Cryptocurrency exchange Bitget has published a detailed timeline outlining the September 24 exploit that resulted in $387.5 million stolen from its hot and warm wallets.
Timeline of the $387.5 Million Breach
Bitget reported that its internal security monitoring flagged unauthorized transfers at 18:31 UTC on September 24, prompting emergency response procedures while keeping offline cold wallets secure. At 19:57 UTC, crypto analyst DCF GOD noted a fresh wallet spending $19.67 million in USDT0 to purchase 7,111 ETH within six minutes, paying premiums up to 5% above prevailing spot prices. Shortly after at 21:06 UTC, on-chain intelligence firm Bubblemaps observed approximately $180 million flowing from Bitget wallets into a single receiving address before being split across multiple destinations.
Bitget CEO Gracy Chen confirmed the attack at 21:30 UTC, making an initial loss estimate of $351.6 million while pausing all user withdrawals. On September 25 at 14:03 UTC, Bitget updated the total to a revised stolen funds estimate of $387.5 million after incorporating affected Zcash and TRON balances. The platform stated the security vulnerability has been patched and committed to publishing a withdrawal restoration update by September 26 at 04:00 UTC.
How Attackers Spoofed Backend Approvals
On September 25 at 00:43 UTC, Gracy Chen explained that attackers gained entry to a critical backend system managing wallet logic. By supplying manipulated transaction data, the hackers forced Bitget's automated authorization system to validate the fraudulent transfers internally, ruling out direct private-key theft.
Key takeaways from the timeline include:
- Backend Data Manipulation: Attackers spoofed transaction instructions to trigger automated platform approvals rather than obtaining private keys.
- Rapid Conversion and Dispersion: The perpetrator quickly traded assets for ETH and channeled proceeds through THORChain, according to tracking firm MistTrack.
- User Balance Coverage: Bitget verified user account balances remain intact and will be reimbursed via the Bitget Protection Fund.
Cybersecurity firms Mandiant and SlowMist are conducting investigations alongside Bitget. Gracy Chen stated that IP address patterns and operational methods align with North Korean hacking organizations, drawing parallels to the February 2025 Bybit breach that the FBI attributed to state-sponsored actors.
Why It Matters
This incident highlights an evolving operational threat for centralized exchanges where automated system logic, rather than private key storage, becomes the primary target. As security measures around cryptographic keys harden, attackers are exploiting the software bridges and approval routines that process high-frequency transfers. Exchange infrastructure teams will likely face increased pressure to implement multi-layered validation protocols for automated backend approvals to prevent transaction-spoofing attacks.
