Contents

Bitget Lost 387.5 Million Dollars Without Losing a Single Private Key

 

Ethical Hacking Complete Course Zero to Expert

Hack like black hat hackers. Penetration testing, Kali Linux, WiFi and web hacking, and the hacker mindset behind it.

→ Take the full course
 
Contents

Attackers took 387.5 million dollars from a crypto exchange, and the exchange signed off on it. Its private keys were never stolen. The same kind of trick took 1.5 billion from another exchange last year.

If you keep crypto on an exchange, you made a deal with it. Your coins sit in the exchange’s wallets, and the exchange guards the private keys that can move them. Those keys are the part you are told to worry about, and the part attackers go after, because whoever holds a key can sign a transfer and the blockchain will accept it. At the crypto exchange Bitget, the keys stayed exactly where they were on September 24, and 387.5 million dollars left anyway.

That evening a trader on X noticed something that made no sense. A brand-new wallet was buying ETH on a network built on top of Ethereum, 7,111 of them in six minutes. It paid with 19.67 million in a stablecoin, a coin that is kept at one dollar, and those had come straight out of a Bitget hot wallet. The wallet paid up to 5 percent above the market price to do it. A buyer who wants a coin looks for the best price. A buyer who is in a hurry to get rid of something pays whatever it takes, and that is what this wallet was doing. The trader’s guess was a 20 million dollar hack.

That guess was off by a factor of almost twenty. Bitget’s first count was 351.6 million dollars. A day later it raised that to 387.5 million, after it had gone through two more blockchains it had missed the first time.

The day after the theft, the CEO of Bitget wrote on X what her team had found so far. The attackers got into one of the systems behind the exchange’s wallets and used it to fake transaction data. That fake data set off the exchange’s own approval process, and the approval process moved the money out. A stolen private key has been ruled out. How the attackers got into that system is something the exchange is still working out.

When you press withdraw on an exchange, the exchange does the signing for you. Your request goes to the servers behind the website, the exchange’s backend. Its systems check your account, your balance and the address you want to send to, and turn that into a transaction: this amount, from this wallet, to that address. That transaction goes to the part of the exchange that holds the keys, and the keys sign it. The blockchain only ever sees the signature, and a valid signature from the exchange’s own key is all it needs.

Bitget keeps its crypto in three layers. Hot wallets are online and pay out withdrawals straight away. Warm wallets sit behind them as a buffer and top the hot wallets up, and cold wallets are kept offline. The attack reached parts of the hot and the warm layer, and the cold wallets stayed untouched.

The attackers went one step earlier than the keys, into the system that decides what the keys get asked to sign, and fed it transfers that looked like the exchange’s own. The approval process said yes and the keys signed them, because as far as either could tell, nothing was wrong. The signatures were valid, and the blockchain accepted them for the same reason it accepts yours.

This kind of trick has worked before, at the exchange Bybit, which lost around 1.5 billion dollars on February 21, 2025. That day it moved money out of one of its cold wallets, a wallet that needed several people to sign off on a transfer, a so-called multisig wallet. The people approving it saw a normal transfer on their screen and signed. What they actually signed replaced the code that runs the wallet and handed control of it to the attackers, who then took over 400,000 ETH out of it. The attackers had placed malicious JavaScript in the web interface of the wallet software the exchange used, and that code only switched on for the exchange’s wallet and one other address. They put it in two days before the theft and took it out again about two minutes after. The investigation traced it back to a developer machine at the wallet software company that the attackers had compromised.

In 2025, the attackers changed what the people signing saw on their screen. This time, they changed what the approval system read before it signed. The keys held both times, and both times the attackers went for the step right before the signature, the part that tells the keys what to sign.

Part of this you can follow yourself, because a blockchain is a public record. Bitget published the address that received the stolen XRP, and you can ask the XRP Ledger what went in and out of it. Three payments arrived there from two wallets that a public XRP lookup site, a ledger explorer, labels as Bitget’s. Together they come to 102,976,680 XRP, the largest single piece of the loss, worth around 158 million dollars at the time. The biggest of the three was 91.4 million on its own. Counted from the moment Bitget says its systems raised the alarm, that one arrived about three quarters of an hour later. The last one, 9.3 million, came close to three hours later.

The address did not keep the coins for long. The same evening it sent them on in five payments: four of exactly 20,000,000 and one of 22,976,677, to five fresh accounts. What is left at that address today is about 3 XRP.

You can check that with nothing more than a terminal. This asks a public server for the balance:

1
2
3
curl -s -H 'Content-Type: application/json' \
  -d '{"method":"account_info","params":[{"account":"rwNhefsz1UQEusxhCvHip3RANinWi4CTck","ledger_index":"validated"}]}' \
  https://xrplcluster.com/

And this one lists the payments in and out, oldest first:

1
2
3
curl -s -H 'Content-Type: application/json' \
  -d '{"method":"account_tx","params":[{"account":"rwNhefsz1UQEusxhCvHip3RANinWi4CTck","ledger_index_min":-1,"ledger_index_max":-1,"limit":50,"forward":true}]}' \
  https://xrplcluster.com/

Amounts come back in drops, and one XRP is 1,000,000 drops, so when the Balance field says 3091975, that is a little over 3 XRP.

The attackers could take their time with the XRP, and the stablecoins show why. The companies behind the big dollar stablecoins can freeze their coins at any address, and they did: they froze about 318,000 dollars linked to the attack. Out of 387.5 million, that is less than 0.1 percent, and the trader on X had already watched 19.67 million of those stablecoins turn into ETH in six minutes. XRP works differently, because the XRP Ledger only lets a company freeze tokens it issued itself, and XRP is the network’s own coin, so it cannot be frozen at all. By Saturday around 83 million dollars of the stolen XRP had already moved on from the accounts it was split into.

The rest of the money followed the same pattern. Within hours it was divided into fresh wallets holding round amounts, around 10,000 ETH or 20 million XRP each, and most of those wallets then sat still. The part that did move went through swap services that turn one coin into another without an account, and came out as Bitcoin and ETH. One route ran around 9.8 million dollars in another coin through a swap service over roughly 13 hours, in small pieces.

Blockchain investigators who followed that money found wallets in the chain that had also been used to launder earlier thefts, among them the 1.5 billion theft of 2025. They have not linked that laundering network to any other group. That points to TraderTraitor, the name the FBI uses for the North Korean hackers it held responsible for that theft.

In cybersecurity, attribution is one of the hardest problems. IP addresses can be routed through somebody else’s VPN, and laundering routes can be shared or copied. What we know for sure is how the money moved, not necessarily who is behind it. Bitget itself says the IP addresses it saw and the patterns in the transactions fit the techniques of groups linked to North Korea, and it has not gone further than that.

If the trail is right, it fits a pattern that has been building for years. Blockchain investigators counted more than 2 billion dollars in crypto stolen by hackers linked to the country in 2025, the highest yearly total on record, and more than 6 billion in total over the years. According to the United Nations and several governments, that money helps pay for the country’s nuclear weapons and missile programmes. With Bitget added, 2026 would pass 1 billion as well.

For Bitget’s customers, the loss is covered. The exchange is paying it from its User Protection Fund, which held over 464 million dollars, so this one theft takes more than four fifths of it. On top of that, Bitget says it holds more than a billion dollars of its own assets. Account balances stayed as they were and trading and deposits kept running, but Bitget paused withdrawals that same evening. It says it found and fixed the vulnerability, and it is opening withdrawals again in steps between September 28 and October 2, starting with Bitcoin. Two outside security firms are still investigating, Bitget has promised a full technical report, and people who help freeze the stolen coins get 5 percent of what they freeze, and another 5 percent of whatever they help recover.

Two things to take from this.

  • → A private key signs what it is given. The system that decides what reaches the key needs as much protection as the key itself. In both of these thefts, that system was where the attackers went in.
  • → Coins on an exchange depend on that exchange’s backend, however good its key storage is. Coins you are not trading can sit in a wallet you control yourself. Before you confirm a transfer, check the address and the amount on the screen of the device that signs it.

You can follow the stolen XRP yourself from your own terminal with one curl command, no account and no wallet needed.

My Ethical Hacking Complete Course Zero to Expert takes you there step by step: reconnaissance, scanning, exploitation and traffic analysis, hands-on, from your first day with no Linux or hacking background.

→ Join my complete ethical hacking course

Hacking is not a hobby but a way of life.

Sources:

Bitget: Security Incident Update | Bitget CEO Gracy Chen on X | TRM Labs | FBI IC3: North Korea Responsible for Bybit Theft

 
NEWSLETTER

Stay updated

Get the latest posts in your inbox every week. Ethical hacking, security news, tutorials, and everything that catches my attention. If that sounds useful, drop your email below.

By Bulls Eye

Jolanda de koff • email • donate

My name is Jolanda de Koff and on the internet, I'm also known as Bulls Eye. Ethical Hacker, Penetration tester, Researcher, Programmer, Self Learner, and forever n00b. Not necessarily in that order. Like to make my own hacking tools and I sometimes share them with you. "You can create art & beauty with a computer and Hacking is not a hobby but a way of life ...

I ♥ open-source and Linux