Friday, September 25, 2026

Bitget hack traced across eight blockchains

Global News
By Scorechain Team

Quick overview

  • On September 24, 2026, Bitget lost $351.6 million from its hot wallets. Early indicators, including Bitget’s own findings, point to North Korea (DPRK), and Scorechain attributes the attacker wallets to North Korea’s Lazarus Group.
  • Within hours, our team mapped 28 attacker-controlled addresses (at the time of writing) across eight networks: Ethereum, Arbitrum, Optimism, Base, BNB Chain, Avalanche, TRON, and the XRP Ledger.
  • About 68,300 ETH (about $183 million) and 102.6 million XRP (about $158 million) are still sitting untouched in attacker wallets.
  • Almost all of the stolen value is still on-chain in wallets the attackers control, which is the window for exchanges to block deposits and support recovery.

On Thursday evening, attackers emptied part of one of the world’s largest crypto exchanges without ever touching its private keys. At 18:31 UTC on September 24, the first transfers left Bitget’s hot wallets for an address the exchange had never paid before. Within 45 minutes, the bulk of $351.6 million in ETH, stablecoins, tokenized gold, BNB, AVAX, XRP, and TRX had followed.

Bitget has confirmed the loss, paused withdrawals, and said its User Protection Fund, reported at more than $464 million, covers it in full. Here is what the blockchain shows about where the money went.

How the attackers got in

According to Bitget’s chief executive, the attackers compromised a backend system in the exchange’s wallet infrastructure, fed it spoofed transaction data, and let Bitget’s own authorisation process release the funds. Cold wallets were not affected.

The on-chain record matches that account. On BNB Chain, Avalanche, and Ethereum, the same Bitget hot wallet, 0xffa8…cd54, sent funds to the same attacker address within nine seconds:

Time (UTC) Network Amount
19:16:14 BNB Chain 12,719.46 BNB
19:16:15 Avalanche 821,012 AVAX
19:16:23 Ethereum 13,966 ETH

Three networks drained in nine seconds points to a single automated batch pushed through the exchange’s approval system, not to someone signing withdrawals by hand. Hot wallets are wired into automated approvals so exchanges can process withdrawals quickly, and that is exactly the layer this attack used. We saw a similar exposure in the Upbit hot wallet hack.

Who is behind the Bitget hack

Bitget said its preliminary evidence included IP addresses resembling VPN infrastructure previously linked to a North Korean threat group. Scorechain attributes the attacker wallets to North Korea’s Lazarus Group, which the U.S. Treasury designated under OFAC sanctions in September 2019. Our research team has traced the group before, including the Bybit hack addresses.

On Scorechain’s 0 to 100 risk scale, where a lower score means higher risk, every address in the cluster scores one, the highest risk level.

Mapping the attacker’s footprint

The attackers used one EVM address, 0x770b…63ee, to receive funds from Bitget on six networks, plus one wallet each on the XRP Ledger and TRON. From there the funds fanned out across 28 attacker-controlled addresses on eight networks. Optimism and Base are easy to miss: Bitget sent 5,738 ETH and 1,555 ETH to the attacker on those networks, and both balances were moved on within 45 minutes.

Out of stablecoins, into ETH

USDT, USDC, and XAUT, a gold-backed token, reached a dedicated swap wallet, 0x7c96…3e1c, within minutes of leaving Bitget. By the same evening they had been converted to ETH, partly through a market maker and partly on Uniswap.

That speed was deliberate. Issuers of fiat-backed stablecoins can freeze tokens at a blacklisted address, but they cannot freeze ETH. By converting early, the attackers moved most of the freezable value out of reach before a freeze request could realistically land.

Consolidated, then split into dormant wallets

Scorechain Exploration tool, consolidation wallet 0xA6dD…5545. ETH arrives from attacker wallets, including 0x469a…7425dc, which also received the Base funds, and an address carrying a Circle blacklist label, and leaves in lots of about 10,000 ETH to new wallets.

The ETH then flowed into a consolidation wallet, 0xA6dD…5545. One of its inflows, $4.13 million, comes from 0x469a…7425dc, the same address that received the ETH Bitget lost on Base. Another comes from an address Scorechain labels as blacklisted by Circle, so any USDC held there is frozen, but the ETH it passed on had already moved.

From 0xA6dD…5545, the ETH was split into lots of about 10,000 ETH and sent to new wallets. None of those wallets has sent a single transaction since.

Where the funds sit now

As of 11:00 UTC on September 25, almost all of the stolen value is still in attacker wallets.

Network Wallets Holding Amount Status
Ethereum 8 ~68,300 ETH (~$183M) Untouched
XRP Ledger 5 ~102.6M XRP (~$158M) Untouched, apart from small test sends
TRON 1 ~18.3M TRX (~$6M) 2.3M TRX started moving this morning

The TRON wallet is the first to move in size. At about 10:25 UTC it sent 2.3 million TRX to three new addresses, which our transaction monitoring flagged as they appeared.

An address-poisoning campaign on the trail

Nearly every wallet in the cluster is also receiving dust from look-alike addresses crafted to match the first and last characters of the real ones. On BNB Chain, the swap wallet alone received more than 100 of these transfers in about two hours. This is address poisoning, aimed at anyone who copies an address from a transaction history. For investigators and compliance teams working this case, the rule is simple: check every character of an address before it goes into a freeze request, a screening list, or an alert rule.

What this means for exchanges and compliance teams

The cluster is attributed in Scorechain. The 28 addresses reflect the cluster at the time of writing. We are following the case with Scorechain’s transaction monitoring and flag new addresses belonging to the attackers as soon as they start to launder. Exchanges and services screening with Scorechain’s transaction monitoring and wallet screening will see these funds flagged as critical risk if they touch their platform, whether they arrive directly or through intermediaries.

Speed matters here. With roughly $347 million still sitting in attacker wallets, the next few days are when exchanges can block deposits and support recovery. When the dormant ETH and XRP start to move, it will likely be in smaller lots and across more networks, which is what customisable alerts on these wallets are built to catch.

FAQ

How much was stolen in the Bitget hack?

Bitget reported $351.6 million in unauthorised transfers from its hot wallets on September 24, 2026. Scorechain has mapped the funds to 28 attacker-controlled addresses across eight networks, a count that will grow as the funds move.

Who is behind the Bitget hack?

Early indicators, including Bitget’s own findings, point to North Korea. Scorechain attributes the attacker wallets to North Korea’s Lazarus Group, an entity designated under OFAC sanctions.

How did the Bitget hack happen?

Bitget says attackers compromised a backend system in its wallet infrastructure and used spoofed transaction data to trigger its own authorisation process. Private keys and cold wallets were not affected.

Where are the stolen Bitget funds now?

As of 11:00 UTC on September 25, about 68,300 ETH and 102.6 million XRP sat untouched in attacker wallets. About 18.3 million TRX remained on TRON after 2.3 million TRX started moving.

Are Bitget user funds safe?

Bitget says its User Protection Fund, reported at more than $464 million, covers the full loss and that account balances are unaffected. Withdrawals were paused during the security review.

Can the stolen Bitget stablecoins still be frozen?

Not at the issuer level. Stablecoin issuers can freeze tokens held at a blacklisted address, but the attackers swapped the stolen USDT, USDC, and tokenized gold (XAUT) for ETH the same evening, and none of the 28 addresses still holds them. The remaining leverage is at exchanges and services, which can block deposits when the funds arrive.

The Bitget hack shows that an exchange’s security is only as strong as the systems that approve its withdrawals. The keys held, the cold wallets held, and $351.6 million still left in under an hour. What happens next depends on how quickly the rest of the market recognises these funds when they start to move.

This analysis reflects on-chain data as of 11:00 UTC on September 25, 2026. The 28 addresses listed are the attacker cluster at the time of publication; Scorechain continues to follow the case with its transaction monitoring and flags new attacker addresses as soon as they start to launder. Exposure to an exchange, market maker, or protocol in this trace does not imply wrongdoing by that party. This material is for informational purposes only and is not legal, tax, or investment advice.

Share

Summarize with AI

Want to see how Scorechain can help you trace illicit crypto flows and strengthen compliance?

Be the first to get news from Scorechain

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

350+ COMPLIANCE &  DIGITAL ASSET TEAMS TRUST US