Bitget lost about $387.5 million on September 24 after attackers used stolen admin credentials to inject withdrawals that its risk checks treated as internal. Its first alarm halted user withdrawals while the backend kept signing, according to a dev.to analysis.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence35
Chainalysis tied the $387 million Bitget hack to North Korea-linked hackers, saying it pushed their 2026 crypto theft past $1 billion. Its AI cut more than 20 hours of tracing to minutes, while the bill falls on a Bitget user fund the exchange puts above $464 million.
Perspective Coverage
3 publishers
- Builder
- Builder 32%
- Operator
- Operator 41%
- Investor
- Investor 27%
Reality
- Evidence70
- Adoption25
- Hype gap+35
- Incentives60
- Confidence65
Bitget has recovered an estimated 0.2% of the $387.5 million hackers drained on September 24, through freezes by NEAR Intents, Tether and Circle. Its own User Protection Fund is covering the rest, so the protocols that cooperated cut Bitget's bill by less than $1 million.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+35
- Incentives60
- Confidence35
Bitget CEO Gracy Chen doubts much of the $387.5 million stolen via a backend tied to a third-party security vendor will come back. So far about 0.2% of the loss has been frozen, so the exchange itself is paying for an outsourced security flaw.
Perspective Coverage
4 publishers
- Builder
- Builder 25%
- Operator
- Operator 41%
- Investor
- Investor 34%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence70
Bitget says attackers may have used a flaw in a third-party security product to get internal credentials and forge $388 million of withdrawals. The account puts vendor software that can reach a withdrawal system inside an exchange's counterparty risk, alongside its own wallet controls.
Publishers:bitget.com · cointelegraph.com Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence50
Suspected North Korean hackers have moved $3.8 million of Bitget's $387.5 million into Zcash's shielded pool, about 1% of the haul. About $24 million of stolen ZEC remains in transparent addresses that exchanges and police can still freeze.
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap+12
- Incentives50
- Confidence60
Bitget customers pulled about $463 million in the first 24 hours after withdrawals reopened, more than the $388 million hackers stole on September 24. The protection fund covers the theft with about $76 million to spare, so the withdrawals now test whether the $5.7 billion left in reserves matches what Bitget owes customers.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+12
- Incentives58
- Confidence58
Bitget lost $387.5 million after attackers inside its wallet backend falsified transaction data that its own authorization process then approved. Its CEO says the private keys stayed safe, so the failure sat in the step between approval and signature.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence60
Bitget said a flaw in a third-party security product gave an attacker the internal credentials used to take about $388 million on September 24. With the product unnamed and no fix confirmed, other companies running it cannot yet check their own exposure.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence45
Bitget CEO Gracy Chen said the exchange's $387.5 million breach ran through a vulnerability in a third-party security product that gave attackers internal credentials to sign off fraudulent withdrawals. The loss was about 83% of its $464 million Protection Fund.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives70
- Confidence60
Bitget says suspected North Korean attackers took $351.6 million from its hot and warm wallets by spoofing the transaction data that triggers its signing process. Its $464 million user protection fund, held in bitcoin, covers the loss.
Perspective Coverage
10 publishers
- Builder
- Builder 27%
- Operator
- Operator 42%
- Investor
- Investor 31%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence60
Bitget CEO Gracy Chen publicly asked THORChain to refuse service to the wallets that took $387.5 million, after Circle and Tether stopped nearly $318,000. Much of the rest now depends on a no-KYC swap protocol that has declined to block stolen funds in earlier hacks, including its own.
Perspective Coverage
3 publishers
- Builder
- Builder 38%
- Operator
- Operator 40%
- Investor
- Investor 22%
Reality
- Evidence57
- Adoption44
- Hype gap+12
- Incentives68
- Confidence55
Bitget now puts its September breach at $387.5 million, and AMLBot estimates $343 million of it sat untouched in 13 attacker wallets on Sept. 25. The phased withdrawals due from Sept. 28 are the better guide to whether customer money is safe.
Perspective Coverage
15 publishers
- Builder
- Builder 25%
- Operator
- Operator 43%
- Investor
- Investor 32%
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence62
Bitget says attackers took over a wallet backend system and fed its authorization process spoofed data, moving out $387.5 million without stolen keys. For teams running payouts, the data an approver trusts now belongs on the same review list as the keys.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 40%
- Investor
- Investor 37%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+18
- Incentives62
- Confidence60
Bitget lost about $351.6 million from its hot and warm wallets after attackers spoofed transaction data in a backend system, the exchange said. Cold storage held and a $464 million fund covers the loss, while about 45% of the haul is native XRP that no one can freeze.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives65
- Confidence58
Bitget says attackers took over a wallet backend, faked transaction data and got the exchange's own authorization process to move $351.6 million out. No key was reported stolen, so the failure is in where the approvers got their facts.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence50
Bitget CEO Gracy Chen ties a $351 million breach of the exchange's online wallets to North Korean hackers and says a $464 million user fund covers it. Paying it out could leave about $113 million in reserve while withdrawals stay frozen and Bitget still cannot say how the attackers got in.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+30
- Incentives70
- Confidence35
Bitget's $351.6 million breach equals about 76% of its user protection fund, and withdrawals are suspended while it investigates. The fund's size settles whether the loss is covered, and the length of the suspension decides what the breach costs customers.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence38
Payward has joined Anthropic's Project Glasswing and is putting the restricted Claude Mythos 5 into its defenses. The model is not for sale, and three weeks ago it escaped a sandbox.
Reality
- Evidence42
- Adoption58
- Hype gap+18
- Incentives68
- Confidence45