Bitget, one of the world’s top ten crypto exchanges by trading volume, watched $463 million walk out the door in a single day after a security breach drained hundreds of millions from its hot wallets. The September 29 outflow figure represents the largest single-day withdrawal event tracked by DefiLlama in four years.
The breach itself occurred on September 24, when attackers exploited a vulnerability in a third-party security product to inject spoofed transaction data into Bitget’s authorization process. The revised loss estimate sits between $387.5 million and $388 million, up from the initial $351.6 million figure reported in the immediate aftermath.
How the attack unfolded
The attackers ran two smaller test transfers first, probing Bitget’s risk controls before executing the main unauthorized withdrawal.
Bitget’s private keys were never compromised, and cold storage wallets remained untouched. The vulnerability lived in a third-party security product that interfaced with the exchange’s backend systems, allowing the attackers to spoof transaction data that looked legitimate to Bitget’s authorization layer.
The trust deficit
Bitget holds roughly $5.7 billion in reserves, which means the hack represented approximately 6.8% of total holdings.
Bitget initiated a phased resumption of withdrawals starting September 28, four days after the breach.
The exchange had maintained a User Protection Fund specifically designed for incidents like this. Before the hack, that fund exceeded $464 million, roughly enough to cover the stolen amount. Post-incident, the fund has reportedly fallen below $200 million, having absorbed a substantial portion of user losses.
If the fund started above $464 million and dropped below $200 million, that’s at least $264 million deployed. The total loss was $387.5 to $388 million.
The Lazarus connection
CEO Gracy Chen disclosed that initial forensic indicators point toward North Korean threat actors, specifically the Lazarus Group. Mandiant and SlowMist, two well-known cybersecurity and blockchain forensics firms, are assisting with the ongoing investigation.
The pattern of test transactions before the main theft is consistent with tactics previously attributed to the group.
Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
8






English (US) ·