S&P 500 5,278.40 +0.45% NASDAQ 16,755.02 +0.67% DOW JONES 38,886.57 +0.32% RUSSELL 2000 2,084.45 +0.15% VIX 13.42 -1.52% GOLD 2,348.30 +0.21% OIL (WTI) 78.62 +0.18% US 10Y 4.28% -0.04%
All articles Federal Reserve

How Fraudulent Approvals Enabled $387M Theft

How Fraudulent Approvals Enabled $387M Theft

The Bitget hack has turned into a much bigger security incident than the exchange’s first estimate suggested. Bitget now says attackers stole $387.5 million from its exchange wallets on September 24, while withdrawals remain suspended and the company says its protection fund covers the loss.

Mandiant and SlowMist are investigating. CEO Gracy Chen suspects North Korean involvement, but the initial entry point remains undisclosed.

Bitget Hack Timeline Starts With Unauthorized Transfers

Bitget says its security systems detected unauthorized transfers at 18:31 UTC and activated emergency procedures within minutes. The incident affected parts of its hot and warm wallets, while offline cold wallets remained secure, according to the company.

That detection time doesn’t establish when attackers first gained access.

Add Coinpedia as a trusted source in Google News

At 19:57 UTC, analyst DCF GOD flagged a fresh wallet spending $19.67 million in USDT0 to purchase 7,111 ETH within six minutes, reportedly paying as much as 5% above market prices.

Then, at 21:06 UTC, Bubblemaps reported roughly $180 million moving from Bitget wallets to a common receiving address before being split across several wallets.

Bitget Hack Details: How Fraudulent Approvals Enabled $387M Theft
Bitget Hack Details: How Fraudulent Approvals Enabled $387M Theft

Bitget Hack Appears To Exploit Authorization

At 21:30 UTC, Chen’s security notice put the initial loss at $351.6 million and confirmed withdrawals had been paused. The notice arrived almost three hours after Bitget’s stated detection time, although that gap doesn’t prove funds continued leaving during the entire period.

By September 25 at 00:43 UTC, the suspected method became clearer.

Chen said attackers compromised a critical backend system that manages wallet operations. They allegedly supplied false transaction data and triggered Bitget’s authorization process, effectively getting the exchange’s own system to approve fraudulent transfers.

Private-key theft was reportedly ruled out. How attackers entered the backend and which security checks failed remain unresolved.

Bitget Hack Details: How Fraudulent Approvals Enabled $387M Theft
Bitget Hack Details: How Fraudulent Approvals Enabled $387M Theft

Bitget Hack Loss Rises After Broader Accounting

At 14:03 UTC, Bitget revised the estimated loss to $387.5 million after including affected Zcash and TRON assets. The exchange said the vulnerability had been fixed and promised to announce a withdrawal plan by September 26 at 04:00 UTC, without promising withdrawals would reopen at that time.

The suspected North Korean connection remains just that: a suspicion. Chen cited IP behaviour and blockchain activity consistent with North Korean groups.

Several details resemble the February 2025 Bybit theft, including manipulated approvals, rapid asset conversion, wallet splitting and the use of THORChain. Those similarities justify further investigation, but they don’t independently identify the attackers.

For now, the Bitget hack leaves the biggest unanswered question behind the $387.5 million loss: exactly how attackers reached the backend system and convinced its authorization process to approve the theft.

Was this writing helpful?

Story Ends Here

Trust with CoinPedia:

Investment Disclaimer:

All opinions and insights shared represent the author’s own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.

Sponsored and Advertisements:

Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.

Read the Next News

Eagle One Intelligence

The edge serious investors read.

Macro shifts, market structure, and the ideas worth tracking — straight to your inbox.

Note. For informational purposes only. Not financial advice. Past performance does not guarantee future results.