Bitget records $463M in net outflows after hack steals up to $388M from exchange

Photo: Pixabay / Pexels

Bitget records $463M in net outflows after hack steals up to $388M from exchange

The largest single-day customer withdrawal event in four years has left Bitget's user protection fund significantly depleted as investigators probe North Korean links.

Bitget, one of the world’s top ten crypto exchanges by trading volume, watched $463 million walk out the door in a single day after a security breach drained hundreds of millions from its hot wallets. The September 29 outflow figure represents the largest single-day withdrawal event tracked by DefiLlama in four years.

The breach itself occurred on September 24, when attackers exploited a vulnerability in a third-party security product to inject spoofed transaction data into Bitget’s authorization process. The revised loss estimate sits between $387.5 million and $388 million, up from the initial $351.6 million figure reported in the immediate aftermath.

How the attack unfolded

The attackers ran two smaller test transfers first, probing Bitget’s risk controls before executing the main unauthorized withdrawal.

Advertisement

Bitget’s private keys were never compromised, and cold storage wallets remained untouched. The vulnerability lived in a third-party security product that interfaced with the exchange’s backend systems, allowing the attackers to spoof transaction data that looked legitimate to Bitget’s authorization layer.

The trust deficit

Bitget holds roughly $5.7 billion in reserves, which means the hack represented approximately 6.8% of total holdings.

Bitget initiated a phased resumption of withdrawals starting September 28, four days after the breach.

The exchange had maintained a User Protection Fund specifically designed for incidents like this. Before the hack, that fund exceeded $464 million, roughly enough to cover the stolen amount. Post-incident, the fund has reportedly fallen below $200 million, having absorbed a substantial portion of user losses.

If the fund started above $464 million and dropped below $200 million, that’s at least $264 million deployed. The total loss was $387.5 to $388 million.

The Lazarus connection

CEO Gracy Chen disclosed that initial forensic indicators point toward North Korean threat actors, specifically the Lazarus Group. Mandiant and SlowMist, two well-known cybersecurity and blockchain forensics firms, are assisting with the ongoing investigation.

The pattern of test transactions before the main theft is consistent with tactics previously attributed to the group.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.
Bitget records $463M in net outflows after hack steals up to $388M from exchange
Bitget records $463M in net outflows after hack steals up to $388M from exchange

The largest single-day customer withdrawal event in four years has left Bitget's user protection fund significantly depleted as investigators probe North Korean links.

Share

Add us on Google

Photo: Pixabay / Pexels

Bitget, one of the world’s top ten crypto exchanges by trading volume, watched $463 million walk out the door in a single day after a security breach drained hundreds of millions from its hot wallets. The September 29 outflow figure represents the largest single-day withdrawal event tracked by DefiLlama in four years.

The breach itself occurred on September 24, when attackers exploited a vulnerability in a third-party security product to inject spoofed transaction data into Bitget’s authorization process. The revised loss estimate sits between $387.5 million and $388 million, up from the initial $351.6 million figure reported in the immediate aftermath.

How the attack unfolded

The attackers ran two smaller test transfers first, probing Bitget’s risk controls before executing the main unauthorized withdrawal.

Advertisement

Bitget’s private keys were never compromised, and cold storage wallets remained untouched. The vulnerability lived in a third-party security product that interfaced with the exchange’s backend systems, allowing the attackers to spoof transaction data that looked legitimate to Bitget’s authorization layer.

The trust deficit

Bitget holds roughly $5.7 billion in reserves, which means the hack represented approximately 6.8% of total holdings.

Bitget initiated a phased resumption of withdrawals starting September 28, four days after the breach.

The exchange had maintained a User Protection Fund specifically designed for incidents like this. Before the hack, that fund exceeded $464 million, roughly enough to cover the stolen amount. Post-incident, the fund has reportedly fallen below $200 million, having absorbed a substantial portion of user losses.

If the fund started above $464 million and dropped below $200 million, that’s at least $264 million deployed. The total loss was $387.5 to $388 million.

The Lazarus connection

CEO Gracy Chen disclosed that initial forensic indicators point toward North Korean threat actors, specifically the Lazarus Group. Mandiant and SlowMist, two well-known cybersecurity and blockchain forensics firms, are assisting with the ongoing investigation.

The pattern of test transactions before the main theft is consistent with tactics previously attributed to the group.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.