Overview
- The breach occurred Thursday, Sept. 24, when attackers exploited a flaw in a third‑party security product to spoof internal withdrawal authorizations and remove roughly $387.5–$388 million from Bitget’s hot wallets.
- Bitget began a staged resumption of withdrawals on Sept. 28 and processed 9,585 Bitcoin withdrawal orders totaling 4,098 BTC while on‑chain trackers showed exchange‑linked Bitcoin reserves fall by about 4,642 BTC.
- Mandiant and SlowMist are assisting Bitget’s investigation and initial forensic signals point to tactics tied to North Korea–linked groups; attribution is not yet confirmed by law enforcement.
- Some services moved to block or freeze funds: NEAR Intents’ SHIELD said it blocked over $50 million in attempted transfers and froze about $503,000, and Circle and Tether blacklisted wallets that held roughly $318,000 in stablecoins.
- THORChain declined Bitget’s request to block attacker addresses and processed swaps linked to the theft, a choice that has intensified debate over whether cross‑chain protocols should screen or preserve permissionless operation and could draw regulatory scrutiny.