Skip to main content
    SpinDepth
    SpinDepth
    News

    How hackers took 388 million dollars from Bitget without touching a private key

    By SpinDepth · Market Authority desk

    7 min read
    How hackers took 388 million dollars from Bitget without touching a private key

    At 6:31 pm UTC on 24 September, an attacker moved 0.184 ETH out of a Bitget hot wallet on Ethereum and 193 TRX out of another on Tron. They were test transfers, tiny enough to look like noise. Half an hour later the real theft began. By the time Bitget suspended withdrawals, an estimated 387.5 million dollars had left its hot wallets, making it the largest crypto hack of 2026 so far and one of the ten largest ever recorded. The most unsettling detail is what the attackers did not need. They never obtained Bitget's private keys, and its cold wallets were untouched.

    The attack went through a supplier

    According to BleepingComputer's report, the attackers exploited a zero-day vulnerability in third-party security products that Bitget used inside its backend. A zero-day is a flaw the software vendor does not yet know about, so no patch exists. Through it, the attackers obtained credentials that let them issue withdrawal commands that Bitget's own systems treated as legitimate, spoofing on-chain transactions from the exchange's hot wallets.

    That is a different category of failure from the hacks that dominated earlier years, where keys were stolen, multisig signers were phished or smart contracts were drained. Here the cryptography held. The weak point was the software layer that decides whether a withdrawal should be sent at all. If that layer can be convinced, the keys simply sign what they are told.

    Bitget chief executive Gracy Chen told The Block the attacker deliberately probed the exchange's risk controls with the small transfers before launching the main theft. That sequence suggests a patient, well-resourced team that had studied how Bitget's monitoring worked and wanted to confirm the path was clear before committing.

    It also explains why the theft was so fast. Once the attackers could issue commands that looked authorised, they did not need to wait for signers or break encryption. The exchange's own automated systems did the work for them, moving funds out of hot wallets as if they were ordinary client withdrawals. That is the nightmare scenario for any platform that has automated withdrawals to give clients faster service.

    Network cabling inside a data centre
    Two small test transfers preceded the main theft by about half an hour

    Why investigators point to North Korea

    Security researchers have attributed the attack to North Korea's Lazarus Group, based on the way stolen assets were rapidly converted, the IP addresses involved and transfers to wallets linked to earlier hacks. Lazarus has been behind many of the largest crypto thefts of the past decade, and its methods have shifted from crude phishing toward supply-chain attacks that compromise trusted software used by many targets at once.

    That shift is the part every exchange should worry about. If the same third-party product is used elsewhere, the vulnerability that opened Bitget may open others until the vendor patches it and every customer applies the fix. Supply-chain attacks scale in a way single-target attacks do not, which is why they have become the preferred route for state-backed groups.

    Attribution also matters for recovery. Funds that flow to Lazarus-linked wallets are typically laundered quickly through mixers, cross-chain bridges and over-the-counter desks. Bitget has offered a 5 percent bounty for freezing attacker funds and another 5 percent for recovery, but history suggests most stolen value in hacks of this type is never returned.

    For the wider industry, the attribution has one more implication. Exchanges that process funds traced to Lazarus can face sanctions exposure, which is why compliance teams across the sector will be screening incoming deposits against the wallets linked to the Bitget theft. That screening can delay legitimate transfers for days, so even exchanges with no connection to the hack may feel its effects through slower deposits and more client complaints.

    • Estimated loss: about 387.5 million dollars from hot wallets
    • Entry point: zero-day vulnerability in third-party security products
    • Keys and cold wallets: not compromised, according to Bitget
    • Attribution: North Korea's Lazarus Group, per security researchers
    • Bounty: 5 percent for freezing funds and 5 percent for recovery

    Does the protection fund really cover it?

    Bitget says the full loss will be covered by its User Protection Fund, which it valued at about 464 million dollars, and it resumed withdrawals from 28 September. On those numbers clients should be made whole. The harder question, raised in coverage by Finance Magnates and others, is what is left afterwards. A full payout could consume around 84 percent of the fund, leaving roughly 76.5 million dollars, well below the 300 million dollar minimum Bitget had publicly committed to maintain.

    That gap will have to be refilled, and the fund's value itself depends partly on the price of the assets it holds. Protection funds are a genuine improvement on the era when hacked exchanges simply froze accounts, but they are only as strong as their size relative to the next incident. Clients now know the fund can be nearly emptied by a single attack.

    The episode lands in a brutal period for the exchange sector. BitMEX, CoinEx and BitMart all shut within two months, citing falling volumes and rising compliance costs, a trend we covered in our look at CoinEx's closure. Exchanges that survive are being asked to prove both solvency and security at the same time, and Bitget has just been tested on both in a single week.

    There is a broader point about how exchanges communicate. Bitget moved quickly to publish details, name the attack vector and confirm the fund would cover losses, and its chief executive spoke publicly within days. That transparency is one reason withdrawals could resume quickly without a run. Exchanges that respond to incidents with silence or vague statements tend to suffer far larger outflows than the hack itself would justify.

    Cryptocurrency security concept image
    A full payout could use about 84 percent of the protection fund

    The cryptography held. The weak point was the software that decides whether a withdrawal should be sent at all.


    What exchanges and brokers should check this week

    The practical lesson is that withdrawal authorisation is now the crown jewel, not just key storage. Firms should inventory every third-party tool that sits in the path of a withdrawal decision, confirm which versions they run, and demand disclosure from vendors about whether the affected products are in their stack. Rate limits and anomaly alerts on hot wallets should be tuned to catch exactly the pattern Bitget saw: small test transactions followed by a burst.

    For forex and CFD brokers that accept crypto deposits, the same logic applies to payment and treasury tooling. Any system that can instruct funds to move is a target. The firms that tell clients clearly what they have checked, rather than issuing a generic statement about security, will hold trust better when the next breach makes headlines.

    Boards should also ask a blunt question: how much could leave our hot wallets in thirty minutes if every automated control trusted a forged instruction? Many firms have never calculated that number. Setting hard caps on how much can move from hot wallets per hour, with human approval above that line, slows withdrawals slightly for large clients but limits the worst case to a level the business can survive. Bitget's experience suggests that trade-off is now worth making.

    What clients should take from it

    For individual traders the lesson is old but newly urgent: assets held on any exchange carry the exchange's operational risk. Keeping only trading balances on a platform, using withdrawal address whitelists and checking a platform's published proof of reserves and protection fund size are simple habits that limit exposure. A protection fund that covers a hack is reassuring. Not needing it is better.

    How much was stolen from Bitget?

    An estimated 387.5 million dollars was taken from Bitget's hot wallets on 24 September 2026, the largest crypto hack of the year so far.

    How did the Bitget hack happen?

    Attackers exploited a zero-day vulnerability in third-party security products to obtain credentials and issue fraudulent withdrawal commands. Bitget says its private keys and cold wallets were not compromised.

    Who was behind the attack?

    Security researchers attributed it to North Korea's Lazarus Group, based on laundering patterns, IP addresses and links to wallets used in earlier hacks.

    Will Bitget users lose money?

    Bitget says its User Protection Fund, valued at about 464 million dollars, will cover the full loss, and withdrawals resumed from 28 September.

    The Bitget hack will be remembered less for its size than for its method. It showed that an exchange can protect its keys perfectly and still lose hundreds of millions of dollars if a trusted vendor's software is compromised. That moves the security debate from vaults to workflows, and it puts every exchange, broker and payment firm that relies on third-party tools on notice. The next attack will not look for the strongest lock. It will look for the most trusted supplier. The firms that audit their vendors this month, rather than after their own incident, will be the ones clients still trust when the next headline lands.

    Speak with the SpinDepth desk
    Share this story