Bitget Confirms $387.5 Million Security Breach as Revised On-Chain Accounting Reveals Wider Losses
Cryptocurrency

Bitget Confirms $387.5 Million Security Breach as Revised On-Chain Accounting Reveals Wider Losses

Bitget raises breach estimate to $387.5 million after on-chain tracing uncovers further transfers

Cryptocurrency exchange Bitget has revised the cost of a major security breach to approximately $387.5 million, up from an initial estimate of $351.6 million, after forensic tracing identified additional attacker transfers on the Zcash and TRON networks. The exchange stressed that the higher figure reflected a more complete accounting of the original incident rather than any fresh unauthorised activity.

The breach, which Bitget dated to 24 September 2026, saw assets moved to attacker-controlled addresses across multiple blockchain networks. Detection came at 18:31 UTC on a Thursday, according to reports, and the platform suspended withdrawals shortly afterwards. Bitget has since declared the incident contained, stating that no further unauthorised transfers are possible under current conditions.

The confirmed affected assets span a broad cross-section of the crypto market: XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX. Bitget’s support notice published receiving addresses controlled by the attackers on EVM-compatible chains, XRP, ZEC and TRON, giving blockchain analysts and competing platforms a concrete trail to monitor.

For more on how digital asset platforms handle major incidents, see our exchange security coverage.

A compromised backend, not a stolen key: inside the attack vector

The most consequential detail in Bitget’s disclosure is not the headline number but the mechanism. Chief executive Gracy Chen said the attackers compromised a critical backend system within the exchange’s wallet infrastructure, then used that access to spoof transaction data and manipulate the platform’s own authorisation process. In effect, the exchange’s internal controls approved the fraudulent transfers as if they were legitimate.

This distinguishes the incident from the more familiar pattern of private-key theft. There is no indication that wallet credentials were lifted directly. Instead, the attackers appears to have exploited the machinery that validates and signs transactions, turning the exchange’s trust architecture against itself. The incident struck parts of Bitget’s hot and warm wallet layers, the segments of an exchange’s infrastructure that are connected to the internet or semi-connected for operational liquidity. Bitget confirmed its cold wallets remained secure throughout.

The distinction matters enormously for the wider industry. Exchanges have spent years hardening cold storage, multi-signature arrangements and key custody. An attack that subverts backend authorisation systems rather than keys suggests a different class of threat, one aimed at the software layer where transactions are constructed, reviewed and approved. Social engineering, supply-chain compromise or insider access to backend systems become the relevant attack surfaces, and none of them are addressed by stronger key management alone.

Reports further indicated that Bitget and outside investigators suspect the attack pattern is consistent with North Korea-linked groups, which have a long documented history of targeting cryptocurrency exchanges and decentralised finance protocols. If that attribution holds as the investigation matures, the incident would join a long line of state-associated operations aimed at liquidity venues in the digital asset sector.

Response, containment and the recovery effort

Bitget has moved quickly on several fronts. The exchange said its protection fund covers the losses, a commitment intended to shield users from bearing the cost of the breach. It has also launched a fund tracing and recovery bounty programme, designed to enlist outside help in freezing and recovering the stolen assets across the chains involved.

The publication of attacker-controlled addresses is a deliberate part of that strategy. By flagging the receiving addresses on EVM networks, XRP, ZEC and TRON, Bitget has enabled other exchanges, stablecoin issuers and chain analytics firms to blacklist the funds at points where they attempt to cross into regulated or centralised venues. XRP and TRON-based USDT, in particular, have issuer-level freeze mechanisms that can be invoked if tainted funds reach issuing entities.

The choice of chains is itself telling. Zcash offers shielded transactions that obscure sender, recipient and amount, which complicates conventional tracing. The movement of stolen funds onto a privacy chain suggests the attackers anticipated pursuit and sought obscurity. TRON, by contrast, offers cheap and fast transfers with heavy stablecoin liquidity, useful for moving value quickly through mixing or bridging services.

Recovery prospects are realistic but partial. Historically, large exchange breaches recover only a fraction of stolen funds, with success hinging on how quickly assets are frozen at centralised off-ramps. Bounty programmes of the kind Bitget has announced tend to accelerate that process by widening the pool of parties watching the flows.

Follow developing stories on affected assets in our market coverage.

Market and regulatory implications

The immediate market question is confidence. An exchange breach approaching $400 million ranks among the largest in the industry’s history, and the fact that it bypassed authorisation controls rather than exploiting a key lapse will prompt uncomfortable questions at every major platform. Expect internal audits of backend transaction approval systems across the sector, and heightened scrutiny of the operational boundaries between hot, warm and cold wallet infrastructure.

For users, Bitget’s assertion that its protection fund absorbs the loss is the pivotal commitment. If client balances are restored in full and withdrawals resume promptly, the incident may prove survivable for the exchange, as several large breaches have been for rivals in past cycles. Any slippage on that promise, by contrast, would accelerate user attrition and invite regulatory intervention.

Regulators are likely to take a keen interest. The suspected North Korea link places the breach in a national security context as well as a consumer protection one, and financial authorities in major jurisdictions have increasingly treated exchange infrastructure failures as systemic touchpoints. The incident strengthens the case for mandated proof-of-reserves, segregated custody, and independent security audits of transaction authorisation systems, not merely of key storage.

There is also a competitive dimension. Exchanges with demonstrated cold storage discipline and transparent incident response will use the episode to market their controls, while decentralised venue advocates will point to the failure of centralised approval systems altogether. The debate between custodial convenience and self-custody security tends to reignite after every breach of this scale, and this one, with its backend spoofing vector, adds a new argument to the self-custody side: even well-managed keys are irrelevant if the system that approves transactions can be deceived.

Closing analysis

The Bitget breach is a landmark case study in the evolution of exchange security threats. The money involved, roughly $387.5 million at the revised count, is significant, but the attack’s shape is the real story. By compromising a backend system and spoofing transaction data until the exchange’s own authorisation process waved the transfers through, the attackers rendered traditional custody defences largely irrelevant. Cold wallets stayed safe, yet hundreds of millions still left the building.

The industry’s response will be watched closely. Bitget has committed its protection fund to the loss, published attacker addresses, launched a recovery bounty and declared the incident contained. Those are the right immediate steps. The harder work is architectural: rebuilding trust in authorisation systems, and proving to users and regulators alike that a spoofed approval can never again trigger a legitimate transfer of this magnitude. Until exchanges can make that case convincingly, the lesson of this breach will hang over the sector.

For ongoing coverage of this developing story, bookmark our security news section.

CN

CryptoGazette Newsroom

Crypto Reporter

CryptoGazette Newsroom is the lead news desk covering price action, on-chain analytics, regulation, DeFi protocols, NFTs, and institutional adoption across the cryptocurrency ecosystem. The Newsroom focuses on time-sensitive market-moving stories.