Research details
Context
Starting at 18:31 UTC on 24 September 2026, about US$387.5 million left Bitget’s hot and warm wallets. Bitget says no private keys were compromised. Instead, an attacker who reportedly entered through a zero-day in a third-party security product obtained valid admin credentials and injected forged withdrawal commands that Bitget’s own signers executed. This analysis was written while Bitget’s formal incident report was still pending, and labels each finding by its basis: on-chain records, Bitget statements, third-party research, or our own analysis. It will be updated when forensic reports are published.
Key takeaways
- The signers worked as designed, and that was the problem. Everything between a system asking for a transfer and the signer signing depended on the backend and admin credentials being trustworthy. Certifications focused on key custody would not have covered this trust boundary, so signers should accept a transfer only when it matches an independent withdrawal record or carries a cryptographic signature from the originating service.
- Detection was fast, but containment did not follow. Reconciliation flagged the discrepancy within seven minutes, yet the block applied only to user-initiated withdrawals while the attacker was commanding the backend. The warm-wallet wave, more than half of the total loss, was signed 11 minutes later. A single emergency stop at the signer, covering every chain and every trigger, would in our assessment have limited the loss to roughly the first wave.
- Security and admin tooling belong inside the wallet trust tier. Bitget has not named the product, so other customers of it may still be exposed. The incident is the latest in a series in which a trusted provider or tool with privileged reach was compromised, and moderate to strong evidence links it to the same DPRK cluster behind Bybit and DMM Bitcoin. Exposure to such tools drives how often an attack can happen; what sits between a command and a signature drives how much it costs.
Contributors
- Rex ZhangOneInfinity
- Daky Wang
Related Research

Bybit Incident Research
How a supply-chain compromise bypassed multi-signature controls in the largest crypto theft in history, and what custody operations can learn from it.
Read the analysis
DMM Bitcoin May 2024 Incident Analysis
Reconstructing the probable attack behind DMM Bitcoin’s $305 million loss through on-chain forensic evidence.
Read the analysis
Recent Centralized Platform Hack Tactics & Mitigation
Mapping the attack tactics behind over $2 billion in centralized platform losses and the layered controls that can disrupt them.
Read the analysisInterested in working together?
Our team is expanding research across Web3, Cybersecurity, and AI.

