Bitget detected unauthorized wallet transfers about 30 minutes before attackers began draining hundreds of millions of dollars from the cryptocurrency exchange, raising questions about the exchange's security response.
The exchange said its systems flagged unauthorized transfers at 18:31 UTC on September 24 and that its security team immediately activated emergency protocols. However, blockchain security firm Hypernative's reconstruction of the attack shows that most losses came later: $87.6 million left hot wallets at 19:01, and another $202.8 million left warm wallets at 19:16.
Those two transfer bursts, completed in a combined 24 seconds, accounted for approximately three-quarters of the $387.5 million Bitget ultimately reported was moved to attacker-controlled addresses. Bitget had roughly 30 minutes after its initial alert to prevent the first major wave and about 45 minutes before the largest transfer burst.
Attack Timeline and Method
Hypernative said the attacker initially tested the compromised route at 18:31 with transfers of 0.84 ETH and 93 TRX to new addresses. After waiting about 28 minutes, the attacker moved $34.75 million of USDT at 18:58 before accelerating the drain across multiple blockchains.
Bitget said its investigation found that the attacker compromised a backend system in its wallet infrastructure, spoofed withdrawal data, and tricked the exchange's authorization process into approving the transfers. The company said private keys were not compromised.
Potential Security Controls
Hypernative identified several controls that could have interrupted the attack after the initial alert:
- Verification that every signed transfer corresponded with an independently stored customer withdrawal or approved treasury transaction, which could have prevented a compromised backend service from creating its own authorization
- Comparison of proposed transactions against parameters normally generated by the exchange, as the attacker's requests included unusual gas limits that differed from Bitget's normal withdrawal pipeline
- Velocity limits on how much individual wallet tiers could transfer within short periods, coupled with secondary approval requirements, which could have delayed or blocked much of the $202.8 million wave that moved across five networks within nine seconds
- Automatic suspension of affected signers upon detecting anomalous transfers, rather than relying on manual intervention
Attacker-linked transfers continued until 21:23 UTC, almost three hours after Bitget's stated detection time.
Bitget has since said it remediated the vulnerability and that no further unauthorized transfers occurred after containment. Mandiant and SlowMist remain involved in the forensic investigation.


