Bitget Detected Hack 30 Minutes Before $290 Million Was Stolen

Bitget Detected Hack 30 Minutes Before $290 Million Was Stolen

Exchange spotted breach before major funds moved

Crypto exchange Bitget detected unauthorized wallet transfers about 30 minutes before attackers began moving hundreds of millions of dollars. Blockchain data indicates the exchange flagged suspicious activity at 18:31 UTC on September 24, yet the largest thefts occurred afterward.

The total amount moved to attacker-controlled addresses reached $387.5 million. However, the majority of these funds left after the initial security alert was triggered.

Timeline of the $387.5 million loss

  • At 18:31 UTC, Bitget systems flagged unauthorized transfers and activated emergency protocols.
  • At 18:31, the attacker tested the compromised route with small transfers of 0.84 Ethereum (ETH) and 93 TRON (TRX).
  • At 18:58, the attacker moved $34.75 million in Tether (USDT), a stablecoin pegged to the US dollar.
  • At 19:01, a wave of $87.6 million left hot wallets (online storage for immediate transactions).
  • At 19:16, a second wave of $202.8 million left warm wallets, occurring within nine seconds across five networks.

These two large bursts, which together totaled nearly $290 million, happened 30 and 45 minutes after the exchange's first alert.

How the attack bypassed security

Bitget stated that private keys were not stolen. Instead, the attacker compromised a backend system in the wallet infrastructure. This allowed them to spoof withdrawal data and trick the exchange's authorization process into approving the transfers.

Security firm Hypernative noted that the fraudulent transactions were signed by Bitget's own wallets. They looked very similar to standard customer withdrawals, allowing them to pass through the exchange's internal checks.

Missed opportunities to stop the drain

Hypernative identified several controls that could have stopped the attack after the initial alert. One suggestion was requiring every signed transfer to match an independently stored customer request. Another was checking transaction parameters, such as gas limits, against normal exchange standards.

The firm also pointed out that velocity limits could have helped. The second wave of $202.8 million moved across five blockchains in just nine seconds. Automatic suspensions triggered by unusual transfer speeds might have blocked this movement.

Why the delay in containment remains unclear

It is currently unknown why Bitget's security systems did not automatically suspend the compromised signing route after the 18:31 alert. The attacker continued to move funds until 21:23 UTC, almost three hours after the detection.

Bitget has stated that the vulnerability has been fixed and no further unauthorized transfers have occurred. Forensic investigations are ongoing with Mandiant and SlowMist.

Where to find more details

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!