On Thursday evening, attackers emptied part of one of the world’s largest crypto exchanges without ever touching its private keys. At 18:31 UTC on September 24, the first transfers left Bitget’s hot wallets for an address the exchange had never paid before. Within 45 minutes, the bulk of $351.6 million in ETH, stablecoins, tokenized gold, BNB, AVAX, XRP, and TRX had followed.
Bitget has confirmed the loss, paused withdrawals, and said its User Protection Fund, reported at more than $464 million, covers it in full. Here is what the blockchain shows about where the money went.
According to Bitget’s chief executive, the attackers compromised a backend system in the exchange’s wallet infrastructure, fed it spoofed transaction data, and let Bitget’s own authorisation process release the funds. Cold wallets were not affected.
The on-chain record matches that account. On BNB Chain, Avalanche, and Ethereum, the same Bitget hot wallet, 0xffa8…cd54, sent funds to the same attacker address within nine seconds:
Three networks drained in nine seconds points to a single automated batch pushed through the exchange’s approval system, not to someone signing withdrawals by hand. Hot wallets are wired into automated approvals so exchanges can process withdrawals quickly, and that is exactly the layer this attack used. We saw a similar exposure in the Upbit hot wallet hack.
Bitget said its preliminary evidence included IP addresses resembling VPN infrastructure previously linked to a North Korean threat group. Scorechain attributes the attacker wallets to North Korea’s Lazarus Group, which the U.S. Treasury designated under OFAC sanctions in September 2019. Our research team has traced the group before, including the Bybit hack addresses.
On Scorechain’s 0 to 100 risk scale, where a lower score means higher risk, every address in the cluster scores one, the highest risk level.
The attackers used one EVM address, 0x770b…63ee, to receive funds from Bitget on six networks, plus one wallet each on the XRP Ledger and TRON. From there the funds fanned out across 28 attacker-controlled addresses on eight networks. Optimism and Base are easy to miss: Bitget sent 5,738 ETH and 1,555 ETH to the attacker on those networks, and both balances were moved on within 45 minutes.
USDT, USDC, and XAUT, a gold-backed token, reached a dedicated swap wallet, 0x7c96…3e1c, within minutes of leaving Bitget. By the same evening they had been converted to ETH, partly through a market maker and partly on Uniswap.
That speed was deliberate. Issuers of fiat-backed stablecoins can freeze tokens at a blacklisted address, but they cannot freeze ETH. By converting early, the attackers moved most of the freezable value out of reach before a freeze request could realistically land.

The ETH then flowed into a consolidation wallet, 0xA6dD…5545. One of its inflows, $4.13 million, comes from 0x469a…7425dc, the same address that received the ETH Bitget lost on Base. Another comes from an address Scorechain labels as blacklisted by Circle, so any USDC held there is frozen, but the ETH it passed on had already moved.
From 0xA6dD…5545, the ETH was split into lots of about 10,000 ETH and sent to new wallets. None of those wallets has sent a single transaction since.
As of 11:00 UTC on September 25, almost all of the stolen value is still in attacker wallets.
The TRON wallet is the first to move in size. At about 10:25 UTC it sent 2.3 million TRX to three new addresses, which our transaction monitoring flagged as they appeared.
Nearly every wallet in the cluster is also receiving dust from look-alike addresses crafted to match the first and last characters of the real ones. On BNB Chain, the swap wallet alone received more than 100 of these transfers in about two hours. This is address poisoning, aimed at anyone who copies an address from a transaction history. For investigators and compliance teams working this case, the rule is simple: check every character of an address before it goes into a freeze request, a screening list, or an alert rule.
The cluster is attributed in Scorechain. The 28 addresses reflect the cluster at the time of writing. We are following the case with Scorechain’s transaction monitoring and flag new addresses belonging to the attackers as soon as they start to launder. Exchanges and services screening with Scorechain’s transaction monitoring and wallet screening will see these funds flagged as critical risk if they touch their platform, whether they arrive directly or through intermediaries.
Speed matters here. With roughly $347 million still sitting in attacker wallets, the next few days are when exchanges can block deposits and support recovery. When the dormant ETH and XRP start to move, it will likely be in smaller lots and across more networks, which is what customisable alerts on these wallets are built to catch.
Bitget reported $351.6 million in unauthorised transfers from its hot wallets on September 24, 2026. Scorechain has mapped the funds to 28 attacker-controlled addresses across eight networks, a count that will grow as the funds move.
Early indicators, including Bitget’s own findings, point to North Korea. Scorechain attributes the attacker wallets to North Korea’s Lazarus Group, an entity designated under OFAC sanctions.
Bitget says attackers compromised a backend system in its wallet infrastructure and used spoofed transaction data to trigger its own authorisation process. Private keys and cold wallets were not affected.
As of 11:00 UTC on September 25, about 68,300 ETH and 102.6 million XRP sat untouched in attacker wallets. About 18.3 million TRX remained on TRON after 2.3 million TRX started moving.
Bitget says its User Protection Fund, reported at more than $464 million, covers the full loss and that account balances are unaffected. Withdrawals were paused during the security review.
Not at the issuer level. Stablecoin issuers can freeze tokens held at a blacklisted address, but the attackers swapped the stolen USDT, USDC, and tokenized gold (XAUT) for ETH the same evening, and none of the 28 addresses still holds them. The remaining leverage is at exchanges and services, which can block deposits when the funds arrive.
The Bitget hack shows that an exchange’s security is only as strong as the systems that approve its withdrawals. The keys held, the cold wallets held, and $351.6 million still left in under an hour. What happens next depends on how quickly the rest of the market recognises these funds when they start to move.
This analysis reflects on-chain data as of 11:00 UTC on September 25, 2026. The 28 addresses listed are the attacker cluster at the time of publication; Scorechain continues to follow the case with its transaction monitoring and flags new attacker addresses as soon as they start to launder. Exposure to an exchange, market maker, or protocol in this trace does not imply wrongdoing by that party. This material is for informational purposes only and is not legal, tax, or investment advice.































