Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Bitget Exchange Had 30 Minutes to Stop Hack Before $290 Million Drained

Blockchain analysis reveals Bitget detected unauthorized transfers at 18:31 UTC on September 24, roughly 30 minutes before attackers began moving hundreds of millions of dollars from the exchange. Most losses occurred after the initial alert.
6 hours ago 10 views
Bitget Exchange Had 30 Minutes to Stop Hack Before $290 Million Drained

Bitget detected unauthorized wallet transfers about 30 minutes before attackers began draining hundreds of millions of dollars from the cryptocurrency exchange, raising questions about the exchange's security response.

The exchange said its systems flagged unauthorized transfers at 18:31 UTC on September 24 and that its security team immediately activated emergency protocols. However, blockchain security firm Hypernative's reconstruction of the attack shows that most losses came later: $87.6 million left hot wallets at 19:01, and another $202.8 million left warm wallets at 19:16.

Those two transfer bursts, completed in a combined 24 seconds, accounted for approximately three-quarters of the $387.5 million Bitget ultimately reported was moved to attacker-controlled addresses. Bitget had roughly 30 minutes after its initial alert to prevent the first major wave and about 45 minutes before the largest transfer burst.

Attack Timeline and Method

Hypernative said the attacker initially tested the compromised route at 18:31 with transfers of 0.84 ETH and 93 TRX to new addresses. After waiting about 28 minutes, the attacker moved $34.75 million of USDT at 18:58 before accelerating the drain across multiple blockchains.

Bitget said its investigation found that the attacker compromised a backend system in its wallet infrastructure, spoofed withdrawal data, and tricked the exchange's authorization process into approving the transfers. The company said private keys were not compromised.

Potential Security Controls

Hypernative identified several controls that could have interrupted the attack after the initial alert:

  • Verification that every signed transfer corresponded with an independently stored customer withdrawal or approved treasury transaction, which could have prevented a compromised backend service from creating its own authorization
  • Comparison of proposed transactions against parameters normally generated by the exchange, as the attacker's requests included unusual gas limits that differed from Bitget's normal withdrawal pipeline
  • Velocity limits on how much individual wallet tiers could transfer within short periods, coupled with secondary approval requirements, which could have delayed or blocked much of the $202.8 million wave that moved across five networks within nine seconds
  • Automatic suspension of affected signers upon detecting anomalous transfers, rather than relying on manual intervention

Attacker-linked transfers continued until 21:23 UTC, almost three hours after Bitget's stated detection time.

Bitget has since said it remediated the vulnerability and that no further unauthorized transfers occurred after containment. Mandiant and SlowMist remain involved in the forensic investigation.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $83,615.09-1.18% EthereumETH $2,686.69-0.10% Tether USDUSDT $0.9997-0.01% BNBBNB $765.87-1.63% XRPXRP $1.50-1.48% USDCUSDC $1.00+0.03% SolanaSOL $119.05-3.10% TRONTRX $0.3360+0.65% HyperliquidHYPE $88.15-3.99% ZcashZEC $1,464.98-8.80%
Prices by Coinranking. Informational only.