Overview
- Bitget detected unauthorized transfers on Sept. 24 after attackers spoofed internal approval data to move assets from the exchange’s hot and warm wallets.
- The company’s later accounting raised the total affected to about $387.5 million after investigators found additional transfers on Zcash and TRON.
- Bitget says private keys and cold wallets were not exposed and that its User Protection Fund, reported at roughly 5,500 BTC, will cover customer balances while forensic work continues.
- On-chain analysts traced large XRP and ETH holdings to attacker-controlled addresses, and investigators report the thief has begun consolidating funds and withdrawing sums through other exchanges.
- Bitget has engaged Mandiant, SlowMist and law enforcement to trace and recover assets, and preliminary IP and on-chain patterns point to North Korea–linked groups though formal attribution remains unconfirmed.