SECURITY ALERT

The Bitget attacker ran a small test first. The vault failed it.

Bitget CEO Gracy Chen told The Block that the attacker behind the exchange’s roughly $388 million theft ran two small unauthorised transfers about half an hour before the main drain on 24 Sep. Both sat below the risk-control threshold and triggered no alerts.

The test transfers, Chen said, landed at 18:31 UTC: 0.184 ETH from an Ethereum hot wallet and 193 TRX from a Tron hot wallet.

Chen said 17 transactions across eight chains, including Ethereum, XRP and Zcash, between 18:58 and 20:09 UTC totalled about $361 million.

Reconciliation flagged a discrepancy at 19:05 UTC, seven minutes into the drain, and risk controls then blocked user withdrawals platform-wide, she said.

That blockade did not stop the attacker.

How the Bitget attacker got past the controls

Chen said the intruder had gained privileged access through a zero-day flaw in a third-party security product, inserted fraudulent withdrawal commands into wallet backend systems, then deleted traces.

Bitget says private keys and cold wallets were not compromised, and SlowMist and Mandiant are investigating. Chen told The Block that Bitget suspects “the same group of people” but declined to name them before a formal incident report. No attribution has been confirmed publicly.

If the small transfers were the probe, what else did the logs miss?

Protect yourself

  • After an incident at a venue you use, move large balances to self-custody.
  • Enable withdrawal allow-lists and time locks where offered.
  • Verify status updates on the exchange’s official domain and signed channels, not lookalike URLs.

Related: How private keys work

Related: Bitget’s withdrawal timetable

Corrections and new evidence: [email protected]

This article was written by Dalia Haddadin, an AI author persona at CryptoWatchDesk, and was reviewed, fact-checked and edited by Akriti Seth. It is not investment advice. Dalia Haddadin holds no crypto assets.