Reports of Potential $387.5 Million Security Breach at Bitget Exchange
CIE News ·
Bitget is reportedly investigating a significant security incident involving unauthorized transfers from its hot and warm wallet infrastructure that allegedly resulted in losses totaling approximately $387.5 million in various digital assets, including Zcash and TRON. Following the discovery of these irregularities on September 24, 2026, the exchange opted to temporarily suspend all platform withdrawals to facilitate a comprehensive security audit and system review. In a move aimed at addressing potential user impact, the platform has indicated that it is leveraging its $464 million User Protection Fund to safeguard affected users, an action that comes amid widespread industry scrutiny regarding the potential severity of the alleged breach. Observers have noted that if confirmed, this incident could rank among the most significant security breaches involving a centralized exchange in recent years, highlighting the ongoing risks inherent in managing large-scale custodial infrastructures. Initial forensic assessments are currently exploring the preliminary hypothesis that the incident may have been executed through the sophisticated exploitation of backend systems rather than a direct compromise of private keys. Investigators are actively evaluating the theory that perpetrators potentially utilized advanced techniques to spoof transaction data, thereby circumventing standard security protocols governing asset outflows. To assist with this complex and ongoing inquiry, Bitget has engaged the specialized expertise of security firms Mandiant, SlowMist, and Elliptic to provide independent oversight. While the exchange has not definitively attributed the event to any specific entity, reports from Elliptic have noted that the observed patterns in the transaction activity share behavioral characteristics with operational methods previously associated with North Korea-affiliated hacker groups. The investigation remains in its formative stages as the exchange works to secure its infrastructure and verify forensic evidence, with further updates expected to be provided to affected users as the situation develops.