the exposure stays with Bitget, whose $464 million protection fund covers the loss with at least $76.5 million to spare.

The Investor · Invest desk

Illustration accompanying Bitget's attacker pulls $1.23 million out of Binance into a wallet linked to the hack

What happened

  • Bitget detected a breach at 18:31 UTC on September 24 that moved up to $387.5 million out of its hot and warm wallets without authorization.
  • The attacker compromised Bitget's backend and spoofed transaction data so forged transfers looked legitimate internally, without stealing private keys or breaching cold storage.
  • On September 25, on-chain analysis showed five separate withdrawals from Binance hot wallets, three of them between roughly 80 and 90 ETH each.
  • Bitget paused withdrawals and pledged to cover customer losses from its User Protection Fund, which holds over $464 million.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost Covering this one breach commits about 83.5% of Bitget's User Protection Fund, leaving at least $76.5 million for any other claim.
  • exposure The first loss estimate has already proved about 10% too low, and another upward revision of about 19.7% would leave losses the pledged fund cannot cover.
  • constraint Once stolen funds leave Binance for an attacker-linked wallet, cooperation between Bitget and Binance can only freeze money still sitting on an exchange.

Crypto Briefing describes the Binance leg as withdrawals from Binance's own hot wallets, forwarded to a wallet linked to the hack [2][3]. The report does not say how the attacker's money got onto Binance, and it does not report any loss of Binance's own funds. On this evidence the hot wallets that failed were Bitget's, since the unauthorized transfers came out of its hot and warm wallets [1]. Binance is a route out.

The sums on that route are small. The three itemised ETH withdrawals of September 25 add up to 257.64 ETH [1]. The report counts five withdrawals but itemises only four, the fourth being about $545,000 in USDT [3]. By September 26 the presumed attacker wallet had received 457.9 ETH [4], roughly 200 ETH more than the itemised pieces account for [2]. The latest $1.23 million is about 0.32% of the $387.5 million [3].

The larger number has already moved once. Investigators first put the loss at $351.6 million and raised it to $387.5 million as they found more unauthorized transfers [9], an increase of $35.9 million, or about 10.2% [4]. The forged transfers looked legitimate to Bitget's own systems [8]. A loss like that gets sized by audit, after the fact.

Bitget's pledge commits about 83.5% of a fund stated at over $464 million [6], leaving a cushion of at least $76.5 million [5]. Before the revision the cushion was $112.4 million [8]. While withdrawals stay paused [10], customers cannot reduce their exposure to Bitget. Bitget, for its part, cannot put most of that reserve to any other use.

From here the cash can go three ways. If $387.5 million is the final figure, the fund pays and customers are made whole. If the estimate rises again, a second revision the size of the first leaves $40.6 million [10], and a rise of about 19.7% uses up the fund entirely [7]. The third path is that tracing across Ethereum, BNB Chain and TRON [6], with Mandiant and SlowMist assisting [7], recovers enough to shrink the net bill. The report names two obstacles to recovery. The attacker's pattern ends in a wallet outside the reach of any single platform's freeze [5]. And according to Crypto Briefing, IP address patterns have prompted speculation, not confirmed by authorities, that North Korean-linked actors are responsible [11].

I think the second path deserves the most weight. The cushion covers about 2.1 revisions the size of the first [9], and that first revision came from finding more of the same unauthorized transfers [9]. The counter-case is that a backend spoof leaves a finite set of forged transfers, and once investigators have matched every one, $387.5 million is final. A closing figure at or below that number would prove this view wrong. So would a report that Binance lost funds of its own, because its hot wallets would then be part of the loss.

What to watch

  • Any further revision to the $387.5 million loss figure; above roughly $464 million the protection fund no longer covers it.
  • Whether Bitget or Binance reports freezing funds in the attacker-linked wallets, or any loss of Binance's own funds.
  • Bitget's timetable for reopening withdrawals and paying claims out of the User Protection Fund.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories