Bitget Loses $387.5M After Backend Authorization Breach
A crypto exchange’s vault was not directly broken — its authorization machinery was turned against itself.

W3 Meteor ID: BITGET-927202632108
Date & Time: September 24, 2026, 18:31 UTC
Origin: Bitget’s exchange wallet infrastructure; an attacker compromised a critical backend component, spoofed transaction data, and used the exchange’s authorization process to move assets from affected hot wallets.
Visibility: Bitget users, centralized exchanges
Trajectory: The incident began with unauthorized transfers detected from Bitget’s hot wallets. The exchange initially estimated $351.6 million affected, then raised the figure to about $387.5 million after tracing additional Zcash and TRON assets.
Direction: The breach shifts attention from private-key theft toward the systems that decide whether a transaction deserves to be signed. If that layer becomes compromised, even strong custody architecture can be bypassed without directly breaking the vault.
Speed: The event moved rapidly from detection to withdrawal suspension and onchain tracing, while Bitget brought in Mandiant and SlowMist and launched a recovery-bounty program. The underlying vulnerability has since been identified and remediated, with withdrawal restoration dependent on further security validation.
Magnitude: At approximately $387.5 million, the incident is large enough to test Bitget’s protection architecture and the broader assumption that separating hot and cold wallets alone defines institutional security. Bitget says its cold wallets and separate self-custodial Bitget Wallet were unaffected.
Altitude: The consequences reach beyond Bitget: centralized exchanges, custodians, wallet providers and DeFi infrastructure may increasingly have to treat backend authorization logic as part of the core security perimeter, not merely as supporting software.
Cock-a-Doodle-Doo: The interesting breach was not necessarily the vault — it was the permission to open it. Crypto spent years teaching us to protect private keys; the next security lesson may be learning to protect the systems that decide when those keys should act.
