Sun. Sep 27th, 2026

Bitget Says Backend Wallet System Was Compromised in $387.5M Breach

ByJohan Shamshad

September 27, 2026 #Bitget
BitgetBitget

Bitget has disclosed its clearest explanation yet of how attackers were able to move approximately $387.5 million from the crypto exchange, saying a critical backend system inside its wallet infrastructure was compromised and used to feed false transaction data into the platform’s authorization process.

The preliminary finding significantly narrows the technical picture of the September 24 breach. According to Bitget, the attacker did not obtain the private keys controlling the affected wallets. Instead, the attacker compromised infrastructure involved in preparing or processing transactions, spoofed transaction data and triggered Bitget’s existing authorization process to approve transfers that the exchange had not intended to make.

Bitget said it has identified the attack path and the methods used to bypass existing security controls. The underlying vulnerability has been remediated, and the company says no additional unauthorized transfers have been detected since containment. Cybersecurity firms Mandiant and SlowMist are supporting the forensic investigation and fund-tracing effort.

The new details follow Bitget’s decision to raise the estimated impact of the breach to $387.5 million, up from the initial estimate of $351.6 million. Bitget said the increase reflects additional Zcash and TRON transactions identified during the investigation rather than a second attack or transfers occurring after containment.

The Attack Reached Hot and Warm Wallet Infrastructure, Not Private Keys

Bitget detected the unauthorized transfers at approximately 18:31 UTC on September 24. The affected infrastructure included portions of the exchange’s hot and warm wallet systems across Ethereum and other EVM-compatible networks, the XRP Ledger, Zcash and TRON.

Confirmed affected assets include ETH, XRP, BNB, ZEC, USD0, XAUT, AVAX, TRX, USDT and USDC. Bitget says its cold wallets were not affected, while Bitget Wallet, the company’s separate non-custodial wallet product, operates on different infrastructure and was also unaffected.

The distinction between a backend compromise and stolen private keys is important. Private keys are ultimately what authorize blockchain transactions, but protecting the keys alone does not necessarily make a custody system safe. If another trusted system can provide manipulated transaction instructions to a legitimate signing process, an attacker may still be able to produce valid blockchain transactions without ever obtaining the keys themselves.

That separates Bitget’s preliminary findings from security incidents in which attackers appear to gain persistent access to signing credentials. A recent XRP wallet drain involving D’CENT, for example, highlighted the very different risk created when wallet credentials apparently remain usable after an initial theft.

Bitget has not yet published a complete forensic report detailing the initial intrusion vector, the exact component that was compromised or every control that failed before the transactions reached the authorization stage. Those questions remain central to determining whether the incident resulted from a narrow vulnerability or exposed a broader weakness in the exchange’s wallet architecture.

Withdrawals Are Due to Restart as Stolen Funds Continue Moving

Bitget has moved from containment toward restoring customer services. Under the exchange’s phased withdrawal restoration schedule, Bitcoin withdrawals are due to reopen at 08:00 UTC on September 28.

Ether withdrawals are scheduled for September 29 across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism, followed by USDT on September 30 across Ethereum, BNB Smart Chain, Solana and TRON. Other tokens, fiat withdrawals and P2P services are scheduled to return on October 2.

Trading and deposits have continued during the suspension. Bitget says customer account balances remain unaffected and that its Protection Fund will cover the financial impact of the incident.

The recovery side is more complicated because the stolen portfolio contains assets with very different control structures. Native cryptocurrencies such as XRP, Bitcoin and Ether cannot simply be frozen by an issuer. Centralized stablecoins can be different: mechanisms that have previously allowed Tether to freeze specified USDT wallets and enabled USDC addresses to be blacklisted can become important recovery tools once stolen assets are identified.

By September 26, roughly 54 million of the approximately 103 million XRP taken in the breach had moved out of the five original holding accounts, worth around $83 million at the time. About $75 million worth of XRP remained in those original accounts. Ripple cannot freeze native XRP at the ledger level, although centralized exchanges receiving stolen tokens can restrict accounts associated with them.

Circle and Tether had separately frozen about $320,000 in stablecoins connected to the incident. Blockchain compliance firm AMLBot also said it traced roughly 4 BTC connected to the stolen funds into a Wasabi CoinJoin transaction after assets moved through TRON, USDT, Ethereum and THORChain. That attribution remains blockchain-analysis work rather than a final Bitget recovery figure, but it illustrates how quickly the tracing problem can become more difficult once funds move across assets and networks.

Why the Backend Compromise Is the More Important Security Question

The headline number is enormous, but the most important part of Bitget’s latest disclosure may be where the control failure apparently occurred.

Crypto custody is often discussed as if security begins and ends with protecting private keys. In practice, a major exchange runs a much longer chain: withdrawal requests, account controls, risk engines, transaction construction, policy checks, approval systems, signing infrastructure, broadcasting, reconciliation and real-time monitoring all sit around those keys.

If Bitget’s preliminary explanation holds, the keys did what they were designed to do. They signed transactions presented through an authorized workflow. The problem was that the workflow had already been poisoned.

That is uncomfortable because it means an exchange can have uncompromised keys and secure cold storage while still losing hundreds of millions of dollars from online operational wallets. The next forensic report therefore needs to explain whether the signing layer independently checked destination addresses, transaction values and other critical data rather than trusting information supplied by the compromised backend.

It also raises the question of circuit breakers. For a platform handling this much capital, investors will want to know what automated limits existed for unusual withdrawal velocity, abnormal cross-chain activity or sudden concentration of transfers to newly created addresses, and why those protections did not stop the unauthorized flow earlier.

Reopening Withdrawals Will Be the First Test, Not the Final One

The September 28 Bitcoin withdrawal restart will give users a visible indication that Bitget believes the rebuilt infrastructure is ready for production. Other platforms have also moved from containment to service restoration after security incidents; Blink’s restoration of services after a custodial-account breach showed how operational recovery and root-cause accountability can remain separate issues.

That distinction matters even more for Bitget given the size of the loss.

A smooth return of BTC, ETH, USDT and eventually the wider withdrawal system would reduce immediate operational uncertainty. It would not explain why fraudulent transaction data reached an authorization process capable of moving almost $400 million.

Three things now matter most. First is whether withdrawals resume on schedule without new security interruptions. Second is whether the eventual forensic report provides enough technical detail to demonstrate that the underlying architecture has been strengthened rather than simply patched. Third is how much of the stolen portfolio Bitget ultimately freezes or recovers, because that determines how much of the $387.5 million economic loss the company and its Protection Fund must absorb.

The latest disclosure is therefore reassuring in one narrow sense: Bitget says the attack path is known, the vulnerability has been remediated and the private keys were not compromised.

But it also sharpens the harder question. The breach appears to have succeeded not by breaking the cryptography protecting Bitget’s wallets, but by getting Bitget’s own infrastructure to authorize transactions that should never have been approved. For investors and customers assessing what happens next, proving that this authorization chain has been redesigned to resist the same class of attack will matter more than simply turning withdrawals back on.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *