Skip to content

Invest12 publishers2 min readPublished Updated

Bitget's preliminary probe blames a backend wallet service for its $351.6 million loss

Bitget's preliminary probe traces a $351.6 million loss to false transfer data fed into its signing approvals, and says no private keys leaked. If the promised root-cause report confirms that, depositors' risk sits in the exchange's backend, because the keys and cold wallets held.

The Investor · Invest desk

Illustration accompanying Bitget's preliminary probe blames a backend wallet service for its $351.6 million loss

What happened

  • Bitget's systems caught unauthorized transfers leaving some hot wallets at 18:31 UTC on September 24, and the exchange now puts the loss at $387.5 million.
  • Chief executive Gracy Chen said attackers broke into a backend wallet system and spoofed transaction data so Bitget's own authorization process approved the payouts.
  • The largest single piece of the haul was about 103 million XRP worth roughly $157 million, and the assets moved across at least five blockchains.
  • Chen said Bitget's User Protection Fund, which holds more than $464 million, will cover the full loss and customer account balances stay intact.
  • Deposits and trading kept running through the incident while withdrawals were frozen as a precaution.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost Bitget's own reserve pays for this hack, and making customers whole takes up to about 84% of the fund's balance.
  • exposure Counterparties that judged exchange risk by how keys are stored were exposed anyway. By Chen's account, the weak point was the transaction data Bitget's approval process accepted as genuine.
  • constraint Until withdrawals reopen, customers hold balances they cannot move, so the fund's promise has not yet been tested against real payout demand.

A freshly created wallet spent $19.67 million in USDT0 on 7,111 ETH in six minutes, according to the pseudonymous researcher DCF GOD, who flagged it before Bitget had confirmed anything [7]. It paid roughly 5% above market through UniswapX and 1inch Fusion [7]. That works out to about $2,766 per ETH [3], and a premium of roughly $940,000 for the speed [4].

"They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet," chief executive Gracy Chen said [5]. Her version is preliminary. Chen wrote that the investigation with Mandiant and SlowMist is ongoing and that thorough forensic analysis takes more than 24 hours [14].

If her account holds, I think the diligence question for anyone with balances at an exchange is what the signing system checks before it approves a transfer. The follow-up is whether a compromised internal system can feed that check false data, as Chen says happened here [6]. The view fails if the forensics turn up a stolen credential or key. Bitget would then be an ordinary custody failure. It is incomplete if the loss keeps growing, as it already has, from roughly $183 million in the first hour to $351.6 million when Bitget went public and $387.5 million a day later [3][4]. For users, the reserve matters more than the method, since Chen says their balances stay whole either way [10].

The cost falls on that reserve. Paying $387.5 million out of a fund of more than $464 million leaves at least $76.5 million [1]. That is about a quarter of the $300 million the fund held in 2023, when it was set aside to cover hacks and theft [12][6]. The source does not say what assets the fund holds. The $387.5 million is itself a market valuation, and about 40% of it is the XRP position [5], so the dollar cost of replacing the stolen coins moves with one token's price.

Chen has been careful on attribution. "We've identified some IP addresses that match the VPN choices by a certain DPRK group," she said, adding that "the pattern looks very much like what the North Korean team did before" [13]. She stressed that the attacker's identity has not been confirmed [13]. In the Bybit case, a $1.4 billion loss in February 2025, the FBI confirmed North Korean involvement weeks later [15].

What to watch

  • When Bitget reopens withdrawals, and whether outflows clear at normal speed against balances the fund has promised to back.
  • Whether Bitget publishes a plan and timetable for refilling the protection fund after the payout.
  • Any official attribution from the law enforcement agencies Bitget says are now investigating.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories