Hot Wallets Emptied Across Eight Chains in Under Minutes
Bitget's security systems flagged unauthorised transfers at 18:31 UTC on 24 September 2026. By the time the alert resolved into a full picture, $387.5 million had left the exchange's hot wallets in what analysis suggests was a backend infrastructure attack — one that spoofed on-chain transactions using signing settings Bitget's own customer withdrawals never employ.
The mechanics set this apart from a conventional key compromise. Funds moved in two concentrated bursts, hitting five chains within seconds of each other, with the transactions bearing the exchange's own wallet signatures. Attribution points to North Korea's Lazarus Group, though the exchange has not publicly confirmed that framing. What is confirmed: the drain spread across eight blockchains, touching BTC, ETH, XRP, ZEC, and TRX among the affected assets.
Bitget moved to suspend withdrawals after the attack was detected, while keeping deposits and trading available — a containment posture designed to prevent a secondary run on balances. The exchange says its User Protection Fund is sufficient to cover the entire loss, and that affected users will be made whole. How quickly that coverage reaches users will be the operational question traders watch.
For centralised exchange tokens and the broader CEX sector, the episode reinforces a pattern: hot wallet infrastructure, not smart contracts or bridges, has become the dominant loss vector in large-scale exchange attacks. Confidence in centralised venue balances tends to cool after events of this scale, and the reaction across exchange-native tokens reflects that pressure.
THORChain Declines to Block Attacker Addresses
In the days following the attack, Bitget asked THORChain to blacklist addresses tied to the theft after a portion of the stolen funds began moving into bitcoin through the permissionless swap venue. THORChain declined. According to reports, a significant number of successful swaps moved a meaningful volume of ETH into BTC through the protocol. The refusal keeps censorship-resistant DEX infrastructure in the regulatory crosshairs and adds an overhang to RUNE specifically, as the episode illustrates the tension regulators have long flagged around permissionless venues processing funds linked to major thefts.
Coverage Timeline and Withdrawal Resumption Are the Next Triggers
With withdrawals still suspended, the immediate catalyst to watch is any Bitget announcement on when normal operations resume and how the User Protection Fund disbursement will be structured. A clear timeline could stabilise sentiment around the exchange; a prolonged suspension may deepen pressure on centralised exchange tokens more broadly. The THORChain situation may also draw regulatory comment — any formal action against permissionless swap venues could weigh on RUNE and similar assets.
Risk Factors
- Withdrawal suspension creates liquidity risk for traders holding balances on Bitget; timeline for resumption is unconfirmed.
- The $464 million User Protection Fund covers the loss by a narrow margin — any additional claims or fund shortfall could alter the coverage picture.
- Attribution to Lazarus Group, if confirmed by external parties, may trigger regulatory scrutiny of exchanges and their hot wallet practices sector-wide.
- Ongoing movement of stolen funds through permissionless venues keeps headline risk elevated for DEX tokens and could accelerate regulatory action against censorship-resistant swap infrastructure.
This article does not constitute financial advice. It is intended for informational purposes only. Trading cryptocurrencies involves significant risk of loss.
This article was generated with AI assistance and may contain errors.
TiMi IA