Bitget Detected Hack 30 Minutes Before $290 Million Was Stolen
Exchange spotted breach before major funds moved
Crypto exchange Bitget detected unauthorized wallet transfers about 30 minutes before attackers began moving hundreds of millions of dollars. Blockchain data indicates the exchange flagged suspicious activity at 18:31 UTC on September 24, yet the largest thefts occurred afterward.
The total amount moved to attacker-controlled addresses reached $387.5 million. However, the majority of these funds left after the initial security alert was triggered.
Timeline of the $387.5 million loss
- At 18:31 UTC, Bitget systems flagged unauthorized transfers and activated emergency protocols.
- At 18:31, the attacker tested the compromised route with small transfers of 0.84 Ethereum (ETH) and 93 TRON (TRX).
- At 18:58, the attacker moved $34.75 million in Tether (USDT), a stablecoin pegged to the US dollar.
- At 19:01, a wave of $87.6 million left hot wallets (online storage for immediate transactions).
- At 19:16, a second wave of $202.8 million left warm wallets, occurring within nine seconds across five networks.
These two large bursts, which together totaled nearly $290 million, happened 30 and 45 minutes after the exchange's first alert.
How the attack bypassed security
Bitget stated that private keys were not stolen. Instead, the attacker compromised a backend system in the wallet infrastructure. This allowed them to spoof withdrawal data and trick the exchange's authorization process into approving the transfers.
Security firm Hypernative noted that the fraudulent transactions were signed by Bitget's own wallets. They looked very similar to standard customer withdrawals, allowing them to pass through the exchange's internal checks.
Missed opportunities to stop the drain
Hypernative identified several controls that could have stopped the attack after the initial alert. One suggestion was requiring every signed transfer to match an independently stored customer request. Another was checking transaction parameters, such as gas limits, against normal exchange standards.
The firm also pointed out that velocity limits could have helped. The second wave of $202.8 million moved across five blockchains in just nine seconds. Automatic suspensions triggered by unusual transfer speeds might have blocked this movement.
Why the delay in containment remains unclear
It is currently unknown why Bitget's security systems did not automatically suspend the compromised signing route after the 18:31 alert. The attacker continued to move funds until 21:23 UTC, almost three hours after the detection.
Bitget has stated that the vulnerability has been fixed and no further unauthorized transfers have occurred. Forensic investigations are ongoing with Mandiant and SlowMist.