This week's report covers the largest failure of the week by any measure: roughly $387.5m left Bitget's exchange wallets on 24 September 2026 through the exchange's own signing process — larger than every on-chain incident this series has covered, and, per Bitget, produced without a single forged signature or stolen key.
We chose it because it moves the pattern this column has been tracking on-chain into centralised infrastructure. Liquid was value created upstream and accepted downstream; rsETH was a valid instruction, reordered; Bitget is a fabricated instruction, signed — and at every moment, the authorisation was genuine.
1 1. In brief
On 24 September 2026, at 18:31 UTC, Bitget's monitoring flagged unauthorised transfers leaving some of its hot and warm wallets. By the time the accounting settled the next day, roughly $387.5m had moved to attacker-controlled addresses — and, per Bitget, not one private key had been stolen. The attacker compromised a third-party security product, used it to obtain high-level internal credentials, and fed false transaction data into the wallet-management backend, which triggered Bitget's own authorisation process to sign the transfers.
The initial estimate was $351.6m; the revision to $387.5m on 25 September added Zcash and TRON transfers to the accounting and, per Bitget, did not represent additional unauthorised outflows. Per Bitget, cold wallets and user account balances were untouched, and the loss sits within the coverage of Bitget's User Protection Fund, valued at over $464m in the first notice.
2 2. Background: how an exchange wallet stack is supposed to work
A centralised exchange runs its custody in tiers. Cold wallets hold the bulk of assets offline and never touch the network. Hot and warm wallets hold working balances for withdrawals, and every payout they make is supposed to pass through a wallet-management backend: a system that checks the request, records it, and drives the exchange's own authorisation and signing process. That backend is infrastructure — the DeFi analogue of a Safe module or an oracle, a convenience layer that sits between intent and execution.
The trust model rests on one assumption: the data the backend acts on is true. If the transaction records fed into the authorisation process are accurate, the signatures it produces are legitimate by construction. Nobody re-verified the input, because the input came from inside.
One structural point matters for everything that follows. The vulnerability was not in a blockchain, a bridge, or a smart contract. It was in a centralised operator's own control plane — the same category of failure this series has been tracking on-chain for weeks, moved onto infrastructure that predates DeFi's discipline of never trusting a single input.
3 3. Mechanism: credentials, then a spoofed feed
Reconstructing the sequence from Bitget's statements gives a path with four steps and no signature forgery at any of them.
| # | Step | What happened | Why it passed |
|---|---|---|---|
| 1 | Third-party foothold | A flaw in a third-party security product exposed high-level internal credentials | The product sat inside the trust boundary, so its compromise was invisible |
| 2 | Backend access | The attacker used the credentials to reach the wallet-management backend | The credentials were genuine and high-level |
| 3 | Spoofed transaction data | False transaction information was fed into the backend | The backend trusted its input feed |
| 4 | Self-authorised payouts | Bitget's own authorisation process signed the transfers | The signatures were genuine — produced by the system designed to produce them |
On-chain, the movement was fast and brazen. Within the hour, on-chain analysts flagged a fresh wallet spending $19.67m of USDT0 to buy 7,111 ETH in six minutes on Arbitrum, paying up to 5% over market through UniswapX and 1inch Fusion to get the size done. That evening, Bubblemaps tracing linked roughly $180m of the outflows across multiple chains to a single address, and Lookonchain later put the EVM-side consolidation at about $183m of ETH. Speed over stealth is the signature of an actor who assumed the freezes would come and priced the discount in.
The composition of the take shapes the recovery: on-chain reporting puts XRP at about $157.5m (roughly 40%), ETH at about $85.8m (31,890 ETH, roughly 22%), plus USDT, USDC, XAUt, BNB, AVAX and TRX across multiple chains — which is why the response had to be multi-chain too.
4 4. Root cause: an authorisation process that trusted its own input
An authorisation system needs to bind every payout it signs to something it can verify. Bitget's backend bound it to the transaction data in front of it — and that data was fabricated. The signatures were genuine outputs of a genuine process; the process was lied to.
In plain terms, the exchange's control plane authorised payouts using data it did not independently verify, from a feed it did not treat as an attack surface. The third-party security product — installed to strengthen the perimeter — became the way in. That inversion is the defect in one sentence.
The failure is therefore not in any chain's consensus, not in a bridge contract, and not in key custody. Every component behaved as specified. The specification itself contained the gap: an authorisation path with no independent check between the input feed and the signature, reachable by anyone who controlled the feed.
5 5. Detection, response and the recovery plan
The breach was detected by Bitget's own monitoring within the transfer window, at 18:31 UTC on 24 September. The company's first notice came that night with the $351.6m estimate and a precautionary suspension of withdrawals; deposits and trading continued throughout. Mandiant and SlowMist were engaged as investigation partners, and the revised $387.5m figure followed on 25 September after further transaction classification.
Four response commitments matter for assessing the outcome. First, the underlying vulnerability was identified and remediated, with no further unauthorised transfers after containment. Second, the loss falls within the User Protection Fund, valued at over $464m — user balances unaffected. Third, tracing and freezing started immediately: Circle had frozen roughly 99,990 USDC and Tether about 218,023 USDT linked to the attack by 26 September, alongside a 5% bounty programme for freezes and recoveries. Fourth, withdrawals restart on a published schedule — BTC on 28 September, ETH on 29 September, USDT on 30 September, and remaining services on 2 October — each phase gated on security checks.
Context is worth recording honestly. Bitget's chief executive has said the IP addresses and patterns resemble activity previously linked to North Korean groups, while the company itself has not confirmed attribution and the forensic investigation continues. The restart schedule is an unusually specific commitment; holding to it, and publishing a recovery percentage for the $387.5m, is how the response should be judged.
6 6. Data: the numbers, and what each one measures
This incident produced a small set of quantities, and conflating them is how coverage of it goes wrong. Each row below is a different measurement.
| Quantity | Value | What it measures | Source |
|---|---|---|---|
| Initial estimate | $351.6m | Assets affected, first notice (24 Sep) | Bitget |
| Revised estimate | ~$387.5m | Total moved to attacker addresses after adding ZCASH and TRON | Bitget (25 Sep) |
| Largest single asset | 102.93m XRP (~$157.5m) | About 40% of the revised total, on one chain | On-chain reporting |
| ETH component | 31,890 ETH (~$85.8m) | About 22% of the take | On-chain reporting |
| Attacker's first conversion | 7,111 ETH for $19.67m USDT0 | Speed of exit liquidity, inside 6 minutes | On-chain analysts |
| Frozen by issuers (26 Sep) | ~99,990 USDC + ~218,023 USDT | Recovery in progress, not recovered | Circle / Tether via press |
| Protection fund | >$464m | Coverage capacity for the loss | Bitget |
The derived number worth stating plainly is the conversion discount. The attacker paid up to 5% over market to move $19.67m into ETH within minutes — roughly $1m sacrificed for immediacy on one slice of the take. That premium is the real-time price of exiting before freezes land, and it is the cleanest on-chain evidence that speed, not stealth, was the plan.
7 7. The same window, three different layers
Bitget was the largest of three failures in the same seven days, and the three make a controlled comparison almost nobody would design on purpose.
| Date | Venue | How value moved | Reported loss | Contained by |
|---|---|---|---|---|
| 24 Sep | Bitget (CEX) | Spoofed backend data drove the exchange's own signing process | ~$387.5m | Withdrawal pause; phased restart; issuer freezes |
| 19-24 Sep | MultiversX (L1) | VM-level atomicity flaw produced invalid state changes | None confirmed; attacker accounts frozen | Five-day mainnet pause; restart 24 September via targeted recovery |
| 22 Sep | Astroport (Neutron) | Admin privileges for the contracts may have been stolen | ~$4.9m | Full chain halt to investigate |
The finding is the same shape as recent weeks, stated one level up. Liquid created value upstream; Symbiosis minted it; Chainflip paid twice; Nostra borrowed against a phantom price; rsETH let a valid instruction be reordered; Bitget signed a fabricated one. In every case the realised loss equals the exit liquidity the attacker could reach before someone pulled a switch — and this time the switch was a withdrawal pause that landed ninety minutes late.
8 8. Impact assessment: who is actually exposed
| Layer | Who is affected | Immediate effect | Resolution depends on |
|---|---|---|---|
| Bitget users | Anyone withdrawing from the exchange | Withdrawals paused, then phased restart from 28 Sep | The restart holding to schedule; balances already intact |
| Bitget's balance sheet | The exchange and its protection fund | A ~$387.5m loss against a >$464m fund | Recovery percentage and the forensic report |
| Exchange counterparty risk | Every CEX user | Re-pricing of 'the exchange's own system approved it' | Whether input verification becomes a standard control |
| Third-party security products | Vendors embedded in operator infrastructure | A demonstrated path from vendor flaw to nine-figure loss | How operators re-assess what a security product is trusted with |
That last row is the one to generalise. The industry now has a catalogue of 'trusted step, unverified input' failures spanning smart contracts (modules, oracles, bridges), protocol operations (admin keys) and now centralised custody. The fix is unglamorous and identical in every case: bind every payout to independently verified data, and treat the approval layer — internal or on-chain — as the attack surface rather than the safety mechanism.
9 9. What this changes for due diligence
- For exchange users: counterparty risk now includes the operator's software supply chain — a flaw in a third-party security product became a nine-figure loss. Treatment of exchange balances as unsecured claims is the prudent default, not pessimism.
- For operators: ask what your authorisation process would sign if its input feed lied, and whether any independent check sits between the feed and the signature.
- For recovery planning: issuer freezes (USDC, USDT) moved within forty-eight hours — the faster attacker addresses are published, the more of the take is freezable.
- For incident response: a published, phased restart schedule is a credibility instrument. Announcing dates and holding to them is worth more than any statement of intent.
10 10. What would change our read
This assessment rests on Bitget's own notices and public on-chain reporting, published before the forensic investigation concludes. It would change materially if the forensic report attributes the entry path to something other than the third-party security product, if the $387.5m figure moves again, if attribution to North Korea-linked actors is confirmed or discarded on evidence, or if the recovery share diverges sharply from the freeze totals visible so far. The restart schedule and the recovery percentage are the specific things to read as they arrive.
The broader conclusion does not depend on those details. Seven failures over the past four weeks — Liquid, Nomic, Symbiosis, Chainflip, Nostra, rsETH and now Bitget — share one assumption: that the step before the payout had been checked. The list now spans bridges, oracles, modules and a centralised backend. Until independently verified inputs are standard at every layer rather than a post-incident upgrade, that is the distribution to expect: frequent small failures, and occasional nine-figure ones that never touched a private key.
11 11. In brief
Bitget lost roughly $387.5m because attackers compromised a third-party security product, used the credentials to feed false transaction data into the wallet-management backend, and let the exchange's own authorisation process sign the transfers — no private key was stolen and, per Bitget, no cold wallet was touched. The response — a $464m protection fund, issuer freezes within forty-eight hours, and a phased withdrawal restart from 28 September — is now the credibility test.
For the wider system, the lesson is the same one Liquid, Chainflip, Nostra and rsETH taught in the same month, stated one level up: the unguarded step is wherever the last person assumed the previous step had checked it. The fix is boring, known, and not yet standard — at any layer of the stack.
Sources & Methodology
- Bitget — incident notices of 24 and 25 September, the 26 September withdrawal update, and the protection-fund valuation.
- Mandiant and SlowMist — the forensic investigation into the breach, as named by Bitget.
- Infosecurity Magazine and The Hacker News — independent coverage of the timeline and the third-party product finding.
- Galaxy Digital and on-chain analysts — the XRP/ETH composition, the 7,111 ETH conversion and the cluster tracing.
- Circle and Tether — freeze totals reported via press coverage on 26 September.
- MultiversX and Astroport — context on the same window's L1 and admin-key incidents used in the comparison.
- DefiLlama — context on tracked-chain volumes used for the conversion-cost analysis.
Headlines and figures on this page are drawn from the outlets listed above; commentary is clearly labelled opinion and is not investment advice. Last reviewed 2026-09-28.