Bitget Security Breach: Cross-Chain Fund Movement and Escalating Investigation

Following the disclosure of a major security incident at Bitget on September 24, on-chain activity indicates the attacker's fund movement operations are ongoing. Latest blockchain data analysis reveals frequent activity associated with the event, with funds flowing across multiple networks including Ethereum, BNB Chain, and TRON.

Fund Flow Patterns and Latest Developments

Monitoring data suggests the attacker likely utilized a centralized exchange for fund intermediation. On September 25, several anomalous withdrawal transactions originated from an address tagged as a Binance hot wallet.

  • Approximately 88.35 ETH withdrawn
  • Approximately 89.36 ETH withdrawn
  • Approximately 79.93 ETH withdrawn
  • Approximately $545,000 worth of USDT stablecoin withdrawn

The total value of these withdrawals is approximately $1.23 million. By September 26, tracking indicated that a consolidated sum of about 457.9 ETH had been aggregated into a new wallet address suspected to be controlled by the attacker. Blockchain analytics firm Bitquery is assisting in tracing the complete cross-chain path of these funds.

Revised Loss Figures and Confirmed Attack Vector

The initially reported loss for this security incident was approximately $351.6 million. After further audit, the platform has revised the estimated loss upward to approximately $387.5 million. According to Bitget's preliminary technical analysis, this attack was not executed through private key theft.

The core attack method involved infiltrating the platform's backend systems. The attacker illicitly triggered the system's authorization mechanism by forging transaction data, thereby siphoning funds. This approach focused on exploiting systemic logic vulnerabilities rather than directly compromising cryptographic keys.

Platform Response and Multi-Party Investigation Progress

Following the incident, Bitget proactively suspended all withdrawal services on its platform to prevent further fund outflow and protect user assets. The platform stated that its "User Protection Fund," valued at over $464 million, will be used to cover user losses resulting from this event.

The investigation has now mobilized multiple parties. Bitget and Binance have confirmed cooperation in the investigation. Professional cybersecurity firms Mandiant and SlowMist have also been engaged for technical forensics. Furthermore, relevant law enforcement agencies have been notified and may join subsequent investigations. Some security analysts, based on IP characteristics captured during the attack activities, have speculated about potential links to actors associated with a specific region, but this claim has not been officially confirmed.

The entire industry is closely watching the subsequent developments of this incident, which concerns not only the recovery of user assets but also serves as a stark warning about backend system security for all trading platforms.