How Bitget's $351.6 million hack unfolded
Bitget says attackers compromised its wallet backend. YFarmX traces about $350.66 million in receipts and finds a failed XRP withdrawal sized against an earlier balance.

Update: 02:54 UTC (25 Sept)
ETH from the three tracked Bridgers payout addresses has been pooled in 0x00154b…411A7. The wallet held 25.98 ETH (about $69,930) at the cutoff after five deposits from five addresses; the three previously tracked payout wallets had emptied. The five deposits arrived between 02:34 and 02:37 UTC: 1, 2, 3, 4, 5.
On Optimism, 495.625 WETH (about $1.33 million) moved from the tracked wallet at 02:29 UTC, then onward at 02:49 UTC through a wallet with delegated code.
Nine larger Ethereum wallets held 67,980.39 ETH (about $182.98 million); the main BNB position held 5,896.58 BNB (about $4.60 million), and four XRP accounts held 82.98 million XRP (about $128.42 million). The XRP figure covers those four accounts. Balances are a snapshot at 02:54 UTC on 25 September 2026. Dollar estimates use the earlier Chainlink references in our evidence index: ETH and BNB at 23:35 UTC on 24 September, XRP at 00:05 UTC on 25 September.
Update: 03:39 UTC (25 Sept)
The tracked Optimism funds crossed to Ethereum through Circle's CCTP. At 02:55:13 UTC, 1,300,000 USDC (about $1.3 million at its dollar peg) was burned on Optimism. At 02:55:23 UTC, ten seconds later, the Ethereum transaction minted 1,299,812.601649 USDC to 0x2b0347…84ecd8, with 187.398351 USDC in fees. These USDC quantities are approximately the same amounts in dollars at the peg.
The bridge transfer was complete by the 03:39 UTC cutoff. CCTP burns USDC on the source chain and mints it on the destination after an attested message is submitted. Both transaction receipts confirm this transfer completed.
Update: 04:22 UTC (25 Sept)
The Optimism funds that crossed through Circle's CCTP continued moving on Ethereum. At 03:02 UTC, the recipient swapped its 1,299,812.601649 USDC for 483.6100066 ETH (about $1.30 million at our earlier ETH quote). It sent 483.7463 ETH to 0x94A43… at 03:05, which sent 484.6482 ETH to 0xA6dD… at 03:08. The differences reflect ETH already in those wallets.
At 03:45:47 UTC, 0xA6dD sent 484.65 ETH (about $1.30 million) to 0x52f08…25d284. That wallet held 3,698.10 ETH (about $9.95 million) at Ethereum block 26,052,050, timestamped 04:22:35 UTC. The dollar illustrations use the earlier $2,691.70 ETH/USD reference in our evidence index. This is an onward movement of the CCTP proceeds, excluded from the original theft count.
Update: 05:55 UTC (25 Sept)
The BNB trail now leads towards Bitcoin. Between 05:36 and 05:48 UTC, five successful deposits into THORChain, a cross-chain swap service, totalled 1,386.003 BNB (about $1.07 million). Their payment instructions name four Bitcoin addresses. The deposits were 416.023 BNB, 320 BNB, 50 BNB, 320 BNB and 279.98 BNB.
One of the 320 BNB swaps names 13RcS1N99wQeD6WvjWqS1L6CwheEKBVC7T, the same Bitcoin address used in the earlier ETH conversion. At 04:18 UTC, 28.24 ETH (about $75,700) entered THORChain with instructions to pay that address. A Bitcoin transaction confirmed at 05:23 UTC paid it 0.89194679 BTC (about $75,200). Its on-chain memo contains the full Ethereum deposit hash, tying that payout to the ETH conversion.
The shared destination connects the ETH conversion and a BNB swap instruction. The five BNB deposits establish requested Bitcoin payouts; completion is checked separately against Bitcoin receipts. Dollar estimates use the trace's dated Chainlink quotes: BNB $771.587 at 03:18 UTC, ETH $2,679.58 at 04:51 UTC and BTC $84,264.73 at 04:47 UTC.
Update: 08:53 UTC (25 Sept)
The BNB conversion has accelerated. The trace now identifies 29 successful THORChain deposits between 05:36 and 08:12 UTC, with instructions to pay 11 Bitcoin addresses. Their gross total is 8,496.95589 BNB (about $6.56 million), including refunded funds deposited again. The original tracked BNB holding was about 5,896.58 BNB ($4.55 million at the same historical quote). Counting each repeated deposit as fresh stolen funds would overstate the amount.
By the 08:53 UTC cutoff, 48.74418538 BTC (about $4.12 million) had arrived in Bitcoin transactions whose OUT: memos name deposits in our trace. This cumulative figure covers the BNB swaps and the earlier ETH conversion. The matched receipt list counts each Bitcoin transaction once, using only outputs paid to the identified destination addresses.
The address bc1qdphrvtvt43nlc26vd4srumdu5u50x6xhx23qu5 appears directly in three traced swap instructions. It also receives onward Bitcoin transfers. That establishes its role as a chosen payout and collection destination; identifying its operator requires further evidence.
The investigation's 08:53 snapshot reports the separate holdings of 68,465 ETH and 102.6 million XRP unchanged, valued together at about $341.8 million. These are dated observations. Valuations use the trace's Chainlink quotes: BNB $771.587 at 03:18 UTC, BTC $84,446.46 at 08:28 UTC, ETH $2,685.17 at 08:21 UTC and XRP $1.5395 at 08:53 UTC.
Bitget, the cryptocurrency exchange, says an attacker compromised part of its wallet infrastructure on 24 September 2026, affecting approximately $351.6 million in assets. Our reconstruction identifies receipts worth about $350.66 million, spread across six Ethereum-compatible networks and the XRP Ledger.
Bitget’s Protection Fund accepts eligible claims for compromised accounts or stolen assets, subject to the exchange’s investigation. The official page sets out the fund’s holdings and claim conditions.
The XRP transfers explain most of the difference between early estimates around $192 million and Bitget’s much larger assessment. They also expose a useful clue: a failed withdrawal requested more XRP than its source wallet held, using an amount that matches an earlier balance.
This is a developing post-incident analysis. Bitget’s explanation of the intrusion is preliminary; the transaction amounts and outcomes below can be checked against the ledger. Our Bitget exploit-tracker record collects the incident figure and key transaction links.
The XRP transfers bring the measured total to $350.66 million
Our selected incident receipts comprise 16 transfers across Ethereum, Arbitrum, Avalanche, Base, BNB Chain and Optimism, plus three successful XRP payments. We count original receipts once, then follow their subsequent movements separately.
| Measured original receipts | Historical value |
|---|---|
| Six Ethereum-compatible networks | $192,611,911.60 |
| 102,976,680.091945 XRP | $158,051,512.55 |
| Combined measured receipts | $350,663,424.15 |
| Bitget’s preliminary incident assessment | Approximately $351.6 million |
The dollar reconstruction uses a 24 September, 21:39:35 UTC reference time, including XRP at $1.53482820. The calculation preserves the earlier basket’s gold-price proxy for XAUT and USDT-price proxy for USDT0. These are valuation assumptions; the underlying token quantities are separate ledger measurements. The calculation and evidence index records the inputs and verification scope.
Bitget’s figure is broadly consistent with this reconstruction. Exact cryptocurrency quantities can be established for the transactions examined; a dollar total also depends on pricing time and incident scope. The selected EVM basket includes an initial 0.84 ETH funding payment whose classification as stolen funds remains provisional.
Bitget says the attacker manipulated its authorisation process
Bitget chief executive Gracy Chen said at 00:43:40 UTC on 25 September that the attacker compromised a critical backend system in the exchange’s wallet infrastructure, spoofed transaction data and triggered its authorisation process. She said private-key compromise had been ruled out and that the initial intrusion method remained under investigation. These are Bitget’s findings, pending its promised technical report.
A wallet backend prepares and routes payment requests. A signer uses a private key to approve the resulting transaction. If a compromised system can persuade that signer to approve an attacker’s destination, the blockchain receives a valid signature on a malicious payment.
The original transfers we examined were authorised by their source accounts. On the Ethereum-compatible chains, the selected set contains 11 native-asset transfers and five direct token transfers. The XRP payments carry signatures and the source accounts’ public signing keys. This establishes that the relevant signing authority was used. A public transaction alone cannot determine whether someone copied a key or caused an existing signing system to use it.
A failed 9.14 million XRP payment exposes an older balance
The account labelled Bitget 2 held 101,578,825.284121 XRP immediately before its large withdrawal on 24 September. At 19:16:20 UTC, it sent 91.42 million XRP, or 90% of that balance, to the attacker’s recipient account. About 10.16 million XRP remained. At 19:28:02, 2 million XRP moved from Bitget 2 to Bitget 1, another exchange-labelled account, leaving about 8.16 million XRP in Bitget 2.
An hour later, at 20:28:20, Bitget 2 attempted another payment to the attacker, this time for 9.14 million XRP. It had only 8.16 million XRP available, so the ledger rejected the payment with tecUNFUNDED_PAYMENT. The attacker received zero XRP from this attempt; the source wallet paid a 0.000020 XRP transaction fee.
The failed request was sized as though the earlier 10.16 million XRP balance still applied. Its exact amount, 9,142,093.8 XRP, equals 90% of the earlier balance after rounding that balance down to whole XRP. The intervening 2 million XRP transfer explains why the wallet could no longer cover that request.
We found this attempt by examining the sender’s history. It was absent from the recipient history previously collected because its recorded changes concerned the sender’s fee and transaction sequence. XRPL’s transaction-result documentation explains how a failed transaction can still consume a fee.
This is evidence consistent with a payment amount being calculated from stale balance information. It leaves several possible explanations, including an automated process, a queued request or a human choosing the amount.
More XRP arrived, then another withdrawal succeeded
At 20:40:02 UTC, Bitget 1 sent 2,183,079.516298 XRP into Bitget 2. Added to the roughly 8.16 million XRP already there, this brought Bitget 2’s balance to about 10.34 million XRP.
At 21:19:21, Bitget 2 successfully sent 9,306,865.8 XRP to the attacker. That was 90% of its total replenished balance, after rounding the balance down to whole XRP. That total included the existing funds and new XRP.
| Time on 24 September, UTC | What happened | Bitget 2 balance afterwards, rounded |
|---|---|---|
| 19:01:32 | First successful attacker payment: 2.25 million XRP leaves Bitget 1 | Separate wallet |
| 19:16:20 | Second successful attacker payment: 91.42 million XRP leaves Bitget 2 | 10.16 million XRP |
| 19:28:02 | Internal transfer: 2 million XRP moves from Bitget 2 to Bitget 1 | 8.16 million XRP |
| 20:28:20 | Failed attempt: requests 9.14 million XRP; delivers zero | 8.16 million XRP, less the fee |
| 20:40:02 | Internal transfer: 2.18 million XRP moves from Bitget 1 into Bitget 2 | 10.34 million XRP |
| 21:19:21 | Third successful attacker payment: 9.31 million XRP leaves Bitget 2 | 1.03 million XRP |
The three successful payments total 102.98 million XRP. The first two account for 93.67 million XRP; the later 9.31 million XRP payment brings the exact total to 102,976,680.091945 XRP, valued at $158.05 million using the price stated above. The 2.18 million XRP replenishment came from Bitget 1. Both internal transfers stayed between exchange-labelled wallets.
The replenishment transaction proves a transfer between exchange-labelled accounts. Its purpose and the process that initiated it require internal evidence. The exploit-tracker entry links the failed and successful transactions for comparison.
A separate first payment of 2,248,871.536237 XRP also matches 90% of an older balance, with rounding to XRP’s smallest unit. That balance existed approximately 26 to 29 minutes before the payment. We compared 85 preceding records from that source across two public XRP servers, alongside eight records covering the second source’s attack window. Both servers returned matching transaction and metadata records.
The settings also resemble earlier exchange payments. A bounded pre-attack sample contains ten outgoing transfers with the same signing public key, fee, destination tag and ledger-expiry spacing as the four examined outgoing transactions during the incident window. Those public settings can be copied. Their investigative value is in identifying the corresponding requests and signing records inside Bitget.
A 286 ETH bridge transfer connects two parts of the same trail
One apparent outside connection resolves into a transfer between chains. The secondary wallet, 0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C, swapped 1,000 BNB, then used Across to send the proceeds to the same address on Ethereum. The destination received 286.005857909746987778 ETH just 29 seconds after the source transaction.
Following the bridge’s deposit and receipt connects this payment to the Bitget-funded branch. Swaps and public bridge services describe the route; attribution to a person or group requires additional evidence.
The earliest verified Ethereum funding of the principal recipient is 0.84 ETH from an account labelled Bitget 6, at 18:31:11 UTC. A subsequent 0.1 ETH payment links it to the secondary wallet. This establishes funding within the exchange-associated trail. It gives investigators no independently identified outside sponsor.
The dated snapshots locate about $348.30 million
Our holdings snapshots locate approximately $348.30 million across the traced accounts. The EVM observations span 23:35:11 to 23:44:09 UTC on 24 September; the XRP snapshot is pinned to the ledger that closed at 00:05:42 UTC on 25 September. Readers should use those dates when describing where the assets were held.
| Traced holdings | Value at the recorded snapshot |
|---|---|
| Ethereum-compatible chains | $188,921,695.59 |
| Eight XRP accounts | $159,373,514.81 |
| Combined, at the separate cutoffs above | $348,295,210.40 |
The Ethereum holdings include six addresses with roughly 10,000 ETH each. On XRP, eight accounts held 102,976,680.092071 XRP in total. That reconciles to the original XRP receipts plus 0.000270 XRP of incidental receipts and minus 0.000144 XRP of fees. The examined XRP history contains no successful outgoing payment beyond those eight accounts by that cutoff.
Located assets remain distinct from recovered assets. Likewise, differences between original receipt values and later holdings values include changes in prices and asset composition. Our tracker record separates holdings from recoveries; the evidence index supplies the full XRP account list and EVM snapshot references.
33,500 XRP moved through a swap service
After the holdings snapshot above, 12 payments totalling 33,500 XRP reached rM27yzkCw6WA3T4g1sPaeC1kpxHUhuxRWn between 00:24:20 and 01:02:01 UTC on 25 September. Their transaction memos name Bridgers and specify three Ethereum destinations. Ripple’s public server confirms the successful deposits; the funding path connects the sending accounts to the earlier XRP recipients.
The three named Ethereum addresses received 19.003612 ETH in 12 payments from 0xc1d13492285eb664951E201BF7C80c7c6318a1b5, identified by Blockscout as SwftSwap. We checked the explorer’s internal-transfer records against a public Ethereum node: all 12 transaction receipts succeeded and their emitted payout amounts agree.
| Ethereum destination | XRP deposits naming it | Observed ETH payouts |
|---|---|---|
0xA077…76feb |
3,000 XRP | 1.704496 ETH |
0xC15c…252c7 |
20,000 XRP | 11.358530 ETH |
0xe9Ae…b11Ec |
10,500 XRP | 5.940586 ETH |
The last 1.979558 ETH arrived at 01:08:23 UTC, taking the payout total beyond the 17.024054 ETH observed by 01:07. The records establish a cross-chain conversion route. Whether a recipient subsequently sold assets for fiat, or whether these payments were a rehearsal, requires further evidence. The service deposits also change the route without making the historical holdings table a current balance report.
Bitget’s logs can explain how those requests were approved
The next decisive evidence is the exchange’s own sequence of balance reads, withdrawal requests and signing approvals. Investigators can search for the exact older balance 2,498,746.151375 XRP, the failed 9,142,093.8 XRP request, and the later successful request after funds arrived.
Those records can show which system supplied the destination, when each amount was calculated, and which authorisation checks accepted it. They would turn the observed payment pattern into a tested explanation of the breach. Bitget has promised a technical report; the ledger already gives that report specific transactions to account for.
Sources
- Gracy Chen: preliminary incident amount, 24 Septemberx.com
- Gracy Chen: wallet backend findings, 25 Septemberx.com
- XRP Ledger: 91.42 million XRP paymentlivenet.xrpl.org
- XRP Ledger: failed paymentlivenet.xrpl.org
- XRP Ledger: successful later paymentlivenet.xrpl.org
- XRP Ledger documentation: tec transaction resultsxrpl.org


