EntryCrypto

Bitget hack: where the $351.6M went, traced on-chain

By EntryCrypto ·

We traced the Bitget exploiter's wallets across Ethereum and Avalanche. About 68,300 ETH ($184M) now sits in eight addresses that have not sent anything out, and outflows from the same hot wallets continued for nearly three hours after Bitget says it detected the attack.

Key facts

  • Bitget lost about $351.6 million from hot and warm wallets on September 24, 2026, the largest crypto exchange hack of 2026.
  • Bitget says no private keys were leaked: a compromised backend system forged transfer instructions that its own signing machines executed.
  • The first transfer to the attacker (0.84 ETH) happened at 18:31:11 UTC, the same minute Bitget says it detected the attack; outflows from the same wallets continued until 21:23 UTC.
  • Stablecoins and 3,000 XAUT worth about $60 million were converted to ETH within 23 minutes through an EIP-7702 delegated account using Uniswap and UniswapX.
  • About 68,295 ETH (roughly $184 million) sits in eight attacker addresses; as of September 25, 03:55 UTC none of it has left the cluster, though the attacker is still consolidating leftovers into those addresses.
  • Bitget covered the loss from its $464 million protection fund; withdrawals were paused, deposits and trading continued.

Bitget confirmed on September 24 that about $351.6 million left its hot and warm wallets in unauthorized transfers. CEO Gracy Chen said the attackers did not obtain private keys; instead they breached a backend system tied to the wallet service, forged transfer instructions, and triggered Bitget’s own signing process. Bitget suspects a supply-chain compromise of a third-party tool and has pointed at North Korea’s Lazarus Group, while stressing that attribution is preliminary. Withdrawals are paused; deposits and trading continue, and Bitget says its $464 million protection fund covers the loss.

That is the company’s account. Below is what the blockchain shows. We pulled the data directly from Ethereum and Avalanche block explorers rather than from screenshots, and filtered out the address-poisoning noise that already pollutes the exploiter’s transaction history. All times are UTC. Dollar values use prices at the time of writing: ETH $2,691, AVAX $10.29, XAUT $4,284.

The addresses

Bitget wallets that lost funds

AddressRoleBalance after the attack
0x1AB4973a48dc892Cd9971ECE8e01DcC7688f8F23Hot wallet; sent ETH, USDT, USDC on Ethereum and USDC on Avalanche45 ETH, 145 BNB
0xffa8DB7B38579e6A2D14f9B347a9acE4d044cD54Aggregation wallet; sent ETH on Ethereum and AVAX on Avalanche155 ETH, 413 BNB
0x5bdf85216ec1e38D6458C870992A69e38e03F7EfSent 3,000 XAUT87 ETH

All three still hold funds. That fits a forged-instruction attack better than a stolen-key attack: whoever controlled the pipeline moved what they could, but never emptied the wallets.

Attacker wallets

AddressRole
0x770b10b273fC44Fe9197D6bF20F145c2e98463EePrimary recipient (“Bitget Exploiter 1”); the same key was used on Ethereum and Avalanche
0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1CEIP-7702 delegated account that converted stablecoins and gold into ETH
0xA6dD3F218B65E32Ccc37BE30f74884133c655545Second-stage aggregator; 43,213 ETH in, 43,213 ETH out
0xe410a2E5710Ee787bcaa63f52A3943ff71F0d946Collector for funds bridged back from other chains (on Ethereum, not Arbitrum as some reports said)
0x274Ee3aeCC2b2D41a4D606155d7E0EbC3da68681, 0x5085b3d52b5587c18EF456FcbcDe9A11d48340F8Cross-chain relay addresses, same key on Avalanche and Ethereum

Timeline

Time (UTC)Event
18:31:110x1AB4 sends 0.84 ETH to the exploiter. A test transfer. It matches Bitget’s stated detection time to the minute.
18:58:5934,751,168 USDT leaves 0x1AB4
19:01:2312,852,046 USDC and 3,000.32 XAUT leave
19:01:357,130.86 ETH leaves 0x1AB4
19:05 to 19:30Stablecoins and XAUT move to 0x7c96 and are swapped into 22,320 ETH in 23 minutes
19:1613,965.93 ETH leaves 0xffa8; on Avalanche, 821,012 AVAX leaves the same wallet
20:09Another 1,879 and 1,396 ETH leave
20:13 to 20:19Two tranches of 10,000 ETH are parked in fresh addresses
20:55On Avalanche, 8,204,679 USDC leaves 0x1AB4
21:23:11The last transfer from a Bitget wallet: 223.2 ETH
21:57 to 23:37The aggregator parks 43,213 ETH across five new addresses

The detail that matters most: the first probe transfer is the exact minute Bitget says its systems raised the alarm, yet the same two wallets kept paying out for another two hours and fifty-two minutes. Detection worked. Containment did not. Whatever component was forging instructions kept its access to the signing flow long after the alert.

Where the money went

Direct outflows on Ethereum (received by the exploiter address)

AssetAmountApprox. value
ETH24,596.6$66.2M
USDT34,751,168$34.8M
USDC12,852,046$12.9M
XAUT3,000.32$12.9M

Direct outflows on Avalanche

AssetAmountApprox. value
AVAX821,012$8.5M
USDC8,204,679$8.2M

That is roughly $143 million visible through one exploiter address. The rest of the $351.6 million sits on chains we did not cover (XRP Ledger and TRON were named among the affected assets) and on BNB Chain, where the exploiter address made exactly one transaction that public RPC nodes would not let us read.

Converting stablecoins and gold. 0x7c96 is not a contract. It is an ordinary account delegated via EIP-7702 to MetaMask’s EIP7702StatelessDeleGator implementation, which let the attacker batch many swaps into single execute calls. USDT and USDC went through Uniswap v4’s PoolManager, v3 pools and UniswapX Dutch-order fills in $3M to $5M chunks. The 3,000 XAUT were sold in ten lots of 300. From the first USDT arriving at 19:07 to 22,320 ETH leaving at 19:30 took 23 minutes. The reason is obvious: Tether, Circle and Tether Gold can freeze their tokens; nobody can freeze ETH.

The Avalanche detour. The 8.2M USDC was swapped into 740,685 AVAX, then swapped back into USDC in batches, then burned through Circle’s CCTP bridge and minted on Ethereum, where MetaMask Swaps turned it into ETH. The round trip through AVAX looks pointless until you consider that Circle can blacklist a specific address while a CCTP transfer is in flight; moving through a fresh asset and a fresh address makes that harder. The 821,000 AVAX took a different route: 21 minutes after it landed on the relay address 0x5085, the same address on Ethereum was already swapping the proceeds into 2,943 ETH.

Other chains flowing back in. Ethereum also shows about 22.3 million USDC arriving as CCTP mints and about 3,031 ETH arriving through Stargate, all feeding the same aggregator. Those are proceeds from chains other than Avalanche, most likely BNB Chain and Arbitrum, converted and bridged to Ethereum within the same three-hour window.

Final resting place: 68,295 ETH, about $183.8 million, still inside the attacker’s cluster.

Parking addressETH
0xD2C2f029eFF5caCc686F24377CfdDcfc82d9F89910,000
0x600cfeDc6Bd65Fa79B604dC44964f419e45784b210,000
0x9FA39d62095302431d7d4167a7E80F8Ec6eA4FA010,000
0xA6BFd7FcaF4711dA1f61D5E91d03A2c7C72dB27210,000
0xFd5EBe912e2061992437767e24e5BCb52a3f9e5410,000
0xeD5a394a7558929112848B7e97B569de6bbE1A5110,000
0xDc2901f741B4003e32B8B752e97b8c4C1891dC634,596
0x52f08Feb1B0Da609A5442514E2Bb43C99D25d2843,698 (3,213 + 485 added at 03:45 UTC Sept 25)

None of the eight has sent anything out. The total lines up with the $180M to $190M that Arkham and Bubblemaps flagged on the night of the attack.

Update, September 25, 03:55 UTC. The cluster is still being tidied, not emptied. At 02:55 UTC a previously unseen address, 0x2b03476bC4070e3019B3D5f4EC46edC27284ecd8, received 1,299,813 USDC minted through Circle’s CCTP bridge, meaning proceeds are still arriving from another chain more than eight hours after the theft. It swapped them into 483.75 ETH and sent that to the staging address 0x94A4 at 03:05, which passed it to the aggregator at 03:08; the aggregator forwarded 484.65 ETH to parking address 0x52f0…d284 at 03:45. That address now holds 3,698 ETH and the parked total is 68,295 ETH. No funds have left the eight parking addresses, and no transfers have gone to bridges, mixers or exchanges. We are checking every 20 minutes and will publish a follow-up if that changes.

What the technique tells us

A MetaMask workflow, end to end. The 7702 delegation uses MetaMask’s delegator contract, the swaps go through MetaMask Swaps’ MetaSwap router, and there is even a 1 ETH test through MetaMask Bridge at 19:10. This reads like an operator working through a wallet interface, not a pre-written exploit script.

The Bybit playbook. Stablecoins to ETH first, ETH parked in 10,000-unit tranches, the same private key reused across chains: every step matches how the Bybit proceeds were handled in February 2025. That is a similarity in tradecraft, not proof of identity. Bitget’s attribution rests on IP addresses that matched VPN services used in earlier DPRK operations, and no technical evidence has been published.

Speed over hygiene. Reusing one key on Avalanche and Ethereum, and converting everything within three hours, suggests the operators expected the stablecoin issuers to act quickly and prioritised speed over operational separation.

The exploiter is being poisoned too. The primary address received 23 fake-token transfers within hours: counterfeit USDC, AVAX and ETH tokens with Cyrillic letters and zero-width characters in their symbols, sent to lookalike addresses that mimic the real parking wallets. Anyone tallying the theft from an explorer page without filtering by token contract will get the wrong number.

What we could not verify

  • BNB Chain. The exploiter address has a nonce of 1 there, so one outbound transaction exists, but every free RPC endpoint refused the log query. That leg needs an API key we do not have.
  • Arbitrum. Several reports say 0xe410 swapped 19.67M USDT0 for 7,111 ETH on Arbitrum. Blockscout shows no Arbitrum activity for that address, while on Ethereum it clearly received CCTP-minted USDC. Either the reports have the wrong chain or the explorer index is lagging; we could not cross-check with a second source.
  • XRP Ledger and TRON were not examined.

What to watch

The eight parking addresses are the signal. When Lazarus-linked funds start moving they typically go to THORChain for BTC, or into mixers such as Tornado Cash, in the days and weeks after the theft. Bitget has promised a full incident report with root-cause analysis by 21:30 UTC on September 25; the timeline above is what it should be measured against, in particular the 172-minute gap between detection and the last outflow.

For users, the practical points have not changed since Bybit: an exchange’s cold storage is only as good as the process that authorises transfers out of it, so keep on exchanges only what you trade, prefer venues with a published protection fund and a track record of covering losses, and read our guide to evaluating exchange safety.

This article will be updated when Bitget publishes its incident report.

Sources

  1. Bitget CEO suspects North Korea behind $352M hack, citing IP clues

    Cointelegraph · · Security · Exchanges

  2. Asia dominates Crypto Adoption Index, Bitget’s $351M hack: Asia Express

    Cointelegraph · · Security · Exchanges

  3. Nearly $352M Moved From Crypto Exchange Bitget Wallets in Suspected Hack

    Bitcoin Magazine · · Security · Exchanges

  4. Crypto exchange Bitget says $352 million affected in a hack, claims user funds are 'safe'

    CoinDesk · · Security · Exchanges

  5. Bitget confirms $351M security breach, suspends withdrawals

    Cointelegraph · · Security · Exchanges

  6. Bitget Suspends Withdrawals, Says $351.6 Million Affected In Hot Wallet Breach

    The Defiant · · Security · Exchanges