BREAKING
Sep 25Hackers Took $351.6M From Bitget Without Stealing a Single Private Key. They Forged the Transfer Orders and Bitget's Own Signing Machines Approved Them●Sep 24BitMEX Invented the 100x Perpetual Swap, Beat a Criminal Case With a Presidential Pardon, Then Lost to the Product It Created. Leave Money There Now and It Costs You $50 a Month●Sep 23Circle Pays Binance Every Month to Push USDC. Now Binance Owns $100M of Circle, and the Filing Landed the Same Day the Sanctions Probe Leaked●Sep 22Last Week Manhattan Prosecutors Moved to Seize $61M of Iranian Oil Money That Ran Through Binance. This Week They're Investigating Binance●Sep 21Polymarket's Payment Processor Was Rejecting 80% of US Deposits as Fraud. The CEO's Reported Answer: Keep Growing, Pay the Fine Later●Sep 20Robinhood Wallet Users Bought Dogwifhat With Credit Cards and Earned Cash Back, Because Visa Was Told They Were Buying E-Books●Sep 19The Senate Needed 60 Votes to Give Crypto a Rulebook and Got 49. The CFTC Needed Zero, and Just Filed One With the White House.●Sep 18The SEC Just Legalized Trading Apple Stock on Uniswap. The $3 Billion of Tokenized Stocks That Already Exist Don't Qualify.●Sep 17Two Robinhood Engineers Front-Ran Their Own Company's Token Listings on Hyperliquid. They Made $50K Each. They're Facing 30 Years.●Sep 16The Democrats Who Helped Write the CLARITY Act Just Voted to Kill It. 49-50. Crypto's Senate Bill Is Dead for 2026.●Sep 25Hackers Took $351.6M From Bitget Without Stealing a Single Private Key. They Forged the Transfer Orders and Bitget's Own Signing Machines Approved Them●Sep 24BitMEX Invented the 100x Perpetual Swap, Beat a Criminal Case With a Presidential Pardon, Then Lost to the Product It Created. Leave Money There Now and It Costs You $50 a Month●Sep 23Circle Pays Binance Every Month to Push USDC. Now Binance Owns $100M of Circle, and the Filing Landed the Same Day the Sanctions Probe Leaked●Sep 22Last Week Manhattan Prosecutors Moved to Seize $61M of Iranian Oil Money That Ran Through Binance. This Week They're Investigating Binance●Sep 21Polymarket's Payment Processor Was Rejecting 80% of US Deposits as Fraud. The CEO's Reported Answer: Keep Growing, Pay the Fine Later●Sep 20Robinhood Wallet Users Bought Dogwifhat With Credit Cards and Earned Cash Back, Because Visa Was Told They Were Buying E-Books●Sep 19The Senate Needed 60 Votes to Give Crypto a Rulebook and Got 49. The CFTC Needed Zero, and Just Filed One With the White House.●Sep 18The SEC Just Legalized Trading Apple Stock on Uniswap. The $3 Billion of Tokenized Stocks That Already Exist Don't Qualify.●Sep 17Two Robinhood Engineers Front-Ran Their Own Company's Token Listings on Hyperliquid. They Made $50K Each. They're Facing 30 Years.●Sep 16The Democrats Who Helped Write the CLARITY Act Just Voted to Kill It. 49-50. Crypto's Senate Bill Is Dead for 2026.●
BTC -- --%
ETH -- --%
Fear & Greed F&G 71 Greed
ESC
Type to search articles
Hackers Took $351.6M From Bitget Without Stealing a Single Private Key. They Forged the Transfer Orders and Bitget's Own Signing Machines Approved Them
BREAKING

Hackers Took $351.6M From Bitget Without Stealing a Single Private Key. They Forged the Transfer Orders and Bitget's Own Signing Machines Approved Them

The attackers who drained $351.6 million from Bitget last night didn’t need its private keys.

According to CEO Gracy Chen, they broke into a third-party tool the exchange uses every day, forged the transfer instructions, and sent them to Bitget’s own signing machines. The machines signed them.

Chen compared it to invoice fraud: the thieves didn’t forge the boss’s signature, they changed the bank details on the invoice the boss was about to sign.

That makes it the largest crypto hack of 2026 so far, and it pushes September’s reported hack losses above $684 million, the worst month of the year.

What Actually Happened

  • September 24, 18:31 UTC (02:31 Beijing time on the 25th): Bitget’s security systems detected unauthorized transfers out of some of its hot wallets.
  • Within minutes, the exchange activated its emergency response, flagged the receiving addresses, and notified law enforcement and blockchain security firms.
  • On-chain watchers saw it first. Arkham flagged unusual outflows, and analyst Emmett Gallic posted: “Looks like Bitget just got hacked for $178M.” Early estimates climbed from about $174M to $183M before Bitget confirmed the full $351.6 million.
  • Withdrawals are paused pending a security review. Deposits and trading are still running.

Chen said on X that there were “unauthorized transfers from some of our hot wallets” and that “Cold wallets remain fully secure.” Bitget uses a three-tier wallet setup, and only parts of the hot and warm layers were hit.

What Got Taken

According to on-chain breakdowns reported by investingLive and TokenPost:

  • ~102.9 million XRP, worth about $157.5 million, the largest single piece
  • 31,890 ETH, about $85.8 million
  • About $34.8M USDT, $21.1M USDC and $19.7M USDT0
  • Smaller amounts of Tether Gold, BNB, AVAX and TRX

The stablecoins didn’t stay stablecoins for long. The attacker swapped $19.7 million of USDT0 into roughly 7,111 ETH in about six minutes through UniswapX and 1inch Fusion, reportedly paying around 5% above market to do it. Losing 5% is cheap compared with having Tether freeze the whole balance. TechFlow noted that this “rapidly converting stablecoins into ETH” move is the same one used in the Bybit heist.

SlowMist says hacker-linked addresses on the XRP Ledger still hold about 103 million XRP across seven wallets.

Was It North Korea?

Probably, but it isn’t confirmed.

Chen said some IP addresses “closely match VPN patterns tied to a group associated with North Korea,” but stressed the identity “is not yet 100% confirmed.” She pointed to the February 2025 Bybit hack, which was attributed to North Korean state hackers.

Independent on-chain investigator Specter separately reported that after the stolen XRP was bridged across chains, its routing could be linked to funds from the AFX hack in July 2026, a roughly $24 million theft attributed to TraderTraitor, a Lazarus-linked cluster.

The playbook also fits. At Bybit in 2025, attackers compromised Safe{Wallet}‘s interface so that signers approved a transaction they couldn’t see properly. At Bitget, a compromised vendor tool forged the instructions and the exchange’s own signing infrastructure approved them. Neither attack cracked the cryptography. Both got in through a trusted tool that sits upstream of the signers.

No government agency has publicly attributed the Bitget hack yet.

Who Pays

Bitget says users don’t. “The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over US$464 million,” Chen said. She added that customer balances remain accurate and that the exchange has more than $1 billion in capital to handle withdrawal demand.

The protection fund exists for exactly this. But covering this loss uses up about three-quarters of it, and that has to be rebuilt before the next incident.

The BGB token fell roughly 3–5% as the news spread. Bitcoin barely moved.

Bitget has promised hourly updates and a full incident report, with root cause and corrective actions, within 24 hours. Xie Jiayin, head of Greater China, said an outside security team is running an independent forensic investigation, and that withdrawals will resume “once potential risks are eliminated.” No date has been given. Chen also said insider involvement “appeared unlikely,” but that “the final attack vector still requires further confirmation.”

The Uncomfortable Lesson

For years, exchange security meant protecting the keys: HSMs, MPC, multisig, cold storage. Bitget did all of that, and the keys still weren’t stolen.

The weak point was the question every signing system has to answer: is this a real transfer request? If a compromised internal or vendor tool can create a request that looks legitimate, perfect key custody doesn’t help. The signer just signs faster.

Bybit showed this in 2025, and Bitget has now shown it again at $351.6 million. Expect every major exchange to spend this week auditing which third-party tools can write to its wallet backend.

Why This Matters for Crypto Jobs

Exchange security budgets tend to grow right after big hacks, and this one is big. Here’s where the hiring is likely to go:

  • Supply-chain and vendor security is the hot specialty now. The attackers came in through a third-party tool, not Bitget’s core systems. Exchanges and custodians need people who can map every vendor with access to wallet infrastructure, lock down its permissions, and watch it continuously. If you’ve done third-party risk or software supply-chain security in TradFi or big tech, crypto teams want you.
  • Transaction verification engineers. The fix isn’t better key storage. It’s independent checks before signing: out-of-band confirmation, policy engines, allowlists, and anomaly detection that can stop a forged instruction before the HSM signs it. Engineers who can build a “second brain” for the signing path will be in demand.
  • On-chain forensics and incident response. Arkham, SlowMist, PeckShield, Hacken and independent investigators like Specter were tracing funds within hours. Exchanges, analytics firms and law enforcement all want investigators who can follow money through bridges, DEX aggregators and intent protocols like UniswapX and 1inch Fusion in real time.
  • Threat intel focused on the DPRK. If Lazarus is behind this, it’s the second nine-figure exchange hit tied to North Korea since Bybit’s $1.5 billion loss. Analysts who track TraderTraitor-style infrastructure, VPN fingerprints and laundering patterns are among the hardest security hires to find.
  • Treasury and risk roles. The protection fund just lost about 75% of its value and has to be refilled. Someone has to size these reserves, manage what they’re held in, and explain the numbers to regulators. That’s a growing niche that combines treasury, actuarial and risk work.

Every big hack is a bad day for an exchange and a busy hiring period for the security industry. Browse the latest crypto and Web3 jobs on Cryptogrind to find security engineering, incident response, on-chain forensics and risk roles at the teams trying to prevent the next one.

How did this hit?

Discussion

Comments are powered by GitHub. Sign in with your GitHub account to chime in.

Related jobs on Cryptogrind

View all

Looking for your next crypto role?

Browse hundreds of Web3 and crypto positions on Cryptogrind — from smart contract engineers to DeFi analysts.

Browse jobs