Loading market data...

Bitget Attacker Ran Test Transfers Before $388M Drain, CEO Says

Bitget Attacker Ran Test Transfers Before $388M Drain, CEO Says

Bitget's attacker executed two small test transfers about 30 minutes before draining $388 million from the exchange, according to CEO Gracy Chen. The detail suggests the breach was planned and rehearsed rather than opportunistic, though Chen did not specify the amounts involved in the test transactions.

The 30-minute window

Test transfers are a common tactic in large-scale crypto thefts. Attackers send tiny amounts first to confirm that a compromised key, contract, or internal process behaves as expected. If the small transfers clear without triggering alarms, the full drain follows. In Bitget's case, that gap lasted roughly half an hour — enough time for the attacker to verify access but short enough to limit the window in which defenders might notice.

Chen's disclosure places the test transfers before the main theft, but it doesn't explain how the attacker obtained whatever access made those tests possible. The exchange has not said whether the test transfers originated from the same address or contract as the $388 million drain, or whether they moved through a different path entirely.

What the $388 million figure covers

Bitget has put the total stolen at $388 million. That number is the only loss figure the exchange has confirmed. Chen has not broken it down by asset, chain, or wallet, and it's not clear whether the figure reflects the value at the time of the transfers or at a later point when prices may have moved.

Public blockchain records would normally allow trackers to follow the funds, but Bitget hasn't published the attacker's addresses. Until it does, independent verification of the $388 million total — and of the two test transfers — depends on the exchange releasing more data.

Why the test transfers matter

If the test transfers came from the same infrastructure that later drained the funds, investigators can treat them as the first confirmed point of contact between the attacker and Bitget's systems. That's often the most useful lead in a post-mortem: not the biggest transaction, but the earliest one that shows how access was established. The 30-minute gap also gives a rough timeline. Whoever ran the tests either moved quickly once they confirmed success or had already prepared the main transfer to fire on short notice.

Chen's statement doesn't say whether Bitget's monitoring systems flagged either test transfer, or whether the exchange had any chance to intervene before the drain. That omission leaves the central operational question open: did the exchange see the warning signs and miss them, or did the attacker's method leave no visible signal until the main theft was already underway?

What Bitget hasn't said

Three basic facts remain undisclosed. The size of the test transfers. The mechanism of the compromise. The current location of the funds. Chen has confirmed the total and the sequence, but not the specifics that would let outside analysts reconstruct the attack. For an exchange that just lost $388 million, those are the details the market will want before it can judge whether the vulnerability has been closed.

Bitget hasn't announced a timeline for publishing the attacker's addresses or a fuller incident report. Until that happens, the two test transfers stand as the earliest concrete lead — and the only one the exchange has chosen to share.