Bitget Hit by $351.6M Hot-Wallet Attack Despite Nearly 3-Hour Transfer Window

Coinmama
Bybit


  • Bitget detected suspicious transactions involving its hot and warm wallets, with US$351.6 million transferred without authorisation.
  • The exchange says cold wallets and user funds remain secure, while withdrawals are suspended during its security review.
  • On-chain analysis traced multiple large transfers across Ethereum, Arbitrum and other networks, with funds continuing to move after Bitget’s public notice.
  • Scammers have already created spoofed tokens and near-identical wallet addresses, posing a risk to people copying transaction details from block explorers.

In the early hours of Friday, Seychelles-registered crypto exchange Bitget experienced what it calls a hot wallet incident. At 4:31 am AEST (UTC+10) on 25 September, the security systems of the AUSTRAC-registered exchange detected some suspicious transactions. CEO Gracy Chen put out a notice on X saying their emergency response team had been activated. In total, US$351.6 million (AU$501.48 million) has left the exchange in these unauthorised transactions.

Chen said that only hot and warm wallets were affected and that cold wallets “remain fully secure”, while user funds remain untouched. Withdrawals have been suspended for all users while the exchange carries out a security review, though deposits and trading continue as normal.

User funds are safe. The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million.

Gracy Chen, Bitget CEO

She added that authorities have been informed and the team is working to establish what caused the incident, with a full report promised within 24 hours. However, Chen stopped short of calling this a hack, saying they wouldn’t “speculate on the attack vector until the investigation is complete”.

itrust

Read also: Bitcoin Hits $87K, Pulls Back to $84K as Market Weighs Next Move 

How Things Went Down

A Forbes’ on-chain analysis found that a wallet tagged “Bitget 6” moved a fraction of an ether to a brand-new address at 4:31:11 am AEST – a pattern security researchers typically read as a dry run ahead of a bigger withdrawal. Oddly, that’s the exact minute Bitget’s own systems reportedly picked up the incident.

Larger transfers followed quickly: tens of millions of USDT roughly 27 minutes later, followed by USDT0 on Arbitrum, USDC and additional ether within the same few minutes. A second wallet, “Bitget 35”, moved thousands more in ether across three transfers.

Money kept moving well after that: a further tranche of ether was funnelled into three previously unused wallets at 6:13 am, 6:19 am and 7:41:11 am AEST – that last transfer landing roughly 11 minutes after Bitget’s public notice went live at 7:30 am AEST. An earlier transfer at 7:23:11 am AEST, just seven minutes before the notice, was close to the final large movement but wasn’t the last one recorded.

According to Forbes’ figures, Ethereum and Arbitrum together accounted for over US$130 million (A$185.37 million) of the losses, plus a separate haul of several million dollars in a gold-backed stablecoin. The remaining balance of the US$351.6 million was spread across additional chains Forbes did not itemise in full.

Read more: Trump Discloses Up to $100,000 Purchase of Strategy Shares

The choice of assets is interesting, as some stablecoins can be frozen, while ETH itself cannot be frozen by an issuer. The attacker was quick to sell out of freezable assets, reportedly paying a premium to do so, according to pseudonymous sleuth DCF GOD.

A Word of Caution

Forbes also warned that scammers have already hijacked the incident and are trying to take advantage. Within hours, fake ETH, USDC and USDT tokens began mirroring the attacker’s transfers, using hidden characters and near-identical wallet addresses to appear legitimate. Fourteen spoofed transactions had appeared by 8:00 am AEST, creating a risk for anyone copying addresses directly from a block explorer.



Source link

Coinbase

Be the first to comment

Leave a Reply

Your email address will not be published.


*