
Bitget Hack Analysis: $387 Million Drained via Zero-Day Exploit
A sophisticated zero-day exploit targeting a third-party security tool allowed attackers to siphon $387.5 million from the Bitget exchange, marking the largest crypto theft of 2026.
Ethbase Newsroom · Published September 30, 2026 · Updated September 30, 2026
The September 24, 2026, security breach of Seychelles-based Bitget has become a defining moment for centralized platform security. While initial reports estimated losses at $351.6 million, subsequent forensic audits confirmed the total drain reached $387.5 million. This theft currently stands as the largest single cryptocurrency heist recorded in 2026.
Unlike many historical exchange hacks that rely on social engineering or compromised private keys, this attack targeted the software supply chain. Investigators identified a zero-day vulnerability within a third-party security product that the exchange had integrated only weeks prior to the event. This flaw allowed perpetrators to bypass standard safeguards by manipulating transaction data at the protocol level.
How the Zero-Day Exploit Worked
According to reporting by Crypto Briefing, the attackers did not need to access Bitget's cold storage or obtain private keys to execute the theft. Instead, the zero-day exploit tricked the exchange's internal approval process. By feeding the system manipulated data, the attackers made unauthorized outbound transfers appear as legitimate internal operations.
Security teams first detected the breach at 18:31 UTC on September 24.
The exploit's ability to automate approvals across multiple blockchain networks facilitated the rapid drain. Stolen assets included a diverse portfolio: $157 million in XRP, followed by significant amounts of ETH, USDT, USDC, ZEC, BNB, AVAX, and TRX. This multi-chain approach suggests the attackers possessed high levels of technical preparation and infrastructure readiness.
Tracing the North Korean Connection
Bitget CEO Gracy Chen has publicly attributed the attack to actors associated with the Democratic People's Republic of Korea (DPRK). This assessment stems from specific IP addresses and behavioral patterns that mirror previous state-sponsored cyber activities. If independent security firms verify this attribution, it would bring the total value of crypto assets stolen by North Korean-linked groups to over $1 billion in 2026 alone.
Attackers are finding weaker links in the increasingly complex ecosystem of institutional crypto custody by targeting third-party security vendors rather than the exchange's own code.
Recovery and the Bitget Exchange Hack 2026 Details
In the immediate aftermath, the exchange moved to stabilize its operations and reassure its user base. According to the Bitget exchange hack 2026 details provided by the platform, the User Protection Fund is the primary mechanism for covering these losses. At the time of the breach, this fund held over $464 million, a figure that exceeds the $387.5 million stolen in the exploit.
The exchange states that this fund is maintained in highly liquid assets to ensure that customer balances can be covered in full without requiring external bailouts. Following the detection of the unauthorized activity, Bitget suspended all withdrawals to prevent further outflows. By late September, the platform began a phased restoration of withdrawal services, prioritizing verified accounts and specific asset classes as security audits were completed. Users are advised to monitor official platform announcements for the specific timing of asset-specific withdrawal resumes and to verify their account security settings.
Laundering Through Zcash Shielded Pools
On-chain data observed by September 30 indicates that the attackers have begun moving the stolen funds through privacy-preserving protocols. Specifically, roughly 18,900 ZEC (valued at approximately $28 million) was moved from the exploit addresses. Of that amount, about 2,700 ZEC ($3.8 million) has been funneled into Zcash’s Ironwood shielded pool.
Zcash offers two transaction types: transparent and shielded. While transparent transactions are visible on a public ledger similar to Bitcoin, shielded transactions use zero-knowledge proofs to encrypt the sender, receiver, and transaction amount. Once funds enter the Ironwood pool, they become virtually untraceable to outside observers. This shift toward Zcash suggests that attackers are moving away from sanctioned mixers like Tornado Cash, which are more frequently flagged by centralized exchanges and regulatory bodies.
The Risks of Third-Party Security Audits
The Bitget incident highlights a growing risk in the cryptocurrency industry: the reliance on external security vendors. While these tools are designed to provide additional layers of protection, they also introduce new attack vectors. For exchanges, the lesson of 2026 is that even "security-enhancing" software must be treated as a potential point of failure.
Law enforcement and on-chain analysts are currently in a race against time to track the remaining $24 million in ZEC still sitting in transparent addresses. If these funds move into shielded pools, the likelihood of recovery drops significantly. For the broader market, the event serves as a reminder that even well-capitalized protection funds cannot replace the need for rigorous, multi-layered defense strategies that include continuous monitoring of third-party integrations. For related context, see Fairshake PAC Targets Sherrod Brown With.
Questions & Answers
- How much was stolen in the Bitget hack?
- A total of $387.5 million was stolen, making it the largest cryptocurrency theft of 2026 as of September 30.
- Are user funds at Bitget safe?
- Bitget has stated that its User Protection Fund, which held $464 million at the time of the hack, is sufficient to cover all customer losses in full.
- What was the cause of the breach?
- The breach was caused by a zero-day exploit in a third-party security product used by the exchange, which allowed attackers to manipulate internal transaction approvals.
- How are the attackers laundering the money?
- Attackers have been observed moving stolen Zcash (ZEC) into 'shielded pools,' a privacy feature that encrypts transaction details and makes them untraceable on the public ledger.
- Who is responsible for the Bitget attack?
- Bitget leadership has attributed the attack to actors linked to North Korea (DPRK), citing IP addresses and behavioral patterns consistent with previous state-sponsored hacks.
