• Bitget raised estimated hack losses to about $387.5M after confirming additional ZEC and TRX damage.
• Elliptic on-chain analysis ties the laundering pattern to North Korea-linked group TraderTraitor.
• North Korea-linked hackers have stolen roughly $1.2 billion across more than 50 incidents in 2026.
Backend Breach, Not a Leaked Key
Bitget chief executive Gracy Chen said on Sept. 25 that the unauthorized outflows detected a day earlier were carried out by an attacker who compromised a critical backend system inside the exchange's wallet infrastructure — not by anyone obtaining the exchange's private key. According to Chen, the intruder fabricated transaction data to manipulate the approval workflow, tricking the signing process into authorizing transfers to external addresses. Because the core signing credentials never left Bitget's control, she said, the most severe risk scenarios can be ruled out, and the incident has been contained, with no further unauthorized fund movements possible. The distinction matters: a key leak would have exposed even the deepest storage tiers, whereas an operational breach of the approval layer leaves the vault perimeter intact.
The entry path into the backend is still under investigation. Bitget said a detailed technical report will follow once every finding is verified, and the company pointedly declined to commit to any deadline it could not guarantee — a contrast with the rushed restoration promises that often follow exchange incidents. Withdrawal functionality is being rebuilt in parallel with system repair and security hardening, with a timeline to be published once confirmed.
The financial picture worsened as forensics progressed. Bitget had estimated the damage at $351.6 million as of Sept. 25, but follow-up on-chain analysis confirmed additional losses tied to Zcash (ZEC) and Tron (TRX) holdings, lifting the estimate to roughly $387.5 million — one of the largest recorded exchange security losses of 2026. The exchange's custody design limits the blast radius: assets sit across a three-tier wallet structure, and the offline cold wallets were untouched, with the breach confined to portions of the hot and warm wallets that handle day-to-day liquidity. Bitget reiterated that its $464 million user protection fund will absorb the entire shortfall, keeping user balances whole.
Laundering Trail Points to TraderTraitor
On-chain forensics have given the incident a geopolitical dimension. Blockchain analytics firm Elliptic traced the laundering path and found that the attackers converted the stolen tokens into other assets within hours of the initial outflow and moved them across chains, routing value through decentralized venues' liquidity pools and automated market maker mechanisms before splitting it further. According to Elliptic, the wallet clusters, swap patterns and address overlaps match the fingerprint of TraderTraitor, a North Korea-aligned hacking collective — and some of the receiving addresses connect to previous operations attributed to the same group, including wallets linked to Bybit's record $1.5 billion theft last year. The speed of the conversion is characteristic of state-linked operations, which prioritize turning volatile holdings into harder-to-trace assets before exchanges can freeze them.
The attribution fits a broader 2026 pattern. By Elliptic's tally, North Korea-linked actors have been involved in more than 50 digital asset security incidents this year, with cumulative thefts of roughly $1.2 billion. Over the past decade, the sanctions-constrained regime has treated crypto-service providers as a revenue channel, moving billions of dollars in digital assets since 2017. Analysts tracking the sector note that adversaries are increasingly folding AI tooling into reconnaissance and exploit development, raising the sophistication of cross-chain attacks.
Bitget has brought in Mandiant and SlowMist to trace the attack source and the exploited weakness. In her public update on X, Chen said the platform is working at full speed to prepare the restoration of withdrawals, with the complete plan due to be published at 04:00 UTC on Sept. 26 — noon in Taipei. The withdrawal halt, imposed the moment the unauthorized transfers were detected, remains in force until then. The exchange has confirmed the affected assets span multiple tokens, with the ZEC and TRX exposure identified only after deeper on-chain tracing.
Approval Layer Was the Failure Point
The Bitget breach, in COINOTAG's reading, turns on one technical distinction: the attacker fed falsified data into the exchange's signing and smart contract approval layer rather than extracting cryptographic keys, which is why the deepest custody tier held while the operational layer failed. The team's post-mortem and Chen's public statements confirm both the root cause — a compromised backend system — and the remediation path: containment of the outflows, full coverage through the $464 million protection fund, external forensics from Mandiant and SlowMist, and a phased withdrawal restoration. The undisclosed variable is the initial entry vector. Until Bitget publishes its technical report, the $387.5 million question for every multi-tier exchange is how much trust its approval pipeline deserves.
