Skip to main content
AVOID.NET

Audit log

Every state-changing event for Bitget Exchange — September 2026 Backend Hack ($387.5M): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-29 12:05:25Z
    Score: ? → ? (no score change)
    anchoranchored
    chain
    ●mainnet-betaslot 451,636,815
    sig
    7xuVhwSgSUzg…kR6ECJivexplorer ↗
    hash
    CYvt7GxqgwyP…TcmRJhwmsha256 → base58
    verifying row…full verify ↗
    canonical bytes (29250 B) ▸
    {"actor":"system:backfill","investigation_id":"f148389b-fbdf-4f1b-9c26-b291f88ef903","kind":"publish","page_slug":"bitget-exchange-september-2026-backend-hack-387-5m","published_at":"2026-09-29T12:05:25.017Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Bitget Exchange — September 2026 Backend Hack ($387.5M)","sections":[{"content":"At 18:31 UTC on September 24, 2026, Bitget's internal security systems detected unauthorized transfers from a limited number of hot and warm wallets. The exchange initially reported losses of approximately $351.6 million; a revised figure of $387.5 million was announced on September 25 after on-chain tracing identified additional affected assets on the Zcash and Tron networks. The incident is described by multiple outlets as the largest cryptocurrency exchange breach of 2026 and among the ten largest of all time. Cold wallets and the separate Bitget Wallet self-custodial product were not affected. Customer account balances were reported as accurate throughout the incident, with Bitget stating that the User Protection Fund — which held more than $464 million at the time — would cover the full loss.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"Crypto exchange Bitget loses $352 million in hack, claims user funds are 'safe' — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/24/crypto-exchange-bitget-loses-usd352-million-in-hack-claims-user-funds-are-safe"},{"credibility":2,"name":"Bitget Suffers Year's Largest Crypto Hack as Losses Top $387 Million — PYMNTS","type":"news_article","url":"https://www.pymnts.com/cryptocurrency/2026/bitget-suffers-years-largest-crypto-hack-as-losses-top-387-million/"},{"credibility":2,"name":"Bitget Hack Losses Climb to $387M: Here's What Happened, and Why North Korea Is a Suspect — Decrypt","type":"news_article","url":"https://decrypt.co/379350/bitget-hack-387m-what-happened-why-north-korea-suspect"},{"credibility":1,"name":"North Korea accused of plundering Bitget for $387 million in year's biggest crypto attack — Fortune","type":"news_article","url":"https://fortune.com/2026/09/25/north-korea-bitget-387-million-crypto-attack/"}]},{"content":"CEO Gracy Chen, speaking during a three-hour X (Twitter) livestream on September 25, stated that the attackers did not steal private keys or forge customer withdrawal requests. Instead, attackers compromised a critical backend system within the exchange's wallet infrastructure and used it to spoof transaction data, tricking Bitget's own authorization process into approving outbound transfers that appeared routine. Security firm Hypernative described the technique as feeding forged transfer data into the exchange's internal approval pipeline, causing hot and warm wallet signing infrastructure to authorize payouts without detecting the manipulation. The attack produced 19 unauthorized withdrawals according to early reporting. This attack vector — exploiting backend authorization logic rather than cryptographic key material — represents a distinct threat model from the private key theft or smart contract exploits seen in most prior major exchange incidents. Assets affected included XRP, ETH, USDT, USDC, BNB, AVAX, TRX, ZEC, USDT0, and XAUt across at least seven blockchains: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, and Base.","heading":"Attack Vector: Backend Wallet Infrastructure Spoofing","severity":"critical","sources":[{"credibility":2,"name":"Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/25/bitget-s-usd351-million-hack-happened-via-spoofed-transfers-not-private-keys-ceo-gray-chen-says"},{"credibility":2,"name":"Bitget's $387M hack: how spoofed requests got signed — Hypernative","type":"research","url":"https://www.hypernative.io/insights/blog/how-spoofed-requests-got-bitgets-own-wallets-to-sign-away-387m"},{"credibility":2,"name":"Crypto Exchange Hack: Bitget's $352 Million Breach Came From Spoofed Transfers, Not Stolen Keys — Crowdfund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/09/312889-crypto-exchange-hack-bitgets-352-million-breach-came-from-spoofed-transfers-not-stolen-keys/"},{"credibility":2,"name":"Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html"},{"credibility":2,"name":"Bitget Hack Explained: How Spoofing Took $387.5M — BIT.com","type":"research","url":"https://www.bit.com/knowledge-hub/bitget-hack"}]},{"content":"Bitget CEO Gracy Chen stated that North Korea is 'very likely' behind the attack, citing IP addresses matching VPN patterns previously associated with a DPRK-linked group, on-chain signatures consistent with techniques used in prior North Korean state-linked operations, and asset conversion patterns matching known Lazarus Group tradecraft. Chen acknowledged that the attacker's identity has not been confirmed and that no technical evidence has been publicly disclosed. Blockchain intelligence firm Elliptic independently stated the breach is 'highly likely' to be DPRK-linked, citing infrastructure overlap with previous North Korea-attributed activity. The FBI has attributed similar operations to TraderTraitor, a North Korean hacking subgroup also responsible for the 2024 DMM Bitcoin theft ($308 million). Independent analyst Specter linked the stolen XRP — which was bridged to other networks — to the $24 million AFX hack from July 2026, which had itself been attributed to the Lazarus Group sub-actor TraderTraitor. ZachXBT initially declined to monitor the incident, citing a policy of prioritizing paid or committed supporters, but later published laundering trail analysis identifying five suspect accounts (see Laundering Trail section). As of the publication of this page, no government body has formally attributed the attack to DPRK. Attribution claims should be treated as preliminary.","heading":"Attribution: Suspected DPRK Lazarus Group / TraderTraitor","severity":"high","sources":[{"credibility":2,"name":"Bitget Confirms $351.6 Million Hack, Suspects North Korea's Lazarus Group — HackRead","type":"news_article","url":"https://hackread.com/bitget-hack-suspects-north-korea-lazarus-group/"},{"credibility":1,"name":"North Korea accused of plundering Bitget for $387 million in year's biggest crypto attack — Fortune","type":"news_article","url":"https://fortune.com/2026/09/25/north-korea-bitget-387-million-crypto-attack/"},{"credibility":3,"name":"Bitget Loses $387 Million in Hack as Lazarus Group Tactics Raise North Korea Fears — The Currency Analytics","type":"news_article","url":"https://thecurrencyanalytics.com/digital-wallet/bitget-loses-387-million-in-hack-as-lazarus-group-tactics-raise-north-korea-fears-297203"},{"credibility":2,"name":"Security Researcher ZachXBT Says 'He Will Not Monitor' the Bitget Hack Incident — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/25/security-researcher-zachxbt-says-he-will-not-monitor-bitget-hack-incident/"},{"credibility":2,"name":"Lazarus Group / TraderTraitor — DPRK September 2026 Blitz Campaign — AVOID.NET","type":"other","url":"https://avoid.net/lazarus-group-tradertraitor-dprk-september-2026-blitz-campaign"}]},{"content":"ZachXBT subsequently published a laundering trail analysis identifying five suspect accounts linked to the movement of stolen funds. The investigator described the operators as Chinese illicit actors working on behalf of the alleged DPRK attackers. A notable operational security failure exposed the network: the suspects posted publicly in the Discord servers and Telegram channels of the services they were using to launder funds, including support requests that revealed their involvement. The five aliases identified in ZachXBT's transaction map are 'jack,' 'HELP ME,' 'Melon,' 'Cc,' and 'lolo' (also known as 'Marin' on Telegram). The account 'Cc' reported sending 277,724 XRP but receiving only 431 in return — a discrepancy consistent with a failed laundering attempt. The account 'jack' expressed concern that losing the assets 'would cause a lot of trouble in my life.' The account 'lolo' / 'Marin' was separately identified as having participated in laundering proceeds from the April 2026 Kelp DAO exploit ($292 million), suggesting a shared laundering infrastructure across multiple DPRK-attributed incidents. These are allegations from an independent investigator, not findings of a court or regulatory body. The identities behind the aliases have not been publicly confirmed.","heading":"Laundering Trail and Suspect Accounts","severity":"high","sources":[{"credibility":2,"name":"Investigator Finds $387M Bitget Hack Suspects Asking for Help in Public Chats — Yahoo News / CoinDesk","type":"news_article","url":"https://www.yahoo.com/news/us/articles/investigator-finds-387m-bitget-hack-122401213.html"},{"credibility":2,"name":"Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/bitget-backend-breach/"},{"credibility":3,"name":"$387M stolen from Bitget linked to laundering — Pluang / ZachXBT","type":"community_report","url":"https://pluang.com/en/news-feed/zachxbt-387-juta-dolar-dicuri-dari-bitget-dialirkan-melalui-mixer"},{"credibility":2,"name":"Bitget Hack Investigation Uncovers Laundering Trail, North Korean Links — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/28/bitget-hack-investigation/"}]},{"content":"Stolen funds were routed across multiple blockchains through cross-chain bridges before being channeled into privacy tools. Investigators documented the following laundering steps: attackers first converted TRX to USDT, then moved funds to Ethereum through USDT0 (an omnichain version of Tether), and subsequently swapped assets into approximately 145 ETH. XRP holdings were converted to Bitcoin using THORChain, a decentralized cross-chain swap protocol. A portion of Bitcoin proceeds was then routed through the Wasabi CoinJoin mixer, which blends coin inputs to obscure transaction origins; crypto.news reported at least 4 BTC routed through Wasabi CoinJoin. Bitget formally requested that THORChain block attacker addresses. THORChain refused, stating the protocol 'does not selectively freeze funds,' though it acknowledged the ability to pause broader network activity in emergencies. The refusal, reported by CoinDesk on September 28, sparked wider debate about the obligations of permissionless cross-chain infrastructure during active theft events. NEAR Intents took a contrasting position: its SHIELD system blocked more than $50 million in attempted transfers connected to the hack, freezing $503,000 during movement, though approximately $166,000 in suspected stolen assets slipped through. NEAR Intents declined the 5% bounty offered by Bitget, stating it wanted to maximize recovery rather than take a fee. Tether and Circle independently froze approximately $318,013 in USDT and USDC linked to the breach.","heading":"Laundering Methods: Wasabi Mixer, Cross-Chain Bridges, THORChain","severity":"high","sources":[{"credibility":2,"name":"ZachXBT Says Bitget Hack Funds Are Moving Through Cross-Chain Bridges and Wasabi — Bitcoin Ethereum News","type":"news_article","url":"https://bitcoinethereumnews.com/tech/zachxbt-says-bitget-hack-funds-are-moving-through-cross-chain-bridges-and-wasabi/"},{"credibility":2,"name":"Bitget hacker routes 4 BTC through Wasabi CoinJoin — crypto.news","type":"news_article","url":"https://crypto.news/bitget-hacker-routes-4-btc-through-wasabi-coinjoin/"},{"credibility":2,"name":"THORChain rejects Bitget request to block hacker as $6 million moves to Bitcoin — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/09/28/thorchain-rejects-bitget-request-to-block-hacker-as-usd6-million-moves-to-bitcoin"},{"credibility":2,"name":"Bitget Hack: NEAR Intents Blocks $50 Million in Stolen Crypto Funds — CoinCentral","type":"news_article","url":"https://coincentral.com/bitget-hack-near-intents-blocks-50-million-in-stolen-crypto-funds"},{"credibility":2,"name":"Bitget Hack's $387.5M Laundered Through Wasabi, Linked to North Korean Actors — Gokhshtein Media","type":"news_article","url":"https://gokhshtein.com/news/2026-09-28-bitget-hacks-3875m-laundered-through-wasabi-linked-to-north"},{"credibility":2,"name":"THORChain's response to Bitget's $387.5M hack sparks blacklist debate — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/28/thorchain-response-hack/"}]},{"content":"XRP represented the largest single asset stolen in the breach, with approximately 103 million XRP worth roughly $157 million taken. Unlike USDT and USDC, which are tokens issued by centralized companies with freeze authority, XRP is the native asset of the XRP Ledger and is not issued by Ripple; Ripple therefore has no technical ability to freeze XRP balances. By September 26 — two days after the hack — approximately $83 million in stolen XRP had been moved from three initial holding wallets. Approximately $75 million remained in wallets that could not be frozen under XRP Ledger's design. Bitget independently froze its own XRP withdrawal functions as 27 million stolen tokens were detected moving. The structural inability to freeze XRP contrasted sharply with the rapid stablecoin freezes executed by Circle and Tether, illustrating the divergent recovery capabilities across asset types.","heading":"XRP: Scale, Freeze Limitations, and Movement","severity":"high","sources":[{"credibility":2,"name":"Bitget hacker moves $83 million in stolen XRP beyond reach of freeze controls — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/26/bitget-hacker-moves-usd83-million-in-stolen-xrp-that-ripple-cannot-freeze"},{"credibility":2,"name":"Bitget Hack: $157M in Stolen XRP Sits in Wallets No One Can Freeze — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/exchanges/bitget-hack-xrp-157m-cannot-be-frozen/"},{"credibility":2,"name":"Bitget Hacker Moved $83M+ in XRP: Why Could Tether Freeze Funds but Ripple Couldn't? — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/bitget-hacker-moved-83m-xrp-093941996.html"},{"credibility":2,"name":"Bitget freezes XRP withdrawals as 27M stolen tokens move — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/bitget-freezes-xrp-withdrawals-as-27m-stolen-tokens-move/"}]},{"content":"Bitget activated emergency response procedures immediately following detection. Trading and deposits continued normally throughout the incident; only withdrawals were suspended. The exchange engaged Google-owned Mandiant and SlowMist for third-party forensic investigation. CEO Gracy Chen stated during an X livestream that the vulnerability had been fixed and that no further unauthorized transfers were possible. Bitget launched a recovery bounty program offering 5% for freezing attacker funds and an additional 5% for funds actually recovered. A real-time tracking dashboard was released to assist independent researchers. Withdrawals were staged for resumption beginning September 28 with Bitcoin, followed by Ether on September 29, USDT on September 30, and other tokens, fiat, and P2P services by October 2. The exchange stated that its User Protection Fund, which held more than $464 million at the time of the incident, would cover the full $387.5 million loss and that customer balances were not affected. Despite the breach, CEO Chen reaffirmed plans to take Bitget public within three years. Bitget's native token BGB fell approximately 7% to $1.93 on news of the hack before partially recovering.","heading":"Bitget's Response and Recovery Program","severity":"medium","sources":[{"credibility":2,"name":"Bitget to resume withdrawals after $387.5M crypto hack — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/bitget-resume-withdrawals-387-5m-105934715.html"},{"credibility":2,"name":"Bitget Reopens Withdrawals After $387.5M Hack: Full Timeline — SpazioCrypto","type":"news_article","url":"https://en.spaziocrypto.com/xrp/bitget-reopens-withdrawals-387-million-hack-timeline-xrp/"},{"credibility":2,"name":"Bitget CEO Gracy Chen affirms IPO plans despite $387.5M security breach — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/bitget-ipo-plans-security-breach/"},{"credibility":2,"name":"Bitget Taps Mandiant, SlowMist After $351M Security Breach — Bitcoin Ethereum News","type":"news_article","url":"https://bitcoinethereumnews.com/finance/bitget-taps-mandiant-slowmist-after-351-security-breach/"},{"credibility":2,"name":"Bitget Hack Update: CEO Says Some Hacker Wallets Frozen, Withdrawals Still Paused — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/25/bitget-hack-update-ceo-says-some-hacker-wallets-frozen-withdrawals-still-paused-bgb-down-3-3/"},{"credibility":3,"name":"Bitget Hack: $387M Stolen, Withdrawals Return From September 28 — AirdropAlert","type":"news_article","url":"https://airdropalert.com/blogs/bitget-hack/"}]},{"content":"The Bitget breach occurred within a pattern of elevated exchange-level attacks in 2026. Fortune reported that blockchain analytics firm Chainalysis documented North Korean groups stealing a record $2 billion in cryptocurrency during 2025, with DPRK-linked actors increasingly infiltrating targets through IT worker placement or recruiter impersonation. The Bitget incident followed two other major exchange-level breaches in 2026: the Liquid Network suffered a $319 million breach in September, and a Coldcard hardware wallet-related incident resulted in approximately $116 million in losses in July. The hack also followed the April 2026 Kelp DAO exploit ($292–293 million), to which at least one of the Bitget money laundering suspects ('lolo' / 'Marin') was independently linked by ZachXBT, suggesting overlapping laundering infrastructure across multiple large 2026 incidents.","heading":"Broader Context: 2026 Exchange Hack Pattern","severity":"medium","sources":[{"credibility":1,"name":"North Korea accused of plundering Bitget for $387 million in year's biggest crypto attack — Fortune","type":"news_article","url":"https://fortune.com/2026/09/25/north-korea-bitget-387-million-crypto-attack/"},{"credibility":2,"name":"Bitget Hack Investigation Uncovers Laundering Trail, North Korean Links — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/28/bitget-hack-investigation/"},{"credibility":2,"name":"Explained: The Kelp DAO Hack (April 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-kelp-dao-hack-april-2026"}]}],"sources_used":[{"credibility":2,"name":"Crypto exchange Bitget loses $352 million in hack, claims user funds are 'safe' — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/24/crypto-exchange-bitget-loses-usd352-million-in-hack-claims-user-funds-are-safe"},{"credibility":2,"name":"Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/25/bitget-s-usd351-million-hack-happened-via-spoofed-transfers-not-private-keys-ceo-gray-chen-says"},{"credibility":2,"name":"Bitget hacker moves $83 million in stolen XRP beyond reach of freeze controls — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/26/bitget-hacker-moves-usd83-million-in-stolen-xrp-that-ripple-cannot-freeze"},{"credibility":2,"name":"THORChain rejects Bitget request to block hacker as $6 million moves to Bitcoin — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/09/28/thorchain-rejects-bitget-request-to-block-hacker-as-usd6-million-moves-to-bitcoin"},{"credibility":2,"name":"Bitget Hack Losses Climb to $387M: Here's What Happened, and Why North Korea Is a Suspect — Decrypt","type":"news_article","url":"https://decrypt.co/379350/bitget-hack-387m-what-happened-why-north-korea-suspect"},{"credibility":1,"name":"North Korea accused of plundering Bitget for $387 million in year's biggest crypto attack — Fortune","type":"news_article","url":"https://fortune.com/2026/09/25/north-korea-bitget-387-million-crypto-attack/"},{"credibility":2,"name":"Bitget Suffers Year's Largest Crypto Hack as Losses Top $387 Million — PYMNTS","type":"news_article","url":"https://www.pymnts.com/cryptocurrency/2026/bitget-suffers-years-largest-crypto-hack-as-losses-top-387-million/"},{"credibility":2,"name":"Bitget Confirms $351.6 Million Hack, Suspects North Korea's Lazarus Group — HackRead","type":"news_article","url":"https://hackread.com/bitget-hack-suspects-north-korea-lazarus-group/"},{"credibility":2,"name":"Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html"},{"credibility":2,"name":"Bitget's $387M hack: how spoofed requests got signed — Hypernative","type":"research","url":"https://www.hypernative.io/insights/blog/how-spoofed-requests-got-bitgets-own-wallets-to-sign-away-387m"},{"credibility":2,"name":"Investigator Finds $387M Bitget Hack Suspects Asking for Help in Public Chats — Yahoo News","type":"news_article","url":"https://www.yahoo.com/news/us/articles/investigator-finds-387m-bitget-hack-122401213.html"},{"credibility":2,"name":"Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/bitget-backend-breach/"},{"credibility":2,"name":"Bitget hacker routes 4 BTC through Wasabi CoinJoin — crypto.news","type":"news_article","url":"https://crypto.news/bitget-hacker-routes-4-btc-through-wasabi-coinjoin/"},{"credibility":2,"name":"ZachXBT Says Bitget Hack Funds Are Moving Through Cross-Chain Bridges and Wasabi — Bitcoin Ethereum News","type":"news_article","url":"https://bitcoinethereumnews.com/tech/zachxbt-says-bitget-hack-funds-are-moving-through-cross-chain-bridges-and-wasabi/"},{"credibility":2,"name":"Bitget Hack: NEAR Intents Blocks $50 Million in Stolen Crypto Funds — CoinCentral","type":"news_article","url":"https://coincentral.com/bitget-hack-near-intents-blocks-50-million-in-stolen-crypto-funds"},{"credibility":2,"name":"Bitget to resume withdrawals after $387.5M crypto hack — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/bitget-resume-withdrawals-387-5m-105934715.html"},{"credibility":2,"name":"Bitget CEO Gracy Chen affirms IPO plans despite $387.5M security breach — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/bitget-ipo-plans-security-breach/"},{"credibility":2,"name":"Bitget Taps Mandiant, SlowMist After $351M Security Breach — Bitcoin Ethereum News","type":"news_article","url":"https://bitcoinethereumnews.com/finance/bitget-taps-mandiant-slowmist-after-351-security-breach/"},{"credibility":2,"name":"Bitget Hack: $157M in Stolen XRP Sits in Wallets No One Can Freeze — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/exchanges/bitget-hack-xrp-157m-cannot-be-frozen/"},{"credibility":2,"name":"Bitget freezes XRP withdrawals as 27M stolen tokens move — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/bitget-freezes-xrp-withdrawals-as-27m-stolen-tokens-move/"},{"credibility":2,"name":"THORChain's response to Bitget's $387.5M hack sparks blacklist debate — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/28/thorchain-response-hack/"},{"credibility":2,"name":"Security Researcher ZachXBT Says 'He Will Not Monitor' the Bitget Hack Incident — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/25/security-researcher-zachxbt-says-he-will-not-monitor-bitget-hack-incident/"},{"credibility":2,"name":"Explained: The Kelp DAO Hack (April 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-kelp-dao-hack-april-2026"},{"credibility":2,"name":"Bitget Hack Investigation Uncovers Laundering Trail, North Korean Links — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/28/bitget-hack-investigation/"},{"credibility":2,"name":"Lazarus Group / TraderTraitor — DPRK September 2026 Blitz Campaign — AVOID.NET","type":"other","url":"https://avoid.net/lazarus-group-tradertraitor-dprk-september-2026-blitz-campaign"}],"summary":"On September 24, 2026, cryptocurrency exchange Bitget suffered the largest crypto exchange breach of 2026, with attackers draining approximately $387.5 million from the exchange's hot and warm wallets via a novel backend wallet infrastructure spoofing technique rather than private key theft. Bitget's CEO Gracy Chen stated that North Korea's Lazarus Group (also tracked as TraderTraitor) is the suspected perpetrator, a preliminary attribution corroborated by blockchain intelligence firm Elliptic and independent investigator ZachXBT, though no confirmed attribution has been publicly issued. Bitget's $464 million User Protection Fund was stated to cover customer losses in full; withdrawals were suspended and staged for reopening beginning September 28, 2026.","timeline":[{"date":"2026-09-24","event":"At 18:31 UTC, Bitget's security systems flag unauthorized transfers from hot and warm wallets. The exchange announces the breach; initial loss estimate is approximately $351.6 million. Trading and deposits continue; withdrawals are suspended.","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2026/09/24/crypto-exchange-bitget-loses-usd352-million-in-hack-claims-user-funds-are-safe"},{"date":"2026-09-25","event":"CEO Gracy Chen conducts a three-hour X livestream, stating the attack exploited backend wallet authorization infrastructure via spoofed transaction data, not private key theft. Bitget revises loss upward to $387.5 million after tracing additional affected assets on Zcash and Tron. Bounty program announced: 5% for freezing, 5% for recovery. North Korea 'very likely' cited as perpetrator. Elliptic corroborates DPRK attribution. BGB token drops ~7%. ZachXBT publicly declines to monitor the incident.","source":"Decrypt / CoinDesk / Fortune","source_url":"https://decrypt.co/379350/bitget-hack-387m-what-happened-why-north-korea-suspect"},{"date":"2026-09-25","event":"Tether and Circle freeze approximately $318,013 in USDT and USDC linked to attacker wallets.","source":"CoinCentral / Yahoo Finance","source_url":"https://coincentral.com/bitget-hack-near-intents-blocks-50-million-in-stolen-crypto-funds"},{"date":"2026-09-26","event":"Approximately $83 million of the 103 million stolen XRP (worth ~$157M) is moved from initial holding wallets; ~$75 million in XRP remains in wallets that cannot be frozen by Ripple or any other party under XRP Ledger rules. Bitget freezes its own XRP withdrawal functions.","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2026/09/26/bitget-hacker-moves-usd83-million-in-stolen-xrp-that-ripple-cannot-freeze"},{"date":"2026-09-26","event":"Bitget announces staged withdrawal reopening schedule: BTC at 08:00 UTC September 28, ETH September 29, USDT September 30, other tokens and fiat by October 2.","source":"Yahoo Finance","source_url":"https://finance.yahoo.com/markets/crypto/articles/bitget-resume-withdrawals-387-5m-105934715.html"},{"date":"2026-09-28","event":"THORChain formally refuses Bitget's request to block attacker addresses, citing permissionless design. Approximately $6 million in stolen funds moves to Bitcoin via THORChain swaps. NEAR Intents' SHIELD system blocks more than $50 million in attempted stolen fund transfers; NEAR Intents declines the 5% bounty. Bitget Bitcoin withdrawals reopen at 08:00 UTC.","source":"CoinDesk / CoinCentral","source_url":"https://www.coindesk.com/tech/2026/09/28/thorchain-rejects-bitget-request-to-block-hacker-as-usd6-million-moves-to-bitcoin"},{"date":"2026-09-28","event":"ZachXBT publishes laundering trail analysis naming five suspect aliases ('jack,' 'HELP ME,' 'Melon,' 'Cc,' 'lolo' / 'Marin'). Investigator identifies the operators as alleged Chinese illicit actors working on behalf of DPRK attackers, and links 'lolo' / 'Marin' to the April 2026 Kelp DAO exploit ($292M). Suspects had publicly posted support requests in Discord and Telegram channels of the services they used to launder funds.","source":"Yahoo News / CyberSecurityNews","source_url":"https://www.yahoo.com/news/us/articles/investigator-finds-387m-bitget-hack-122401213.html"},{"date":"2026-09-28","event":"At least 4 BTC from stolen proceeds routed through Wasabi CoinJoin mixer, reported by crypto.news.","source":"crypto.news","source_url":"https://crypto.news/bitget-hacker-routes-4-btc-through-wasabi-coinjoin/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision fda0dad5-0134-443a-97e8-d16468e2b78d
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.