The Bitget exchange experienced a security breach that resulted in a major theft of customer funds. Initial reports put total losses at $351.6 million, with a later update raising the total to $387.5 million. Unauthorized transfers were first detected at 18:31 UTC on Sept 24, and Bitget said attackers had compromised a backend system inside its wallet infrastructure to spoof transaction data and trigger payouts.
Bitget’s chief executive Gracy Chen said attackers gained access to a backend system within the exchange’s wallet infrastructure and used that access to manipulate internal transaction records. The attackers generated falsified transaction data inside Bitget systems rather than submitting forged user withdrawal requests. Chen said the incident did not involve compromise of private keys for cold, hot, or warm wallets. The manipulated internal data was used to move assets out of the exchange.
According to Chen, the compromised backend system allowed the attackers to present payouts that appeared routine to the exchange’s own authorization processes. Those internal authorization checks relied on the spoofed data and approved transfers that otherwise would have been flagged. The method therefore bypassed standard checks without requiring control of individual account credentials or private keys. Bitget identified the anomaly and publicly described the attack as a backend spoofing of transaction information.
Chen provided the account of the attack in Bitget’s incident reporting. Bitget said an investigation is ongoing with external security firms Mandiant and SlowMist.
Circle blacklisted the Bitget exploiter address labeled Bitget Exploiter 8 at 05:00 UTC on Friday, and on-chain records show that the wallet held about 170.47 ETH, 218,023 USDT and 99,990 USDC. MistTrack reports that Tether has since banned the same wallet, and those issuer actions have left roughly $318,000 in stablecoins frozen and inaccessible. The frozen stablecoins are a subset of the balances associated with the named exploiter address rather than the full set of assets moved during the breach. Exploiter addresses collectively hold more than 63,000 ETH that no issuer can freeze, meaning the majority of stolen ETH remains beyond issuer-imposed freezes. Circle’s blacklist and Tether’s ban were recorded as part of post-incident mitigation steps affecting the named exploiter wallet.
Deposits and trading on Bitget remained operational after the breach while withdrawals were frozen as a precaution. The company said unauthorized transfers were detected at 18:31 UTC on Sept 24, with about $183 million moved within an hour and total losses reaching $351.6 million that day; total losses were later reported at $387.5 million. External security firms Mandiant and SlowMist are participating in the ongoing investigation. On-chain observers flagged suspicious wallet activity: DCF GOD identified a wallet that spent $19.67 million in USDT0 to buy 7,111 ETH in six minutes, and MistTrack reported that Tether had banned the exploiter wallet. North Korea is suspected as the likely culprit, though that link is not confirmed.
Coverage has documented a security breach at Bitget in which attackers accessed a backend wallet system and used spoofed transaction data to move assets, while Bitget said private keys were not compromised. Post-incident actions included issuer blacklisting and banning of exploiter addresses with some stablecoins frozen and Bitget placing withdrawals on hold while deposits and trading continued. An external investigation involving Mandiant and SlowMist is ongoing and Bitget has indicated its User Protection Fund will absorb the financial impact.


