DEV Community

Anoymask
Anoymask

Posted on

Bitget: $387.5M Stolen via Wallet Backend Compromise and Transaction Data Tampering

1. Overview

  • Article Title: Bitget Security Latest Incident Update: Fund Tracing and Recovery Bounty Program
  • Source: Bitget
  • Published Date: 2026-09-25
  • Original: Bitget
  • Related Sources: BleepingComputer: withdrawal resumption, BleepingComputer: initial incident, Bitget: initial security notice, Bitget: phased withdrawal schedule, MITRE ATT&CK: Data Manipulation
  • Related Malware, Threat Groups, CVEs, and Products: North Korean threat actors (Bitget attribution), Bitget Exchange, hot wallet, warm wallet, wallet backend
  • Severity: Critical (Bitget confirmed that approximately $387.5 million worth of assets was transferred from multi-chain hot and warm wallets to attacker-controlled addresses following the compromise of a critical backend system and the abuse of authorization processes.)

  • Revisions: Differentiated transaction data tampering from undisclosed details of the signing system, confirmed compromise evidence, and investigation candidates, while updating ATT&CK to parent techniques. Separated official schedules and secondary reports regarding withdrawal resumptions.

2. Quick Summary

According to Bitget, attackers compromised a critical backend within the exchange's wallet infrastructure and manipulated transaction data to abuse authorization processes. Bitget confirmed that approximately $387.5 million in cryptocurrency was fraudulently transferred across multiple chains.

3. Attack Flow

Asset Theft via Authorization Abuse from Wallet Backend

  1. Attackers breached a critical backend system within Bitget's wallet infrastructure. Specific initial access vectors or vulnerabilities used in the breach have not been disclosed.
  2. According to statements by the Bitget CEO cited by BleepingComputer, the attackers exploited the compromised backend to falsify transaction data. Specific data fields that were altered and internal signing implementation details have not been disclosed.
  3. Based on the falsified transaction data, legitimate authorization processes were triggered, advancing the transfer process. This does not confirm that signing keys themselves were directly stolen or that communications were intercepted and altered in transit.
  4. Assets were fraudulently transferred from hot and warm wallets spanning multiple blockchains (EVM-compatible chains, XRP Ledger, Zcash, and TRON) to addresses controlled by the attackers.
  5. Following the execution of transfers, the attackers distributed and moved funds across chains. Bitget is tracing the affected funds with industry partners and reports that some assets have been frozen through their cooperation. Mandiant and SlowMist are assisting with the investigation.
Processing System / Component Attacker Involvement and Impact Scope of Description Publication Status and Unconfirmed Items
Wallet Backend Breached core infrastructure and falsified transaction data (CEO statement) Compromised backend and transaction data Specific initial access vectors and exploited vulnerabilities are unpublicized
Authorization Illegitimately triggered legitimate authorization processes using falsified data Authorization processing upon receiving transaction data (details unpublicized) Bypassed verification conditions and specific bypass methods are unpublicized
Signing Potential exploitation of legitimate signing workflows (inference) Structure of signing and verification processes unpublicized Direct theft of signing keys or in-transit tampering unconfirmed in public information
On-Chain Fraudulent transfer of approximately $387.5 million across Ethereum/EVM, XRP, Zcash, and TRON Network delivery and ledger recording of transactions Tracking of attacker addresses and fund freezing ongoing post-transfer

4. Attacker Position and Execution Location

  • Attackers influenced transaction data from within Bitget's wallet backend or through access that allowed them to control it. Specific privileges and internal operations have not been disclosed.
  • The primary stated destinations for the fraudulently transferred assets are attacker-controlled addresses across the EVM, XRP, Zcash, and TRON networks as published by Bitget.

5. Visibility for Victims and Administrators

Victims

  • While user balances were protected and maintained according to Bitget, the complete temporary suspension of withdrawals resulted in a period where users were unable to move their assets.

Administrators

  • Bitget detected unauthorized transfers from limited hot and warm wallets as an anomaly. Specific details of internal authorization and signing logs, or the exact stage at which alerts were generated, have not been disclosed.

6. Conditions for Success and Failure

Success Conditions

  • Successful compromise of a critical backend system capable of generating or modifying wallet transactions.
  • Acceptance of falsified transaction data by authorization and transfer processes. The presence of independent verification features or which checks were bypassed has not been disclosed.
  • Existence of target assets in hot and warm wallets without manual or automated stop controls triggering before transfer completion.

Failure Conditions and Risk Mitigation

Below are general defensive measures and mitigation proposals in this report and do not directly indicate internal configurations or implemented measures published by Bitget.

  • Strictly separate transaction generation systems from signing systems, re-verifying destinations, amounts, chain IDs, and nonces in an independent component immediately before signing.
  • Apply rate limiting, destination allowlists, multi-signature/quorum approvals, and out-of-band confirmations to new destination addresses, high-value transfers, and simultaneous multi-chain transfers.
  • Minimize online hot wallet balances to operational necessities and establish an emergency kill switch to immediately halt transfers across all chains upon detecting anomalies.

7. What Happens Upon Success

  • Approximately $387.5 million worth of cryptocurrency was fraudulently transferred to groups of attacker-controlled addresses.
  • Associated with withdrawal suspensions, large-scale availability impacts occurred on user fund mobility and exchange business operations.
  • The extent to which the compromised backend affected other credentials or wallet control permissions has not been disclosed.

8. Observable Logs

Below are infrastructure investigation candidates within one's own organization. References to devices such as HSMs target organizations deploying such equipment and do not confirm adoption or log collection status at Bitget.

  • Email: No evidence has been confirmed indicating that email was used as a primary initial access vector.
  • Proxy / SWG / DNS: Correlate communication logs destined for management APIs, external SaaS, or unknown external destinations against known attacker infrastructure and normal administrative connection sources.
  • Endpoint / EDR: Scrutinize process trees, deployment histories, access to secrets, modifications to binaries or configuration files, administrative shell launches, and CI/CD execution histories on wallet backend servers.
  • Identity / IdP: Review authentication and authorization logs for internal service accounts, signing authorities, HSM sessions, and administrator VPNs. Bitget's HSM adoption status is unpublicized.
  • SaaS / Cloud: Reconcile parameters during transaction generation, signing digests, authorization records, policy decisions, transmission payloads, and blockchain receipts using unique transaction IDs.
  • Network: Track transfers destined for published attacker addresses in on-chain records while separately verifying communications from backends to unknown IP addresses or management ports. Distinguish between blockchain destination addresses and communication destination IPs.

9. Attack Success Determination

Confirmed in Public Information

  • Subsequent Compromise Confirmed: Bitget officially described the backend compromise and the unauthorized transfer of approximately $387.5 million. Evidence such as specific unauthorized authentication records or traces of malware execution remains unpublicized. (Target: Bitget exchange hot/warm wallets, multiple chains)

Internal Assessment Criteria

  • Malware Execution or Successful Authentication Confirmed: Determination criteria: Unauthorized authentication success or malware execution is determined via authentication logs and process audit trails. General explanatory overviews of backend compromises alone do not substantiate specific attack execution methods. (Target: Organization backend investigation; detailed authentication and execution records at Bitget are unpublicized)

10. Investigation Playbook

  • Investigation Starting Point: Initiate investigations upon detecting unauthorized transfers, discrepancies between transaction generation values and signed values, or high-value transfer alerts to new destinations.
  • Initial Verification: Identify impacted wallets, chains, asset types, transaction hashes, authorization personnel/systems, signing keys, and backend requesters.
  • Endpoint and Server Investigation: Perform forensic preservation of wallet backend systems, CI/CD environments, administrative jump hosts, and HSM integration components to investigate changes and signs of persistence.
  • Authentication and Cloud Investigation: Disable compromised service accounts, terminate affected HSM sessions, and revoke or rotate exposed administrative credentials and API keys. Audit suspicious permission changes.
  • Tracking Subsequent Operations: Track fund movements from attacker addresses to cross-chain bridges, mixers, and other exchanges, coordinating with relevant authorities to issue freezing requests.
  • Containment: Emergency-stop withdrawal functions, isolate the signing path from the network, and rebuild transaction verification functions in a clean environment.
  • Judgment Categories: Clearly distinguish and record the stages of backend compromise, transaction data tampering, signing execution, network broadcast, on-chain finalization, and fund freezing/recovery.

11. Defense and Detection Ideas

  • Single Event: Immediately detect and block transfers destined for addresses outside allowlists, high-value transfers exceeding anticipated limits, transfers to chains not normally used, and signed transactions inconsistent with policies.
  • Time-Series Correlation: Correlate events on a second-by-second timeline, from backend access through transaction generation, authorization, signing, broadcast, and on-chain transfers.
  • Threat Hunting: Retrospectively investigate historical access logs targeting wallet backend secrets, deployment configurations, and administrative access paths.
  • Log Limitations: Without storing both pre-signing canonical transaction data and signed payloads, post-event identification of data tampering locations is difficult.
  • Prioritized Countermeasures: Prioritize deploying independent transaction verification infrastructure, physical and logical separation of key management from backends, minimization of hot wallet balances, quorum approvals, and cross-chain kill switches.

12. Facts / Inference / Hypothesis

Facts

  • On September 24, 2026, Bitget detected multiple unauthorized transfers from limited hot and warm wallets and completely suspended withdrawals.
  • According to statements by the Bitget CEO cited by BleepingComputer, attackers compromised a critical backend of the wallet infrastructure, falsified transaction data, and triggered authorization processes. Initial access vectors and signing mechanism details have not been disclosed.
  • On-chain tracking investigations as of September 25 confirmed by Bitget showed that approximately $387.5 million in cryptocurrency spanning Ethereum/EVM-compatible chains, XRP Ledger, Zcash, and TRON was transferred to attacker-controlled addresses.
  • Bitget explained that it identified and patched the underlying vulnerability, contained the incident, and ensured no additional unauthorized transfers can occur. The official schedule planned for phased Bitcoin withdrawal resumptions starting September 28 at 08:00 UTC, and BleepingComputer also reported the resumption of withdrawals on September 28.
  • Based on the CEO statement cited by BleepingComputer, Bitget evaluated that attacker IP behaviors and on-chain analysis results exhibit high consistency with known patterns of North Korean threat actors. However, independent attribution confirmation by public authorities has not been shown.
  • Bitget stated that customer account balances were unaffected and losses will be fully covered by the exchange's Protection Fund. Mandiant and SlowMist participated in the investigation.

Inference

  • If the backend is in a state capable of modifying transaction details destined for signing, assets can be fraudulently transferred by abusing legitimate signing workflows without directly stealing the wallet's cryptographic keys themselves.
  • While resumed withdrawals indicate progress in containment and security validation, they do not independently establish how the attackers gained initial access or prove that all follow-on risks have been eliminated.

Hypothesis

No additional hypotheses. Unconfirmed items are listed in "14. Unknowns and Additional Investigations."

13. MITRE ATT&CK Mapping

ID Technique Confidence Basis
T1565 Data Manipulation medium Corresponds to the falsification of transaction data mentioned in the CEO statement. Classified under the parent technique as it remains unpublicized whether modifications were executed in stored data, communication channels, or runtime processes.
T1657 Financial Theft high Fraudulently transferred cryptocurrency to groups of attacker-controlled addresses.

14. Unknowns and Additional Investigations

  • The initial access vector to critical backend systems and the specific vulnerabilities exploited.
  • The exact boundary within signing policies, authorization flows, HSMs, or related components where transaction data falsification was established.
  • Objective evidence supporting attribution to North Korean threat actors, along with the attacker's initial access date and dwell time.

15. Impact on SOCs and Organizations

For organizations providing cryptocurrency exchanges or custody services, securing the integrity of backends that generate transactions prior to signing—alongside independent verification of destinations, amounts, and chain IDs—is indispensable, extending beyond hot wallet private key management. For high-value transfers, new addresses, and simultaneous multi-chain transfers, defense-in-depth is required that does not blindly trust parameters passed from backends and mandates separated policy verification engines alongside out-of-band approvals.

16. Summary by Target Audience

  • For SOCs: Perform time-series correlation from backend access to signing, broadcasting, and on-chain transfer, tracking transfers to published attacker addresses and subsequent fund movements.
  • For Administrators: Establish independent verification regimes for transaction signing targets, reduce hot wallet holdings, tighten approval quorums, and deploy cross-chain immediate-stop kill switches.
  • For Users: According to Bitget, there are no direct losses to customer account balances. Verify officially guided phased withdrawal schedules and the latest security notices.

Top comments (0)