Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$83,780▼ 0.64%ETH$2,681▼ 0.19%SOL$121.02▲ 3.57%TOTAL CRYPTO$2.88T▼ 2.82%S&P 5007,743.41▲ 0.86%NASDAQ27,068.72▲ 3.51%DOW51,828.62▼ 3.26%GOLD4,320.50▼ 7.97%WTI92.44▲ 12.24%BRENT97.47▲ 10.04%EUR/USD1.1392▼ 2.37%USD/JPY157.19▼ 1.23%DXY101.04▲ 2.14%
Crypto

Bitget CEO Says $351.6M Hack Came Via Spoofed Transfers

Bitget CEO Gracy Chen says attackers spoofed transaction data rather than stealing keys, while Circle and Tether froze $318,000 in stablecoins tied to the heist.

Pexels – Lucas Andrade

Bitget CEO Gracy Chen said the $351.6 million hack that hit the exchange on Thursday came from spoofed transaction data that tricked its own authorization process, not from a stolen private key. The disclosure is the first clear account of how attackers pulled off the largest crypto exchange breach of 2026, and it came alongside the first tangible recovery effort: Circle and Tether froze about $318,000 in stablecoins tied to the linked attacker wallets.

Chen said the attackers compromised a wallet backend and fed the exchange authorization system forged transaction details, so staff approved movements they believed were legitimate. She ruled out a private key compromise and linked the actors to VPN infrastructure associated with North Korean hacking groups, according to statements reported by CoinDesk. She also rejected comparisons to FTX, saying reserves cover the loss in full.

The money is mostly ether, and ether cannot be frozen

Circle blacklisted a wallet labeled “Bitget Exploiter 8” on Etherscan at 05:00 UTC Friday, blocking roughly 99,990 USDC. Tether banned the same address about seven hours later, freezing around 218,023 USDT. Together the two issuers immobilized approximately $318,000, per reporting from Cryptonomist and Benzinga.

That is a rounding error against the total. Most of the stolen funds sit in ether, which no issuer can freeze at the contract level. On-chain trackers show the linked wallets holding about 170 ETH, with more than 63,000 ETH spread across other linked addresses. Forbes traced the movement hour by hour: 7,130.86 ether left one wallet at 19:01:35 Thursday, a second wallet added 15,362 ether in three transfers, and the attacker sold everything that could be frozen before consolidating the rest.

Bitget initially estimated its loss at $351.6 million and later revised the figure to $387.5 million. The exchange paused withdrawals pending a security review and said cold storage was untouched. Its user protection fund, holding more than $464 million, is covering the entire loss, which is why no retail customer has been asked to absorb a haircut so far.

A new attack class for exchange security teams

The spoofed-transfer method matters beyond Bitget. Exchanges have spent years building defenses against key theft, phishing and insider compromise. This attack bypassed all of that by corrupting the data humans relied on when approving withdrawals, which means the authorization step itself, long treated as the final checkpoint, became the weak point.

Security researchers will want to know how the backend was compromised in the first place. The statement from Chen describes the mechanism but not the initial entry. A full incident report was promised for 21:30 UTC Friday, and the answer to that question will determine whether other exchanges need to rework their own approval flows. If a single backend compromise can rewrite what operators see on screen, then display integrity becomes a control surface on par with key management.

The breach lands at a sensitive moment for the industry. Three smaller DeFi exploits drained $11 million on the same day, hitting Payy Network for $1.8 million, the casino platform Duelbits for $7 million and the Meter protocol for $2.3 million. Thursday was among the busiest days for crypto theft this year even before the Bitget number came in.

The market barely blinked

Bitcoin held near $84,400 through Friday, essentially flat, and 93 of the 100 largest tokens rose over 24 hours. The BGB token fell between 3 and 5.5 percent depending on the venue, but the broader market treated the hack as a contained event. That reaction tracks the size of the protection fund and the absence of any customer loss, though the withdrawal pause is still in place.

The muted response also reflects where demand is coming from. Bitcoin ETFs logged a sixth straight day of inflows on September 24, and corporate treasuries keep adding to positions, so the marginal buyer in this market is an institution rather than a retail trader who flees at the first headline. When Strategy disclosed another 950 BTC purchased last week, the flow story simply drowned out the security story.

A second scam is already running. Forbes reported that fraudsters are contacting Bitget users with fake recovery offers, a pattern seen after every major breach. The exchange has not said when withdrawals will reopen, and users with funds on the platform face an uncomfortable wait until the security review concludes.

What the freeze actually shows

The episode is a live demonstration of what stablecoin issuers can and cannot do. USDT and USDC are frozen because Circle and Tether control upgradeable contracts and can blacklist addresses. Ether, bitcoin and most other stolen assets have no such switch. Recovery from a hack of this size therefore depends on exchange cooperation, chain analytics firms tracing the funds, and the slow grind of law enforcement rather than any technical kill switch.

North Korean groups have historically held stolen funds for months before laundering them, moving in small tranches through mixers and cross-chain bridges. That habit gives investigators time, and it is why the small stablecoin freeze still matters: any attacker who later touches the frozen USDT or USDC hands investigators a confirmed link. The remaining 63,000 ether is the real prize, and the question is whether any of it moves toward an exchange or mixer where it can be traced further.

What happens next depends on two things: whether the incident report shows the spoofing vector could have been caught earlier, and whether Bitget can reopen withdrawals without a fresh incident. Exchanges that survived previous large hacks, including those hit by the Lazarus-linked campaigns of earlier years, generally recovered once customer funds were made whole quickly. The $464 million fund covering a $387.5 million loss leaves little slack, and the revised number may still move again as the audit continues.

For the wider market, the lesson is uncomfortable but familiar: the largest exchange breach of the year was not a cryptographic failure but a human-process failure, and it happened at an exchange that had marketed its security posture heavily. Operators everywhere will now be re-reading their own approval flows with the same question Chen could not yet answer on day one: who checked the data, and against what source of truth?

SourcesCoinDesk; Forbes; Cryptonomist; Benzinga
Share: X