Hackers Took $351.6M From Bitget Without Stealing a Single Private Key. They Forged the Transfer Orders and Bitget's Own Signing Machines Approved Them
The attackers who drained $351.6 million from Bitget last night didn’t need its private keys.
According to CEO Gracy Chen, they broke into a third-party tool the exchange uses every day, forged the transfer instructions, and sent them to Bitget’s own signing machines. The machines signed them.
Chen compared it to invoice fraud: the thieves didn’t forge the boss’s signature, they changed the bank details on the invoice the boss was about to sign.
That makes it the largest crypto hack of 2026 so far, and it pushes September’s reported hack losses above $684 million, the worst month of the year.
What Actually Happened
- September 24, 18:31 UTC (02:31 Beijing time on the 25th): Bitget’s security systems detected unauthorized transfers out of some of its hot wallets.
- Within minutes, the exchange activated its emergency response, flagged the receiving addresses, and notified law enforcement and blockchain security firms.
- On-chain watchers saw it first. Arkham flagged unusual outflows, and analyst Emmett Gallic posted: “Looks like Bitget just got hacked for $178M.” Early estimates climbed from about $174M to $183M before Bitget confirmed the full $351.6 million.
- Withdrawals are paused pending a security review. Deposits and trading are still running.
Chen said on X that there were “unauthorized transfers from some of our hot wallets” and that “Cold wallets remain fully secure.” Bitget uses a three-tier wallet setup, and only parts of the hot and warm layers were hit.
What Got Taken
According to on-chain breakdowns reported by investingLive and TokenPost:
- ~102.9 million XRP, worth about $157.5 million, the largest single piece
- 31,890 ETH, about $85.8 million
- About $34.8M USDT, $21.1M USDC and $19.7M USDT0
- Smaller amounts of Tether Gold, BNB, AVAX and TRX
The stablecoins didn’t stay stablecoins for long. The attacker swapped $19.7 million of USDT0 into roughly 7,111 ETH in about six minutes through UniswapX and 1inch Fusion, reportedly paying around 5% above market to do it. Losing 5% is cheap compared with having Tether freeze the whole balance. TechFlow noted that this “rapidly converting stablecoins into ETH” move is the same one used in the Bybit heist.
SlowMist says hacker-linked addresses on the XRP Ledger still hold about 103 million XRP across seven wallets.
Was It North Korea?
Probably, but it isn’t confirmed.
Chen said some IP addresses “closely match VPN patterns tied to a group associated with North Korea,” but stressed the identity “is not yet 100% confirmed.” She pointed to the February 2025 Bybit hack, which was attributed to North Korean state hackers.
Independent on-chain investigator Specter separately reported that after the stolen XRP was bridged across chains, its routing could be linked to funds from the AFX hack in July 2026, a roughly $24 million theft attributed to TraderTraitor, a Lazarus-linked cluster.
The playbook also fits. At Bybit in 2025, attackers compromised Safe{Wallet}‘s interface so that signers approved a transaction they couldn’t see properly. At Bitget, a compromised vendor tool forged the instructions and the exchange’s own signing infrastructure approved them. Neither attack cracked the cryptography. Both got in through a trusted tool that sits upstream of the signers.
No government agency has publicly attributed the Bitget hack yet.
Who Pays
Bitget says users don’t. “The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over US$464 million,” Chen said. She added that customer balances remain accurate and that the exchange has more than $1 billion in capital to handle withdrawal demand.
The protection fund exists for exactly this. But covering this loss uses up about three-quarters of it, and that has to be rebuilt before the next incident.
The BGB token fell roughly 3–5% as the news spread. Bitcoin barely moved.
Bitget has promised hourly updates and a full incident report, with root cause and corrective actions, within 24 hours. Xie Jiayin, head of Greater China, said an outside security team is running an independent forensic investigation, and that withdrawals will resume “once potential risks are eliminated.” No date has been given. Chen also said insider involvement “appeared unlikely,” but that “the final attack vector still requires further confirmation.”
The Uncomfortable Lesson
For years, exchange security meant protecting the keys: HSMs, MPC, multisig, cold storage. Bitget did all of that, and the keys still weren’t stolen.
The weak point was the question every signing system has to answer: is this a real transfer request? If a compromised internal or vendor tool can create a request that looks legitimate, perfect key custody doesn’t help. The signer just signs faster.
Bybit showed this in 2025, and Bitget has now shown it again at $351.6 million. Expect every major exchange to spend this week auditing which third-party tools can write to its wallet backend.
Why This Matters for Crypto Jobs
Exchange security budgets tend to grow right after big hacks, and this one is big. Here’s where the hiring is likely to go:
- Supply-chain and vendor security is the hot specialty now. The attackers came in through a third-party tool, not Bitget’s core systems. Exchanges and custodians need people who can map every vendor with access to wallet infrastructure, lock down its permissions, and watch it continuously. If you’ve done third-party risk or software supply-chain security in TradFi or big tech, crypto teams want you.
- Transaction verification engineers. The fix isn’t better key storage. It’s independent checks before signing: out-of-band confirmation, policy engines, allowlists, and anomaly detection that can stop a forged instruction before the HSM signs it. Engineers who can build a “second brain” for the signing path will be in demand.
- On-chain forensics and incident response. Arkham, SlowMist, PeckShield, Hacken and independent investigators like Specter were tracing funds within hours. Exchanges, analytics firms and law enforcement all want investigators who can follow money through bridges, DEX aggregators and intent protocols like UniswapX and 1inch Fusion in real time.
- Threat intel focused on the DPRK. If Lazarus is behind this, it’s the second nine-figure exchange hit tied to North Korea since Bybit’s $1.5 billion loss. Analysts who track TraderTraitor-style infrastructure, VPN fingerprints and laundering patterns are among the hardest security hires to find.
- Treasury and risk roles. The protection fund just lost about 75% of its value and has to be refilled. Someone has to size these reserves, manage what they’re held in, and explain the numbers to regulators. That’s a growing niche that combines treasury, actuarial and risk work.
Every big hack is a bad day for an exchange and a busy hiring period for the security industry. Browse the latest crypto and Web3 jobs on Cryptogrind to find security engineering, incident response, on-chain forensics and risk roles at the teams trying to prevent the next one.
Discussion
Comments are powered by GitHub. Sign in with your GitHub account to chime in.