Skip to content

Leadership1 publisher3 min readPublished

Bitget says spoofed backend data drained $351.6 million from its hot and warm wallets

Bitget lost about $351.6 million from its hot and warm wallets after attackers spoofed transaction data in a backend system, the exchange said. Cold storage held and a $464 million fund covers the loss, while about 45% of the haul is native XRP that no one can freeze.

The Board Room · Leadership desk

Illustration accompanying Bitget says spoofed backend data drained $351.6 million from its hot and warm wallets

What happened

  • Bitget detected unauthorized transfers from parts of its hot and warm wallets at 18:31 UTC on Sept. 24 and put the damage at about $351.6 million.
  • The exchange said attackers had broken into a critical backend system in its wallet infrastructure and spoofed transaction data to push the funds out.
  • XRP was the largest slice, 102.93 million coins worth $157.48 million, alongside 31,890 ETH and roughly $75 million in stablecoins.
  • By Sept. 25 only about 400,000 XRP had left the five wallets holding the stolen coins, and four of those wallets had not moved at all.
  • Bitget said its User Protection Fund holds more than $464 million and covers the full estimated loss, with customer balances unaffected.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • constraint About 45% of the loss is out of reach of any issuer freeze, so getting it back depends on exchanges and swap services refusing the coins when they surface.
  • cost Bitget's own balance sheet absorbs the loss with about $112 million of headroom, and because the fund is held in bitcoin, that margin shrinks if BTC falls.
  • decision Cold tiering bounded the loss, so exchanges now have to decide how backend instructions are verified before hot and warm wallets sign them, and how much float sits behind that check.
  • exposure Bridgers and other swap desks sit on the cash-out path for about 102.6 million untouched XRP, so their screening is now part of whether Bitget recovers anything.

The board-deck version of the Bitget incident is short: cold storage held, customer balances are accurate and the protection fund is larger than the hole [2][12]. Withdrawals are paused while deposits and trading continue [14]. All of that is true. Bitget's three-tier wallet design did keep the damage to portions of the hot and warm layers [2].

That version leaves out where Bitget places the failure. By the exchange's account, the attackers did not have to break a wallet. They had to get into the backend that feeds the wallets their transaction data, and falsify it [3]. In its first notice, Bitget declined to speculate on the attack vector and promised a report covering root cause and corrective measures [15]. The account published so far does not explain how the spoofed data cleared whatever approval checks sit between that backend and the signing step [3][15].

A skeptic would say the controls worked, since the cold tier held and the fund covers the loss. The tiering confined the loss to two layers, and those layers still gave up about $351.6 million [1]. The fund's margin over that estimate is about $112 million [1]. Bitcoin.com News reports the fund holds 5,500 BTC [13], so its dollar value moves with bitcoin. At roughly $63,900 a coin, it would only equal the loss estimate [3]. The stolen assets are XRP, ETH and stablecoins, so the cost of replacing them moves too [4].

Recovery depends on the asset. Chen said Bitget has contacted foundations on every affected chain and that a few have "already frozen the hacker's wallet addresses" [8]. Freezes of that kind work for tokens with an issuer behind them, such as USDT or USDC [9]. The XRP Ledger's freeze tools apply only to issued tokens, not to XRP itself [7]. XRP worth $157.48 million is about 45% of the estimated loss [4][2]. For that share, according to Bitcoin.com News, the only chokepoints left are the exchanges and bridges the attacker has to pass through to cash out [10]. Onchain analyst Yfarmx saw 33,500 XRP move through the Bridgers swap service on Sept. 25 and called it "a test run before a bigger cash-out" [11].

This week's question is whether the roughly 102.6 million XRP still sitting in the attacker's wallets starts to move [4]. I think attribution matters more to investigators than to operators. Chen said IP behavioral patterns and onchain signatures are "consistent with techniques used by DPRK-linked hacker groups," while stressing that the attacker's identity is not confirmed [16]. Analyst Specter's link to July's roughly $24 million AFX theft runs through a single Ethereum wallet holding about $4,300 [17]. Blockaid has attributed roughly $609 million of first-half 2026 losses to the Trader Traitor cluster, which it ties to the Lazarus Group [18].

In my view the control point for an exchange is the approval and verification layer between internal systems and the signers. Custody still did its part by bounding the loss. This quarter's decision is whether signers check each instruction against a record the backend cannot alter, and how much float sits behind that check. Next quarter's consequence comes from the XRP. Funds held in a native asset with no freeze function can be stopped only at the exchanges and bridges the attacker chooses for the cash-out [7][10].

What to watch

  • Bitget's full incident report, and whether it explains how spoofed transaction data passed approval before the hot and warm wallets signed.
  • Movement from the four untouched 20 million XRP wallets through Bridgers or other swap desks, and whether those services hold the funds.
  • Whether Bitget reopens withdrawals, and how the bitcoin-held fund's dollar value compares with the loss when it pays out.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories