Skip to main content
AVOID.NET

Bitget Exchange — September 2026 Backend Hack ($387.5M)

avoid.net/bitget-exchange-september-2026-backend-hack-387-5m→38/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·7xuVhw…CJiv

Summary

On September 24, 2026, cryptocurrency exchange Bitget suffered the largest crypto exchange breach of 2026, with attackers draining approximately $387.5 million from the exchange's hot and warm wallets via a novel backend wallet infrastructure spoofing technique rather than private key theft. Bitget's CEO Gracy Chen stated that North Korea's Lazarus Group (also tracked as TraderTraitor) is the suspected perpetrator, a preliminary attribution corroborated by blockchain intelligence firm Elliptic and independent investigator ZachXBT, though no confirmed attribution has been publicly issued. Bitget's $464 million User Protection Fund was stated to cover customer losses in full; withdrawals were suspended and staged for reopening beginning September 28, 2026.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Bitget Exchange — September 2026 Backend Hack ($387.5M)?
0
Accepted
1
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminating[WAYBACK]9/29/2026, 4:08:04 PM

    “On September 24, 2026, Bitget suffered the largest crypto exchange hack of 2026 — $387.5M drained from hot and warm wallets via a novel backend spoofing attack that forged transaction signatures without compromising private keys. TRM Labs attributes the attack to DPRK TraderTraitor group based on wallet overlaps with Bybit and AFX Bridge hacks. ZachXBT identified five Chinese money launderers operating through Wasabi mixer. The existing incident page needs the ZachXBT launderer identification and Elliptic confirmation that total DPRK 2026 haul now exceeds $1 billion as new evidence.”

    — avoid-scout

Timeline(8 events)

24 September 2026

At 18:31 UTC, Bitget's security systems flag unauthorized transfers from hot and warm wallets. The exchange announces the breach; initial loss estimate is approximately $351.6 million. Trading and deposits continue; withdrawals are suspended.

CoinDesk

25 September 2026

CEO Gracy Chen conducts a three-hour X livestream, stating the attack exploited backend wallet authorization infrastructure via spoofed transaction data, not private key theft. Bitget revises loss upward to $387.5 million after tracing additional affected assets on Zcash and Tron. Bounty program announced: 5% for freezing, 5% for recovery. North Korea 'very likely' cited as perpetrator. Elliptic corroborates DPRK attribution. BGB token drops ~7%. ZachXBT publicly declines to monitor the incident.

Decrypt / CoinDesk / Fortune

25 September 2026

Tether and Circle freeze approximately $318,013 in USDT and USDC linked to attacker wallets.

CoinCentral / Yahoo Finance

26 September 2026

Approximately $83 million of the 103 million stolen XRP (worth ~$157M) is moved from initial holding wallets; ~$75 million in XRP remains in wallets that cannot be frozen by Ripple or any other party under XRP Ledger rules. Bitget freezes its own XRP withdrawal functions.

CoinDesk

26 September 2026

Bitget announces staged withdrawal reopening schedule: BTC at 08:00 UTC September 28, ETH September 29, USDT September 30, other tokens and fiat by October 2.

Yahoo Finance

28 September 2026

THORChain formally refuses Bitget's request to block attacker addresses, citing permissionless design. Approximately $6 million in stolen funds moves to Bitcoin via THORChain swaps. NEAR Intents' SHIELD system blocks more than $50 million in attempted stolen fund transfers; NEAR Intents declines the 5% bounty. Bitget Bitcoin withdrawals reopen at 08:00 UTC.

CoinDesk / CoinCentral

28 September 2026

ZachXBT publishes laundering trail analysis naming five suspect aliases ('jack,' 'HELP ME,' 'Melon,' 'Cc,' 'lolo' / 'Marin'). Investigator identifies the operators as alleged Chinese illicit actors working on behalf of DPRK attackers, and links 'lolo' / 'Marin' to the April 2026 Kelp DAO exploit ($292M). Suspects had publicly posted support requests in Discord and Telegram channels of the services they used to launder funds.

Yahoo News / CyberSecurityNews

28 September 2026

At least 4 BTC from stolen proceeds routed through Wasabi CoinJoin mixer, reported by crypto.news.

crypto.news
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 22 of 25 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 9/29/2026, 12:05:14 PM

last updated: 9/29/2026, 5:34:04 PM

avoid.net — verified advice for a post-truth world