Key TakeawaysBitget detected unauthorized outflows from its hot and warm wallets at 18:31 UTC on Thursday, September 24, 2026 and later put the loss at about $387.5 million across seven networks, inclKey TakeawaysBitget detected unauthorized outflows from its hot and warm wallets at 18:31 UTC on Thursday, September 24, 2026 and later put the loss at about $387.5 million across seven networks, incl

Bitget Hack Explained: How $387 Million Was Stolen Without a Single Key, and the THORChain Standoff Splitting Crypto

Key Takeaways
Bitget detected unauthorized outflows from its hot and warm wallets at 18:31 UTC on Thursday, September 24, 2026 and later put the loss at about $387.5 million across seven networks, including Ethereum and other EVM chains, the XRP Ledger, Zcash and TRON. It is one of the largest exchange thefts on record, behind Bybit's $1.46 billion in 2025.
No private keys were stolen and cold storage was untouched. According to CEO Gracy Chen, attackers exploited a flaw in a third party security product and stolen internal credentials to compromise a backend system in the wallet stack, forge transaction data, and trick Bitget's own approval flow into signing transfers that looked routine.
Bitget says user balances are unaffected and its User Protection Fund of more than $464 million will absorb the loss. Withdrawals are restarting in phases: Bitcoin on September 28, Ethereum on September 29, USDT on September 30, and remaining tokens, fiat and P2P by October 2. Trading and deposits never stopped.
The aftermath produced a public standoff. Chen formally asked THORChain to refuse service to the publicly listed attacker addresses as loot was swapped through the protocol into Bitcoin; THORChain declined, citing its permissionless design, while SlowMist and OKX founder Star Xu noted it had paused itself quickly when its own funds were at risk.
Bitget suspects North Korean linked groups based on IP patterns and onchain behavior, with Mandiant and SlowMist investigating, Circle and Tether freezing about $318,000 in stablecoins, and 5% bounties on offer for freezing or recovering assets.
 
 

What Happened on September 24

The breach surfaced the way exchange hacks usually do now: onchain analysts saw it before the announcement. Bubblemaps, Wu Blockchain and others flagged unusual outflows from Bitget addresses within the hour, users began posting about failed withdrawals, and Bitget's own systems logged the unauthorized transfers at 18:31 UTC. CEO Gracy Chen posted a security notice at 21:30 UTC and withdrawals were paused. The initial estimate of about $351.6 million covered roughly $183 million leaving EVM chains and a single striking move on the XRP Ledger, where two Bitget wallets sent 93.7 million XRP, worth about $143 million, to a fresh address. Two days later the exchange raised the total to $387.5 million after tracing additional affected transactions on Zcash and TRON, stressing that the revision reflected a fuller accounting of the original attack rather than a second breach. The stolen assets included XRP, ETH, USDT, USDC, USDT0, ZEC, XAUt, BNB, AVAX and TRX.
 

How It Was Done Without Stealing a Key

The most unsettling detail is that Bitget's keys were never taken. According to Chen's account, the attackers exploited a vulnerability in a third party security product and used stolen internal access credentials to compromise a backend system within the wallet infrastructure. From there they forged transaction data so that transfers to their own addresses appeared as ordinary, legitimate withdrawals, and Bitget's approval flow signed them. Cold wallets were not involved, and the exchange says the vulnerability has since been identified and fixed so that no further unauthorized transfers are possible. Mandiant and SlowMist are assisting the forensic work, and a full incident report is still pending.
The technique matters because it echoes the Bybit heist of February 2025, in which attackers manipulated what signers saw rather than breaking cryptography, and because Bitget says IP patterns and onchain behavior resemble prior operations linked to North Korean groups, though formal attribution rests with investigators. Together the two incidents suggest the frontier of exchange security has moved from key management to the integrity of the systems that present transactions for approval.
 
 

The Protection Fund Faces Its Biggest Test

Bitget's response leaned on a promise it made years ago. The exchange says its User Protection Fund, which holds more than $464 million and is separate from its proof of reserves system, will cover the full loss, meaning customers should not bear any of it. Trading and deposits continued throughout, and Bitget framed the withdrawal freeze as a security measure rather than a liquidity problem. The proof is in the restart: Bitcoin withdrawals resumed at 08:00 UTC on September 28, Ethereum and other EVM networks follow on September 29, USDT on September 30, and the remaining tokens, fiat channels and P2P services are due back by October 2, each phase gated on validation checks. Bitget has also announced separate 5% bounties for anyone who helps freeze or recover stolen assets, Circle and Tether froze about $318,000 in stablecoins, and Binance founder Changpeng Zhao publicly voiced support. The phased reopening is the exchange's first operational test since the attack, and the market will read any hiccup harshly.
 
 

The THORChain Standoff

Within a day, part of the haul was moving. On September 25, MistTrack, the tracing unit of SlowMist, reported that Bitget linked funds were entering THORChain for swaps and cross-chain transfers, and pointedly asked what responsibility a protocol carries once the source of funds is known, noting that nearly $1.2 billion of the $1.46 billion Bybit loot had moved through the same rails in 2025. On Saturday Chen escalated, posting that Bitget's attacker addresses were public and tracked and formally asking THORChain to refuse them service. "Decentralization is a design principle, not a shield for facilitating known stolen funds," she wrote. "The industry is watching."
THORChain expressed regret but declined, arguing it is permissionless in the same sense as Bitcoin, Ethereum or BNB Chain and has no address level blocking in its validator design. SlowMist and OKX founder Star Xu disputed that framing, observing that THORChain had paused its network quickly when its own funds were at risk. The swaps continued: CoinDesk identified 27 transactions moving about 2,390 ETH into 75.2 BTC, roughly $6 million, and tracing shows the attacker also routing through Uniswap, 1inch, Stargate, Across, Relay, Chainflip and Circle's cross-chain transfer protocol, with about $83 million in stolen XRP already on the move.
The dispute is the same argument crypto has been having all month from different angles. Cronos validators rolled back nearly two hours of history to reverse a $120 million exploit, Blockstream paused the Liquid Network and negotiated with its hackers on chain, and now a decentralized protocol has refused to intervene at all. Each choice is defensible on its own terms, and each carries a cost: chains that can intervene weaken finality, and chains that cannot become the preferred laundromat for the industry's worst actors.
 

What It Means for Traders on MEXC

The market reaction was contained, with Bitcoin and XRP absorbing the news and ETF inflows continuing, but the incident is a reminder that counterparty risk on any centralized venue is real and that the details of protection funds, proof of reserves and withdrawal policies deserve reading before a crisis rather than during one. Practical habits apply everywhere: keep long term holdings in self custody or spread across venues, keep exchange balances sized to active trading, harden accounts with two factor authentication and withdrawal safeguards, and be alert to the wave of phishing that follows every major hack, as impersonators pose as support teams offering help. Traders can follow the assets at the center of the story on XRP/USDT and ETH/USDT.
 
Disclaimer: This content is for educational and reference purposes only and does not constitute any investment advice. Digital asset investments carry high risk. Please evaluate carefully and assume full responsibility for your own decisions.
市場機遇
4 圖標
4實時價格 (4)
$0.020735
$0.020735$0.020735
USD

本頁面分享的文章均源自公開平台,僅供參考。該內容不代表 MEXC 的立場或觀點。所有版權歸 OoJae 所有。如果您認為任何內容侵犯了第三方的權益,請聯絡 service@support.mexc.com 以便及時刪除。 MEXC 不保證任何內容的準確性、完整性或及時性,且不對基於所提供信息而採取的任何行動負責。本內容不構成財務、法律或其他專業建議,亦不應被解釋為 MEXC 的推薦或認可。如需專家見解和深入分析,請造訪 MEXC 學院。

4 最新動態

查看更多
從稀缺交易到估值紀律:SpaceX的回調考驗OpenAI的IPO野心

從稀缺交易到估值紀律:SpaceX的回調考驗OpenAI的IPO野心

據報導,OpenAI 傾向將其 IPO 推遲至 2027 年,但更強烈的市場訊號來自 SpaceX。SpaceX 於 6 月 22 日收盤下跌了 16.4%,收於 154.60 美元,較盤中高點 225.64 美元降低了 31.5%,但仍較其 135 美元的 IPO 價格高出 14.5%。這一走勢使 SpaceX 從一個由稀缺性驅動的 IPO 成功案例,轉變為 AI 相關超大型上市週期中首個重大公開市場壓力測試。 OpenAI 的問題不在於需求,而在於估值。路透社引用《紐約時報》的報導指出,OpenAI 正考慮等待至 2027 年,以維持高達 1 兆美元的估值目標,而顧問將此選擇定調為:要麼等待達到該估值,要麼以較低目標提前上市。 預測市場已開始反映這種謹慎態度。Polymarket 的 OpenAI IPO 市場近期顯示,OpenAI 在 2026 年 12 月 31 日前完成 IPO 的機率約為四分之一,這表明交易者不再將近期上市視為明確的基本情境。對於加密貨幣交易者而言,這使得 AI 上市前的曝險從單向的稀缺性交易,轉變為與公開市場基準掛鉤的估值紀律交易。
2026/06/29
Coldcard Mk3 警告隨 $38M Bitcoin 掃蕩而來,但原因仍未確認

Coldcard Mk3 警告隨 $38M Bitcoin 掃蕩而來,但原因仍未確認

比特幣硬體錢包製造商 Coinkite 已警告用戶,Coldcard 裝置存在種子生成問題,影響範圍涵蓋所有 4.0.1 及更高版本的 Mk3 韌體。此警告是在安全研究人員調查一宗涉及 594.48 BTC(價值約 3,800 萬美元)的協調性盜取事件時出現的。然而,目前尚無公開的技術證據證實 Coldcard 的問題導致了這些轉帳。
2026/07/31
Mastercard 完成對 BVNK 的收購,金額高達 18 億美元——穩定幣進入全球支付核心

Mastercard 完成對 BVNK 的收購,金額高達 18 億美元——穩定幣進入全球支付核心

Mastercard 於三月宣布該交易後,已於 2026 年 8 月 3 日(UTC +8)完成對穩定幣基礎設施供應商 BVNK 的收購。
2026/08/04
查看更多