#circletetherfreezebitgethackerwallet

Bitget Hack Explained: How $387.5M Was Stolen Without Private Keys

Bitget is dealing with one of the largest crypto security incidents of 2026 after attackers moved approximately $387.5 million from parts of the exchange’s hot and warm wallet infrastructure.

What makes the incident unusual is that the attackers reportedly did not steal private keys.

Bitget detected unauthorized transfers at 18:31 UTC on September 24, initially estimating the affected assets at about $351.6 million. The figure was later raised to $387.5 million after on-chain investigators identified additional assets involving networks including Zcash and TRON.

The attack reportedly targeted the backend

According to Bitget CEO Gracy Chen, investigators ruled out a direct private-key compromise.

Instead, the attacker reportedly compromised a critical backend system within Bitget's wallet infrastructure and spoofed transaction data. The altered information was then processed by the exchange's normal authorization system, causing transactions to appear legitimate to the signing process.

That distinction is important.

The incident was not simply a case of someone obtaining a private key and draining a wallet. The reported attack targeted the infrastructure that tells the wallet system what transaction it is actually approving.

Bitget said its cold wallets were not affected, while the investigation continued with assistance from cybersecurity firms including Mandiant and SlowMist.

Where did the money go?

On-chain trackers identified large quantities of XRP, ETH, USDT, USDC and other assets among the transferred funds. Bitget's later revision added assets that were not included in its initial estimate.

The attackers also began converting portions of the stolen assets into other cryptocurrencies, making recovery more difficult.

Circle and Tether were able to freeze approximately $318,000 worth of USDC and USDT connected to the attack. However, that amount represents only a small fraction of the total funds involved.

Bitget says its protection fund can cover the loss

Bitget has said its User Protection Fund, valued at more than $464 million, is sufficient to cover the affected customer funds. The exchange has also stated that customer account balances remain accurate.

Withdrawals were temporarily suspended following the incident while Bitget investigated and secured the affected infrastructure.

The exchange has announced a phased restart beginning September 28, with additional assets scheduled to follow through October 2.

Bitget CEO Gracy Chen has publicly linked the attack to North Korean-linked actors, citing IP addresses and similarities in laundering patterns.

Blockchain intelligence firm Elliptic has also assessed that the incident was highly likely to be connected to North Korean operators. However, attribution of cyberattacks can evolve as investigators examine additional evidence, so the distinction between reported attribution and independently established identity remains important.

Why this breach matters

The Bitget incident highlights a security problem that goes beyond protecting private keys.

Cold storage can protect assets from direct wallet compromise, but exchanges also depend on backend infrastructure, transaction-generation systems, authorization layers and monitoring tools.

If an attacker can manipulate the information presented to an authorization system, the security model can potentially be challenged without directly stealing the underlying signing keys.

For crypto exchanges, the question after Bitget is therefore not only “Are the private keys secure?”

It is also:

“Can the system accurately verify what those keys are being asked to sign?”

That distinction could become one of the most important security lessons from the Bitget incident.