Bitget hack: where the $351.6M went, traced on-chain
We traced the Bitget exploiter's wallets across Ethereum and Avalanche. About 68,300 ETH ($184M) now sits in eight addresses that have not sent anything out, and outflows from the same hot wallets continued for nearly three hours after Bitget says it detected the attack.
Key facts
- Bitget lost about $351.6 million from hot and warm wallets on September 24, 2026, the largest crypto exchange hack of 2026.
- Bitget says no private keys were leaked: a compromised backend system forged transfer instructions that its own signing machines executed.
- The first transfer to the attacker (0.84 ETH) happened at 18:31:11 UTC, the same minute Bitget says it detected the attack; outflows from the same wallets continued until 21:23 UTC.
- Stablecoins and 3,000 XAUT worth about $60 million were converted to ETH within 23 minutes through an EIP-7702 delegated account using Uniswap and UniswapX.
- About 68,295 ETH (roughly $184 million) sits in eight attacker addresses; as of September 25, 03:55 UTC none of it has left the cluster, though the attacker is still consolidating leftovers into those addresses.
- Bitget covered the loss from its $464 million protection fund; withdrawals were paused, deposits and trading continued.
Bitget confirmed on September 24 that about $351.6 million left its hot and warm wallets in unauthorized transfers. CEO Gracy Chen said the attackers did not obtain private keys; instead they breached a backend system tied to the wallet service, forged transfer instructions, and triggered Bitget’s own signing process. Bitget suspects a supply-chain compromise of a third-party tool and has pointed at North Korea’s Lazarus Group, while stressing that attribution is preliminary. Withdrawals are paused; deposits and trading continue, and Bitget says its $464 million protection fund covers the loss.
That is the company’s account. Below is what the blockchain shows. We pulled the data directly from Ethereum and Avalanche block explorers rather than from screenshots, and filtered out the address-poisoning noise that already pollutes the exploiter’s transaction history. All times are UTC. Dollar values use prices at the time of writing: ETH $2,691, AVAX $10.29, XAUT $4,284.
The addresses
Bitget wallets that lost funds
| Address | Role | Balance after the attack |
|---|---|---|
0x1AB4973a48dc892Cd9971ECE8e01DcC7688f8F23 | Hot wallet; sent ETH, USDT, USDC on Ethereum and USDC on Avalanche | 45 ETH, 145 BNB |
0xffa8DB7B38579e6A2D14f9B347a9acE4d044cD54 | Aggregation wallet; sent ETH on Ethereum and AVAX on Avalanche | 155 ETH, 413 BNB |
0x5bdf85216ec1e38D6458C870992A69e38e03F7Ef | Sent 3,000 XAUT | 87 ETH |
All three still hold funds. That fits a forged-instruction attack better than a stolen-key attack: whoever controlled the pipeline moved what they could, but never emptied the wallets.
Attacker wallets
| Address | Role |
|---|---|
0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee | Primary recipient (“Bitget Exploiter 1”); the same key was used on Ethereum and Avalanche |
0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C | EIP-7702 delegated account that converted stablecoins and gold into ETH |
0xA6dD3F218B65E32Ccc37BE30f74884133c655545 | Second-stage aggregator; 43,213 ETH in, 43,213 ETH out |
0xe410a2E5710Ee787bcaa63f52A3943ff71F0d946 | Collector for funds bridged back from other chains (on Ethereum, not Arbitrum as some reports said) |
0x274Ee3aeCC2b2D41a4D606155d7E0EbC3da68681, 0x5085b3d52b5587c18EF456FcbcDe9A11d48340F8 | Cross-chain relay addresses, same key on Avalanche and Ethereum |
Timeline
| Time (UTC) | Event |
|---|---|
| 18:31:11 | 0x1AB4 sends 0.84 ETH to the exploiter. A test transfer. It matches Bitget’s stated detection time to the minute. |
| 18:58:59 | 34,751,168 USDT leaves 0x1AB4 |
| 19:01:23 | 12,852,046 USDC and 3,000.32 XAUT leave |
| 19:01:35 | 7,130.86 ETH leaves 0x1AB4 |
| 19:05 to 19:30 | Stablecoins and XAUT move to 0x7c96 and are swapped into 22,320 ETH in 23 minutes |
| 19:16 | 13,965.93 ETH leaves 0xffa8; on Avalanche, 821,012 AVAX leaves the same wallet |
| 20:09 | Another 1,879 and 1,396 ETH leave |
| 20:13 to 20:19 | Two tranches of 10,000 ETH are parked in fresh addresses |
| 20:55 | On Avalanche, 8,204,679 USDC leaves 0x1AB4 |
| 21:23:11 | The last transfer from a Bitget wallet: 223.2 ETH |
| 21:57 to 23:37 | The aggregator parks 43,213 ETH across five new addresses |
The detail that matters most: the first probe transfer is the exact minute Bitget says its systems raised the alarm, yet the same two wallets kept paying out for another two hours and fifty-two minutes. Detection worked. Containment did not. Whatever component was forging instructions kept its access to the signing flow long after the alert.
Where the money went
Direct outflows on Ethereum (received by the exploiter address)
| Asset | Amount | Approx. value |
|---|---|---|
| ETH | 24,596.6 | $66.2M |
| USDT | 34,751,168 | $34.8M |
| USDC | 12,852,046 | $12.9M |
| XAUT | 3,000.32 | $12.9M |
Direct outflows on Avalanche
| Asset | Amount | Approx. value |
|---|---|---|
| AVAX | 821,012 | $8.5M |
| USDC | 8,204,679 | $8.2M |
That is roughly $143 million visible through one exploiter address. The rest of the $351.6 million sits on chains we did not cover (XRP Ledger and TRON were named among the affected assets) and on BNB Chain, where the exploiter address made exactly one transaction that public RPC nodes would not let us read.
Converting stablecoins and gold. 0x7c96 is not a contract. It is an ordinary account delegated via EIP-7702 to MetaMask’s EIP7702StatelessDeleGator implementation, which let the attacker batch many swaps into single execute calls. USDT and USDC went through Uniswap v4’s PoolManager, v3 pools and UniswapX Dutch-order fills in $3M to $5M chunks. The 3,000 XAUT were sold in ten lots of 300. From the first USDT arriving at 19:07 to 22,320 ETH leaving at 19:30 took 23 minutes. The reason is obvious: Tether, Circle and Tether Gold can freeze their tokens; nobody can freeze ETH.
The Avalanche detour. The 8.2M USDC was swapped into 740,685 AVAX, then swapped back into USDC in batches, then burned through Circle’s CCTP bridge and minted on Ethereum, where MetaMask Swaps turned it into ETH. The round trip through AVAX looks pointless until you consider that Circle can blacklist a specific address while a CCTP transfer is in flight; moving through a fresh asset and a fresh address makes that harder. The 821,000 AVAX took a different route: 21 minutes after it landed on the relay address 0x5085, the same address on Ethereum was already swapping the proceeds into 2,943 ETH.
Other chains flowing back in. Ethereum also shows about 22.3 million USDC arriving as CCTP mints and about 3,031 ETH arriving through Stargate, all feeding the same aggregator. Those are proceeds from chains other than Avalanche, most likely BNB Chain and Arbitrum, converted and bridged to Ethereum within the same three-hour window.
Final resting place: 68,295 ETH, about $183.8 million, still inside the attacker’s cluster.
| Parking address | ETH |
|---|---|
0xD2C2f029eFF5caCc686F24377CfdDcfc82d9F899 | 10,000 |
0x600cfeDc6Bd65Fa79B604dC44964f419e45784b2 | 10,000 |
0x9FA39d62095302431d7d4167a7E80F8Ec6eA4FA0 | 10,000 |
0xA6BFd7FcaF4711dA1f61D5E91d03A2c7C72dB272 | 10,000 |
0xFd5EBe912e2061992437767e24e5BCb52a3f9e54 | 10,000 |
0xeD5a394a7558929112848B7e97B569de6bbE1A51 | 10,000 |
0xDc2901f741B4003e32B8B752e97b8c4C1891dC63 | 4,596 |
0x52f08Feb1B0Da609A5442514E2Bb43C99D25d284 | 3,698 (3,213 + 485 added at 03:45 UTC Sept 25) |
None of the eight has sent anything out. The total lines up with the $180M to $190M that Arkham and Bubblemaps flagged on the night of the attack.
Update, September 25, 03:55 UTC. The cluster is still being tidied, not emptied. At 02:55 UTC a previously unseen address, 0x2b03476bC4070e3019B3D5f4EC46edC27284ecd8, received 1,299,813 USDC minted through Circle’s CCTP bridge, meaning proceeds are still arriving from another chain more than eight hours after the theft. It swapped them into 483.75 ETH and sent that to the staging address 0x94A4 at 03:05, which passed it to the aggregator at 03:08; the aggregator forwarded 484.65 ETH to parking address 0x52f0…d284 at 03:45. That address now holds 3,698 ETH and the parked total is 68,295 ETH. No funds have left the eight parking addresses, and no transfers have gone to bridges, mixers or exchanges. We are checking every 20 minutes and will publish a follow-up if that changes.
What the technique tells us
A MetaMask workflow, end to end. The 7702 delegation uses MetaMask’s delegator contract, the swaps go through MetaMask Swaps’ MetaSwap router, and there is even a 1 ETH test through MetaMask Bridge at 19:10. This reads like an operator working through a wallet interface, not a pre-written exploit script.
The Bybit playbook. Stablecoins to ETH first, ETH parked in 10,000-unit tranches, the same private key reused across chains: every step matches how the Bybit proceeds were handled in February 2025. That is a similarity in tradecraft, not proof of identity. Bitget’s attribution rests on IP addresses that matched VPN services used in earlier DPRK operations, and no technical evidence has been published.
Speed over hygiene. Reusing one key on Avalanche and Ethereum, and converting everything within three hours, suggests the operators expected the stablecoin issuers to act quickly and prioritised speed over operational separation.
The exploiter is being poisoned too. The primary address received 23 fake-token transfers within hours: counterfeit USDC, AVAX and ETH tokens with Cyrillic letters and zero-width characters in their symbols, sent to lookalike addresses that mimic the real parking wallets. Anyone tallying the theft from an explorer page without filtering by token contract will get the wrong number.
What we could not verify
- BNB Chain. The exploiter address has a nonce of 1 there, so one outbound transaction exists, but every free RPC endpoint refused the log query. That leg needs an API key we do not have.
- Arbitrum. Several reports say
0xe410swapped 19.67M USDT0 for 7,111 ETH on Arbitrum. Blockscout shows no Arbitrum activity for that address, while on Ethereum it clearly received CCTP-minted USDC. Either the reports have the wrong chain or the explorer index is lagging; we could not cross-check with a second source. - XRP Ledger and TRON were not examined.
What to watch
The eight parking addresses are the signal. When Lazarus-linked funds start moving they typically go to THORChain for BTC, or into mixers such as Tornado Cash, in the days and weeks after the theft. Bitget has promised a full incident report with root-cause analysis by 21:30 UTC on September 25; the timeline above is what it should be measured against, in particular the 172-minute gap between detection and the last outflow.
For users, the practical points have not changed since Bybit: an exchange’s cold storage is only as good as the process that authorises transfers out of it, so keep on exchanges only what you trade, prefer venues with a published protection fund and a track record of covering losses, and read our guide to evaluating exchange safety.
This article will be updated when Bitget publishes its incident report.