Cryptocurrency exchange Bitget detected unauthorized transfers at 18:31 UTC on Sept. 24, approximately 30 minutes before attackers drained $290 million in two concentrated waves, according to a post-mortem reconstruction by blockchain security firm Hypernative. The findings raise critical questions regarding why the exchange's emergency protocols failed to halt the exploit, which ultimately saw $387.5 million moved to attacker-controlled addresses.
Timeline of the $387.5M Security Breach
The exploit began at 18:31 UTC with initial test transactions of 0.84 ETH and 93 TRX. After a 28-minute pause, the hacker transferred $34.75 million in USDT at 18:58 UTC, before rapidly accelerating fund withdrawals across multiple networks.
The heaviest losses occurred shortly after. At 19:01 UTC, attackers extracted $87.6 million from Bitget's hot wallets. Just 15 minutes later, at 19:16 UTC, warm wallets were drained of $202.8 million across five blockchains in just nine seconds. Combined, these two major bursts took only 24 seconds to complete and accounted for roughly three-quarters of the stolen funds. Unauthorized transfers continued until 21:23 UTC, nearly three hours after the initial detection trigger.
Infrastructure Controls and Response Failures
According to Bitget, the breach stemmed from a compromised backend system in its wallet infrastructure that spoofed withdrawal data and tricked the authorization process into approving transfers. Bitget confirmed that private keys were not compromised. Because the transactions were signed by Bitget's own system, they closely mirrored normal customer withdrawal activity. The ongoing investigation follows heightened community focus on the incident, as ZachXBT identified Bitget hack suspects attempting to seek support in public chatrooms.
Hypernative highlighted several security safeguards that could have contained the attack during the 30-minute window:
- Independent cross-verification: Matching signed transfers against independently stored user withdrawal requests or approved treasury actions.
- Parameter checks: Detecting unusual gas limits that diverged from Bitget's standard withdrawal pipeline during the 18:31 UTC test phase.
- Velocity caps and automated signoff suspensions: Imposing hard volume caps on short-term wallet movements—such as the $202.8 million moved in nine seconds—and automatically revoking compromised signer permissions.
Bitget stated it has remediated the vulnerability and halted further unauthorized transfers, while cybersecurity firms Mandiant and SlowMist remain involved in the forensic investigation.
Why It Matters
This incident highlights a major vulnerability in exchange risk management: detection systems are ineffective without automated kill switches. Relying on manual response during an automated backend spoofing attack creates fatal delays, allowing massive capital outflow in seconds. As trading platforms scale, real-time velocity restrictions and independent transaction cross-referencing must become non-negotiable operational standards.



