· via dev.to (home feed)
Zero-day exploit and stolen admin credentials drained $387.5M from Bitget, analysis finds
Bitget lost $387.5M after attackers chained a third-party zero-day with stolen admin credentials, then laundered funds through THORChain; only 0.2% was frozen.

Crypto exchange Bitget lost roughly $387.5 million in a breach on September 24, 2026, according to a detailed technical analysis published on dev.to. The attackers never touched the exchange's private keys or cold wallets. Instead, they chained a zero-day flaw in a third-party security product with stolen, highly privileged internal credentials to inject fraudulent withdrawal instructions straight into Bitget's wallet backend.
A three-hour window
According to the dev.to timeline, the intrusion opened at 18:31 UTC with small unauthorized test transfers of ETH and TRX. The amounts were deliberately kept below Bitget's automated risk-control thresholds, so nothing tripped an alert. After confirming the path worked, the attacker escalated: between 18:58 and 20:09 UTC, seventeen large withdrawals moved funds across nine networks, including Ethereum, TRON, XRP, BNB Chain, Base, Arbitrum, Optimism, Avalanche and Zcash.
Bitget's reconciliation system flagged a discrepancy at 19:05 UTC and halted user-initiated withdrawals, but the attacker kept feeding forged commands into the wallet backend. The final fraudulent transfer landed at 21:23 UTC, and signing machines were fully shut down at 21:44 UTC, well over two hours after the first internal alert. An initial loss estimate of $351.6 million was later revised to $387.5 million once Zcash and TRON transactions were fully accounted for.
The signing chain, not the keys
The analysis stresses that the transaction-signing trust chain was the real target. Because the injected commands appeared to originate from legitimate internal infrastructure, they bypassed standard risk checks. To slow down responders, the attackers systematically deleted logs and traces of the forged commands after each transfer.
Laundering at machine speed
The stolen portfolio included about $75.48 million in stablecoins, namely USDT, USDC and USDT0, plus 3,000 XAUt, a gold-backed token. Knowing that centralized issuers could freeze those assets, the attackers swapped every stablecoin into native tokens such as ETH and AVAX within 41 minutes of the initial theft.
Cross-chain liquidity protocols then obscured the trail. Roughly $269 million was routed through THORChain and consolidated into Bitcoin, while about $37.27 million moved via Chainflip. Once converted to Bitcoin, CoinJoin transactions mixed the coins to break the on-chain link between inputs and outputs.
Freezes barely dented the haul. Publicly visible immobilizations totaled around $840,000, or about 0.2% of the stolen sum: Tether and Circle froze roughly $340,000 in stablecoins left dormant on attacker addresses, and NEAR Intents intercepted about $503,000 mid-execution. The loss was absorbed by Bitget's User Protection Fund, valued at about $465 million at the time, and the exchange committed to topping the fund back up to at least $300 million within a week using corporate reserves exceeding $1.4 billion.
AI compressed the investigation
The speed of the laundering forced an equally fast response. Per the analysis, investigators used in-house artificial intelligence and agentic AI platforms to interrogate on-chain data and match deposits to corresponding payouts across fragmented protocols. That compressed what the write-up describes as more than 20 hours of manual bridge reconciliation into under 10 minutes, while human investigators still defined the logic, reviewed outputs and directed strategy.
Why it matters
The breach reframes the attack surface of centralized exchanges. Cold storage and key custody were not the weak point here; the signing infrastructure was, because commands from seemingly legitimate internal systems were trusted by default. The 41-minute stablecoin conversion shows that manual intervention cannot keep pace with automated laundering, which is why the analysis argues for dynamic, context-aware risk thresholds that catch behavioral anomalies rather than static limits that micro-transactions can safely probe, alongside automated circuit breakers and AI-driven tracing. It is worth noting that the figures in this account come from a single detailed write-up on dev.to, which itself cites security-firm advisories, blockchain analytics reports and crypto media, so independent confirmations of the exact numbers may still differ.
- #crypto
- #security
- #zero-day
- #exchanges
- #thorchain