Bitget's own timeline (UTC+8, September 25): at 02:31 the attacker sent tiny test transfers — 0.84 ETH and 93 TRX — small enough to stay under risk-control thresholds. Between 02:58 and 04:09 came 17 large transfers across XRP Ledger, ZEC, BSC, Base, Arbitrum, Optimism and other chains, roughly $360 million. The reconciliation system flagged a discrepancy at 03:05 and automatically blocked user withdrawals; a P0 emergency response started at 03:14. A second wave of seven transfers on Avalanche and other chains (about $28M) followed between 04:55 and 05:13, and at 05:44 the team shut down withdrawal services, including signing machines. The root cause was identified at 16:43 the same day and a report filed with authorities at 21:42. Deposits reopened around noon on September 26; BTC withdrawals reopened September 28, with ETH, USDT and fiat rails to follow.
This was not a leaked private key and not a user-side compromise. Per Bitget's root-cause analysis, the attacker exploited a zero-day vulnerability in a third-party security product to steal internal network credentials, entered key management systems with a valid identity, then accessed wallet-related backend services and wrote forged withdrawal instructions directly — bypassing risk checks before any withdrawal record existed — moving funds out of warm and hot wallets and deleting traces after each transfer. No common malware was involved; Bitget calls it a highly targeted operation and has preliminarily ruled out insiders. CEO Gracy Chen said investigators found IP addresses matching VPN patterns of a known DPRK group and that "the pattern looks very much like what the North Korean team did before." North Korean crews were linked to about $2.02 billion of crypto theft in 2025, including the $1.5 billion Bybit hack. A formal report is due this week.
Affected assets include ETH, XRP, BNB, AVAX, USDT and USDC across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base — the XRP Ledger saw the largest single-chain loss. Several chain foundations have frozen hacker addresses and some funds have been recovered. The attacker has been swapping ETH for BTC through THORChain, which answered criticism by pointing out it is permissionless like Bitcoin or Ethereum; an attempt to route funds through Chainflip failed when the broker rejected the deposits and returned them. Blockchain-analytics firm MistTrack is tracking the remainder.
Bitget has been clearer and faster than most exchanges in this situation: trading and deposits stayed or came back online, the Protection Fund (5,500 BTC at verifiable addresses) will absorb the loss and be replenished, and compensation terms are to be announced separately. That is the right response — and it is still a promise, not a guarantee. Until a balance is back in a wallet you control, it is counterparty exposure. Three practical steps: withdraw what you do not actively trade as rails reopen (BTC first); ignore the timing of the post-hack "Alliance Program" (a 30% fee-revenue reward pool running September 28 to October 26 — a retention promo, not compensation); and if you are in the EEA, remember Bitget does not yet hold a MiCA licence, while licensed alternatives exist. Bitget stays on our deals page with a warning, because the bonus terms did not change — but the risk framing did.
Bitget says user funds are covered 1:1 from its Protection Fund of 5,500 BTC (about $464 million, held at publicly verifiable addresses) and that cold wallets were not affected. Deposits reopened on September 26 and BTC withdrawals on September 28; other assets and fiat are being restored gradually. Cover is a promise from the exchange, not a legal guarantee, so treat any balance you cannot withdraw yet as counterparty exposure until it is back in your wallet.
According to Bitget's root-cause analysis, the attacker exploited a zero-day vulnerability in a third-party security product to steal internal network credentials, entered internal management systems with a valid identity, wrote forged withdrawal instructions directly into wallet backend services (bypassing risk checks) and deleted traces after each transfer. No private keys were leaked, no malware was used, and insider involvement has been preliminarily ruled out. CEO Gracy Chen said IP addresses match VPN patterns of a North Korean group.
ETH, XRP, BNB, AVAX, USDT, USDC and other tokens across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base, with the XRP Ledger seeing the largest single-chain loss. Bitget's timeline puts the main wave at 17 large transfers worth about $360 million between 02:58 and 04:09 (UTC+8) and a second wave of about $28 million; the exchange's stated exposure is $351.6 million.
That is your call, and Bitget remains listed on our deals page with a warning. Two facts matter: the exchange is covering losses and kept trading online throughout, which is the right response; but it does not yet hold a MiCA licence for the EEA, so EU-based readers already have licensed alternatives. For savings, the lesson is the same as after Bybit in 2025: an exchange is a counterparty, and a hardware wallet removes that risk entirely.
Why self-custody is the only real fix →Join The Crypto Edge — our free weekly briefing for sober crypto investors. New subscribers get our DCA ebook. No spam, no hype.
Subscribe free →HomeCryptoInvest is independent — no sponsored rankings, real testing with our own money. If our coverage saved you time, you can buy us a coffee.
Buy me a coffee →Disclosure: Bitget is an affiliate partner of HomeCryptoInvest; we earn a commission if you sign up through our deals page. That relationship did not soften this update, and no affiliate links appear in it. Sources: Bitget statements and livestream timeline, CoinDesk, Cointelegraph, BlockBeats, MistTrack, Foresight News. Not financial advice. Disclosure · Privacy