DEV Community

qanzhi111
qanzhi111

Posted on

Bitget $387.5M Hack Analysis: Zero-Day Exploit, Admin Credential Theft, and THORChain Laundering

In late September 2026, the cryptocurrency industry witnessed one of its most sophisticated exchange breaches to date. Bitget, a major global digital asset platform, suffered a massive security incident resulting in the loss of approximately $387.5 million. Unlike typical hot wallet key extractions, this attack leveraged a zero-day vulnerability, compromised administrative credentials, and highly efficient cross-chain laundering techniques. The incident not only highlights the evolving tactics of state-aligned threat actors but also underscores the critical role of artificial intelligence in modern blockchain forensics.

The Timeline and Attack Mechanism

The breach unfolded on September 24, 2026, beginning with a calculated probing phase. At 18:31 UTC, the attacker initiated small, unauthorized test transfers involving ETH and TRX. Because these initial movements were deliberately kept below the exchange's automated risk-control thresholds, they failed to trigger any immediate security alerts.

Emboldened by the success of the test transactions, the threat actor escalated the operation. Between 18:58 and 20:09 UTC, the attacker executed 17 large-scale withdrawals across multiple networks, including Ethereum, XRP, Zcash, TRON, BNB Chain, Base, Arbitrum, Optimism, and Avalanche. The initial internal reconciliation estimated the loss at $351.6 million, but this figure was later revised to $387.5 million after additional Zcash and TRON transactions were fully accounted for.

Bitget’s automated reconciliation system finally flagged a major discrepancy at 19:05 UTC, prompting the platform to halt user-initiated withdrawals. However, the attacker continued injecting fraudulent commands directly into the wallet backend systems until the final transfer was recorded at 21:23 UTC. It was not until 21:44 UTC that the exchange completely shut down its signing machines and wallet withdrawal services.

Root-Cause Technical Breakdown

A common misconception in exchange hacks is that private keys are always the primary target. In the Bitget incident, the underlying private keys were never compromised, and the platform's cold wallets remained entirely untouched. Instead, the attackers exploited a critical weakness in the transaction-signing trust chain.

The root cause was a zero-day vulnerability in a third-party security product, which the attackers chained together with stolen, highly privileged internal network credentials. This combination granted the threat actors access to Bitget's internal management systems. From there, they were able to inject fraudulent withdrawal instructions directly into the wallet backend. Because the commands originated from what the system recognized as legitimate internal infrastructure, they bypassed standard risk checks. To further complicate the incident response, the attackers systematically deleted the logs and traces associated with their forged commands after each transfer.

Laundering Mechanics and Economic Impact

Once the funds were extracted, the laundering process began with astonishing speed. The stolen portfolio included roughly $75.48 million in stablecoins (USDT, USDC, and USDT0) alongside 3,000 XAUt (a gold-backed token). Recognizing the centralized nature of these assets and the risk of issuer-level freezes, the attackers swapped every stolen stablecoin into native tokens like ETH and AVAX within just 41 minutes of the initial theft.

Following the initial conversion, the attackers utilized cross-chain liquidity protocols to obscure the trail. The primary mechanism for consolidating the stolen wealth was THORChain, a decentralized cross-chain swap protocol. Over the days following the hack, approximately $269 million was routed through THORChain to be consolidated into Bitcoin. Other protocols, such as Chainflip, were also utilized to move roughly $37.27 million. Once converted to Bitcoin, the attackers began utilizing CoinJoin transactions to mix the coins and break the on-chain link between inputs and outputs.

Despite the rapid movement of funds, only a tiny fraction was immobilized. Publicly visible freezes totaled approximately $840,000, representing just 0.2% of the stolen sum. Tether and Circle froze about $340,000 in stablecoins that were left dormant on attacker addresses, while NEAR Intents intercepted roughly $503,000 during execution.

Economically, the $387.5 million loss was absorbed by Bitget’s User Protection Fund, which held a valuation of approximately $465 million at the time. The exchange committed to replenishing the fund to at least $300 million within a week using corporate reserves that exceeded $1.4 billion.

An incident like this scale is very serious, but serious doesn't mean existential.

AI Forensics and the Speed of Investigation

The sheer velocity of the cross-chain laundering necessitated an equally rapid investigative response. Traditional manual tracing of complex bridge transactions across multiple blockchains is incredibly time-consuming. In this case, investigators leveraged in-house artificial intelligence to build custom automations tailored to the specific investigation.

By utilizing agentic AI platforms to interrogate on-chain data sources, investigators were able to match deposits to corresponding payouts across fragmented protocols. This AI-assisted approach compressed what would have been more than 20 hours of manual bridge reconciliation into under 10 minutes. While the AI accelerated the data processing and graph-building, human investigators remained essential for defining the logic, reviewing the outputs, and directing the overall strategy.

Concrete Lessons for Builders and Users

The Bitget breach offers several critical takeaways for the Web3 ecosystem:

  1. Secure the Entire Trust Chain: Protecting private keys is not enough. Exchanges must rigorously audit third-party security products and enforce strict, multi-layered access controls for internal administrative credentials. The transaction-signing infrastructure itself must be treated as a primary attack surface.
  2. Implement Dynamic Risk Thresholds: Static risk limits can be easily bypassed by attackers using micro-transactions to test the waters. Platforms need dynamic, context-aware monitoring that flags anomalous behavioral patterns, even if individual transaction values fall below predefined limits.
  3. Automate Incident Response: The 41-minute window in which attackers swapped all stablecoins demonstrates that manual intervention is too slow. Exchanges must deploy automated circuit breakers and AI-driven tracing tools to identify and freeze illicit flows in real-time.

Closing Takeaway

The Bitget hack is a stark reminder that the security perimeter of centralized exchanges extends far beyond cold storage. As threat actors increasingly rely on zero-day exploits, credential theft, and decentralized cross-chain protocols to launder funds, the defensive posture of the industry must evolve accordingly. From an on-chain security and investigation perspective, firms like ChainSentinel emphasize that automated, AI-driven tracing is no longer a luxury but a baseline requirement for modern exchange operations. Ultimately, surviving these sophisticated breaches will depend on how quickly platforms can detect anomalies, shut down compromised trust chains, and collaborate with forensic analysts to track funds across an increasingly fragmented multi-chain landscape.

Sources: Security-firm advisories, blockchain analytics reports, and crypto media.

Top comments (0)