Particle.news

Bitget Hack Moves $387.5 Million Through Cross‑Chain Routes Into Bitcoin

A zero‑day in third‑party security software let attackers spoof wallet approvals and the rapid use of cross‑chain services and mixers has left most funds beyond reach.

Overview

  • The attackers drained about $387.5 million from Bitget’s hot and warm wallets on Sept. 24, 2026 by exploiting a zero‑day in a vendor security product that gave them high‑level credentials to submit forged withdrawal commands while cold wallets and private keys remained secure.
  • Investigators traced the initial outflows across 23 transfers to Ethereum, the XRP Ledger, Zcash and TRON and found the thieves quickly converted freezeable tokens before moving value across bridges and liquidity protocols.
  • Blockchain forensics firms report heavy use of THORChain to move roughly $269 million through cross‑chain swaps and that much of the stolen value was consolidated into Bitcoin and routed into CoinJoin mixers and Zcash shielded pools.
  • Chainalysis published an analysis linking most stolen XRP to DPRK‑linked actors and said its in‑house AI slashed bridge reconciliation time from more than 20 hours to under 10 minutes while investigators reviewed results.
  • Only about $840,000 has been publicly frozen by issuers and services, Bitget has restored withdrawals in phases and pledged to cover customer losses from its User Protection Fund as forensic work and bounty efforts continue and recovery prospects remain limited.