Bitget has confirmed that an attacker moved about $387.5 million from its wallet infrastructure on Sept. 24, after compromising a backend system and tricking the exchange's authorization process into signing off on the transfers. The exchange says private keys were never compromised and that the vulnerability has since been remediated.
What makes the incident unusual is the timeline. Bitget flagged unauthorized activity at 18:31 UTC. The bulk of the money didn't leave until nearly an hour later.
An 18:31 test, then the real thing
The attacker's first move looked like a probe, not a heist. At 18:31 UTC, two small transfers — 0.84 ETH and 93 TRX — went out to freshly created addresses. That's the moment Bitget's detection systems fired.
Then the attacker waited. About 28 minutes passed before $34.75 million in USDT moved at 18:58 UTC, the first substantial transfer. From there the drain accelerated across multiple blockchains. The biggest hits came within minutes of each other: $87.6 million left hot wallets at 19:01 UTC, and another $202.8 million left warm wallets at 19:16 UTC.
Those two bursts took a combined 24 seconds to execute and accounted for roughly three-quarters of the total losses.
The signatures looked normal
Security firm Hypernative, which reviewed the transactions, said they were signed by Bitget's own wallets and resembled ordinary customer withdrawals closely enough to pass through the exchange's infrastructure unchallenged. That detail matters. It means the attack didn't break cryptography — it broke process.
Per Bitget's own investigation, the attacker got into a backend system inside the wallet stack, spoofed withdrawal data, and pushed it through an authorization flow that approved it. No private keys were taken.
Hypernative flagged several controls that could have cut the attack short after the initial 18:31 alert. Among them: requiring every signed transfer to match an independently stored customer withdrawal or approved treasury transaction; checking proposed transactions against normal withdrawal parameters such as gas limits; velocity limits on wallet tiers; and automatic suspension of affected signers the moment an anomalous-transfer alert fires.
Three hours of movement
Attacker-linked transfers kept going until 21:23 UTC — nearly three hours after Bitget's stated detection time. That gap between spotting the problem and stopping it is likely to draw scrutiny from the forensic teams still working the case.
Mandiant and SlowMist remain involved in the investigation. Bitget says no further unauthorized transfers occurred after containment.
There's no word yet on how much, if any, of the $387.5 million is recoverable, and the forensic review hasn't been given a completion date. Those are the two questions worth watching — the rest is now a paper trail.



