Key TakeawaysBitget detected unauthorized outflows from its hot and warm wallets at 18:31 UTC on Thursday, September 24, 2026 and later put the loss at about $387.5 million across seven networks, inclKey TakeawaysBitget detected unauthorized outflows from its hot and warm wallets at 18:31 UTC on Thursday, September 24, 2026 and later put the loss at about $387.5 million across seven networks, incl

Bitget Hack Explained: How $387 Million Was Stolen Without a Single Key, and the THORChain Standoff Splitting Crypto

Key Takeaways
Bitget detected unauthorized outflows from its hot and warm wallets at 18:31 UTC on Thursday, September 24, 2026 and later put the loss at about $387.5 million across seven networks, including Ethereum and other EVM chains, the XRP Ledger, Zcash and TRON. It is one of the largest exchange thefts on record, behind Bybit's $1.46 billion in 2025.
No private keys were stolen and cold storage was untouched. According to CEO Gracy Chen, attackers exploited a flaw in a third party security product and stolen internal credentials to compromise a backend system in the wallet stack, forge transaction data, and trick Bitget's own approval flow into signing transfers that looked routine.
Bitget says user balances are unaffected and its User Protection Fund of more than $464 million will absorb the loss. Withdrawals are restarting in phases: Bitcoin on September 28, Ethereum on September 29, USDT on September 30, and remaining tokens, fiat and P2P by October 2. Trading and deposits never stopped.
The aftermath produced a public standoff. Chen formally asked THORChain to refuse service to the publicly listed attacker addresses as loot was swapped through the protocol into Bitcoin; THORChain declined, citing its permissionless design, while SlowMist and OKX founder Star Xu noted it had paused itself quickly when its own funds were at risk.
Bitget suspects North Korean linked groups based on IP patterns and onchain behavior, with Mandiant and SlowMist investigating, Circle and Tether freezing about $318,000 in stablecoins, and 5% bounties on offer for freezing or recovering assets.
 
 

What Happened on September 24

The breach surfaced the way exchange hacks usually do now: onchain analysts saw it before the announcement. Bubblemaps, Wu Blockchain and others flagged unusual outflows from Bitget addresses within the hour, users began posting about failed withdrawals, and Bitget's own systems logged the unauthorized transfers at 18:31 UTC. CEO Gracy Chen posted a security notice at 21:30 UTC and withdrawals were paused. The initial estimate of about $351.6 million covered roughly $183 million leaving EVM chains and a single striking move on the XRP Ledger, where two Bitget wallets sent 93.7 million XRP, worth about $143 million, to a fresh address. Two days later the exchange raised the total to $387.5 million after tracing additional affected transactions on Zcash and TRON, stressing that the revision reflected a fuller accounting of the original attack rather than a second breach. The stolen assets included XRP, ETH, USDT, USDC, USDT0, ZEC, XAUt, BNB, AVAX and TRX.
 

How It Was Done Without Stealing a Key

The most unsettling detail is that Bitget's keys were never taken. According to Chen's account, the attackers exploited a vulnerability in a third party security product and used stolen internal access credentials to compromise a backend system within the wallet infrastructure. From there they forged transaction data so that transfers to their own addresses appeared as ordinary, legitimate withdrawals, and Bitget's approval flow signed them. Cold wallets were not involved, and the exchange says the vulnerability has since been identified and fixed so that no further unauthorized transfers are possible. Mandiant and SlowMist are assisting the forensic work, and a full incident report is still pending.
The technique matters because it echoes the Bybit heist of February 2025, in which attackers manipulated what signers saw rather than breaking cryptography, and because Bitget says IP patterns and onchain behavior resemble prior operations linked to North Korean groups, though formal attribution rests with investigators. Together the two incidents suggest the frontier of exchange security has moved from key management to the integrity of the systems that present transactions for approval.
 
 

The Protection Fund Faces Its Biggest Test

Bitget's response leaned on a promise it made years ago. The exchange says its User Protection Fund, which holds more than $464 million and is separate from its proof of reserves system, will cover the full loss, meaning customers should not bear any of it. Trading and deposits continued throughout, and Bitget framed the withdrawal freeze as a security measure rather than a liquidity problem. The proof is in the restart: Bitcoin withdrawals resumed at 08:00 UTC on September 28, Ethereum and other EVM networks follow on September 29, USDT on September 30, and the remaining tokens, fiat channels and P2P services are due back by October 2, each phase gated on validation checks. Bitget has also announced separate 5% bounties for anyone who helps freeze or recover stolen assets, Circle and Tether froze about $318,000 in stablecoins, and Binance founder Changpeng Zhao publicly voiced support. The phased reopening is the exchange's first operational test since the attack, and the market will read any hiccup harshly.
 
 

The THORChain Standoff

Within a day, part of the haul was moving. On September 25, MistTrack, the tracing unit of SlowMist, reported that Bitget linked funds were entering THORChain for swaps and cross-chain transfers, and pointedly asked what responsibility a protocol carries once the source of funds is known, noting that nearly $1.2 billion of the $1.46 billion Bybit loot had moved through the same rails in 2025. On Saturday Chen escalated, posting that Bitget's attacker addresses were public and tracked and formally asking THORChain to refuse them service. "Decentralization is a design principle, not a shield for facilitating known stolen funds," she wrote. "The industry is watching."
THORChain expressed regret but declined, arguing it is permissionless in the same sense as Bitcoin, Ethereum or BNB Chain and has no address level blocking in its validator design. SlowMist and OKX founder Star Xu disputed that framing, observing that THORChain had paused its network quickly when its own funds were at risk. The swaps continued: CoinDesk identified 27 transactions moving about 2,390 ETH into 75.2 BTC, roughly $6 million, and tracing shows the attacker also routing through Uniswap, 1inch, Stargate, Across, Relay, Chainflip and Circle's cross-chain transfer protocol, with about $83 million in stolen XRP already on the move.
The dispute is the same argument crypto has been having all month from different angles. Cronos validators rolled back nearly two hours of history to reverse a $120 million exploit, Blockstream paused the Liquid Network and negotiated with its hackers on chain, and now a decentralized protocol has refused to intervene at all. Each choice is defensible on its own terms, and each carries a cost: chains that can intervene weaken finality, and chains that cannot become the preferred laundromat for the industry's worst actors.
 

What It Means for Traders on MEXC

The market reaction was contained, with Bitcoin and XRP absorbing the news and ETF inflows continuing, but the incident is a reminder that counterparty risk on any centralized venue is real and that the details of protection funds, proof of reserves and withdrawal policies deserve reading before a crisis rather than during one. Practical habits apply everywhere: keep long term holdings in self custody or spread across venues, keep exchange balances sized to active trading, harden accounts with two factor authentication and withdrawal safeguards, and be alert to the wave of phishing that follows every major hack, as impersonators pose as support teams offering help. Traders can follow the assets at the center of the story on XRP/USDT and ETH/USDT.
 
Disclaimer: This content is for educational and reference purposes only and does not constitute any investment advice. Digital asset investments carry high risk. Please evaluate carefully and assume full responsibility for your own decisions.
市場の機会
4 ロゴ
4価格(4)
$0.020888
$0.020888$0.020888
USD

このページで共有されている記事は公開プラットフォームから収集したものであり、参考情報としてのみ提供されています。MEXCの立場や見解を代表するものではありません。すべての権利は OoJae に帰属します。第三者の権利を侵害するコンテンツがあると思われる場合は、service@support.mexc.com までご連絡いただければ速やかに削除いたします。MEXCはいかなるコンテンツの正確性、完全性、適時性も保証せず、提供された情報に基づいて取られたいかなる行動についても責任を負いません。本コンテンツは、金融、法律、またはその他の専門的なアドバイスを構成するものではなく、MEXCによる推奨または支持として解釈されるべきものでもありません。専門家の洞察と詳細な分析については、MEXC 学ぶ をご覧ください。

4 の最新情報

もっと見る
JR東日本(9020)株価分析|還元強化とインバウンドで見直し、目標株価¥4,091の鉄道最大手は買い

JR東日本(9020)株価分析|還元強化とインバウンドで見直し、目標株価¥4,091の鉄道最大手は買い

JR東日本(東日本旅客鉄道、9020)は現在 ¥3,386(2026年6月26日時点)、当社判断は「買い」。鉄道最大手で、運輸に加え不動産・駅ナカ物販が成長する。27年3月期の増収増益と株主還元の強化を好感して株価は急伸し、アナリスト平均目標株価は約¥4,091と2割の上昇余地を示す。予想PER約15倍・配当利回り2.5%と割高感もなく、インバウンドと非運輸の成長を中期の支えとみる。
2026/07/31
JX金属(5016)株価は買い場か|高値から3割安、半導体材料への転換を映す目標株価¥5,450

JX金属(5016)株価は買い場か|高値から3割安、半導体材料への転換を映す目標株価¥5,450

JX金属(5016)は現在 ¥4,085(2026年7月3日時点)、当社判断は「中立」。2025年上場の非鉄金属大手で、銅製錬から半導体材料への収益転換が進む。光通信基板材料の10倍増産などを好感し株価は年初来3倍近くに急騰したが、高値から3割安まで調整した。アナリスト平均目標株価は約¥5,450と上値余地を示すが、市況の循環性を踏まえ見極めたい局面とみる。
2026/07/31
USD1が1週間で9.7%増・$4.85Bへ:World Liberty Financial発行ステーブルコインが3ヶ月100パーセンタイルの成長

USD1が1週間で9.7%増・$4.85Bへ:World Liberty Financial発行ステーブルコインが3ヶ月100パーセンタイルの成長

World Liberty Financialが発行するステーブルコインUSD1の流通供給量が、過去7日間で9.7%増加し、48.5億ドルに達しました。1週間の純増は約4.27億ドル相当で、直近3カ月の供給履歴では最も速い拡大ペースです
2026/07/31
もっと見る