Bitget hacker withdraws $1.23M from Binance, funnels funds to attacker-controlled wallet

3 hours ago 11

The attacker behind the massive Bitget security breach has started moving money through Binance, withdrawing $1.23 million from the exchange and routing it to a wallet linked to the hack. The transaction marks a new phase in what has become one of the largest crypto heists of 2026, with investigators now racing to trace funds across multiple blockchain networks.

The original breach, detected on September 24 at 18:31 UTC, resulted in unauthorized transfers totaling as much as $387.5 million from Bitget’s hot and warm wallets.

How the funds are moving

On September 25, just one day after the initial heist, on-chain analysis revealed five separate withdrawals from Binance’s hot wallets. These included approximately 88.35 ETH, 89.36 ETH, 79.93 ETH, and roughly $545,000 in USDT.

By September 26, a total of 457.9 ETH had been forwarded to a wallet presumed to be under the attacker’s control. The latest $1.23 million withdrawal follows the same playbook: pull funds from a major exchange, then consolidate them in a wallet outside the reach of any single platform’s freeze capabilities.

Blockchain analysis firms, including Bitquery, have traced stolen funds flowing across Ethereum, BNB Chain, and TRON. Bitget and Binance have confirmed they are collaborating on tracing the stolen funds. Law enforcement agencies have also been notified, and cybersecurity firms Mandiant and SlowMist are both assisting in the investigation.

Inside the breach

The attack itself was unusually sophisticated. Rather than stealing private keys or breaching cold storage, the attacker compromised Bitget’s backend system in a way that allowed them to spoof transaction data, tricking the system into authorizing transfers that looked legitimate internally but were actually routing funds to the attacker.

Initial loss estimates pegged the damage at $351.6 million, but that figure was later revised upward to $387.5 million as investigators identified additional unauthorized transfers. Bitget paused withdrawals shortly after the breach was detected and pledged to cover customer losses through its User Protection Fund, which holds over $464 million.

North Korea speculation and industry fallout

IP address patterns identified during the investigation have led some analysts to speculate that North Korean-linked actors may be behind the breach. This attribution has not been confirmed by authorities, but it would fit a well-documented pattern. North Korean hacking groups, particularly Lazarus Group, have been linked to billions of dollars in crypto theft over the past several years, often using similarly sophisticated multi-chain laundering techniques.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article