YFarmX logoYFarmX

Tools Crypto Exploit Tracker exploit-0140

Exploit record

Bitget reports $351.6 million affected in wallet backend breach

Loss
$352M
Attack vector
Wallet backend compromise (preliminary)
Chain
Multichain
Sector
Centralised Exchange

What happened

Bitget reports approximately $351.6 million affected after unauthorised hot-wallet transfers on 24 September 2026. On 25 September, CEO Gracy Chen said a compromised wallet backend manipulated transaction data and triggered authorisation; the initial intrusion remains under investigation.

The loss field uses Bitget's preliminary assessment. YFarmX measured 16 original receipts on six Ethereum-compatible chains plus three XRP receipts totalling 102,976,680.091945 XRP: about $350.66 million at the 24 September 21:39:35 UTC valuation reference. The selected basket includes a provisionally classified 0.84 ETH funding payment. A failed 9,142,093.8 XRP request delivered zero, followed by a successful 9,306,865.8 XRP payment after replenishment. Dated holdings snapshots locate about $348.30 million, combining EVM observations at 23:35–23:44 UTC on 24 September with XRP at 00:05:42 UTC on 25 September. Located holdings are distinct from recoveries. Chen says private-key compromise was ruled out; that conclusion requires company-side evidence. Actor attribution remains unresolved. Later, 12 XRP payments totalling 33,500 XRP named three Ethereum destinations in Bridgers memos. Those destinations received 19.003612 ETH from the SwftSwap-labelled contract by 01:08:23 UTC on 25 September. This establishes a conversion route; fiat cash-out and rehearsal intent remain unproven.

On-chain references

Sources

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 25 September 2026