BITGET HACK: THE FULL ON-CHAIN TIMELINE OF A $351.6M BREACH
At 18:31:11 UTC on September 24, a wallet labeled "Bitget 6" sends 0.84 $ETH to an address created that same day. Small, forgettable amount. That's the tell. It's a test transaction, the move that precedes a real drain, and it lands in the exact same minute Bitget's own systems flag the intrusion.
The real money follows fast.
18:58:59 UTC — "Bitget 6" sends 34,751,168 USDT
19:01:20 UTC — on Arbitrum, 19,668,851 USDT0 goes out
19:01:23 UTC — 12,852,046 USDC follows
19:01:35 UTC — 7,130.86 ETH
A second wallet, "Bitget 35," adds another 15,362 ETH across three more transfers. A final 223.2 ETH moves at 21:23:11, two hours and 52 minutes after detection, seven minutes before Bitget's public notice goes out.
Across just Ethereum and Arbitrum, $188.4 million left Bitget-labeled wallets. Add 3,000 Tether Gold tokens, $12.8 million more, from a third address.
https://arbiscan.io/tx/0xd032320ad8a3cddc61ec0db5e6e26a6dcf813243a77b7edc5a65451ade0b84e3
Here's where the attacker's discipline shows. A newly created wallet, 0xe410...d946, takes 19.67 million USDT0 and converts it into 7,111 ETH on Arbitrum. Six minutes. Routed through UniswapX and 1inch Fusion. Paying up to 5% above spot price, which briefly pushed the WETH/USDC pool to $2,870 against a real spot price near $2,688.
Pseudonymous analyst DCF GOD, who caught the Arbitrum leg before Bitget said a word publicly, put it simply: paying that much over spot "makes no sense if someone was just trying to buy eth."
It makes complete sense if you're racing a freeze function. USDT and USDC can both be frozen at the contract level by their issuers. ETH can't. Every stablecoin this attacker touched got converted to ETH within minutes, overpaying without hesitation, because being fast mattered more than getting a good price.
Total affected, per Bitget CEO Gracy Chen: $351.6 million, across three hot wallets and one cold wallet. On-chain analysts' independently visible tally sits lower, around $180-192 million, the gap being funds routed in ways not yet fully mapped publicly. Assets taken span ETH, AVAX, BNB, USDC, USDT, USDT0, and XAUT.
What didn't happen: user balances weren't rewritten, cold wallet reserves stayed secure, and the compromised wallets still held roughly $530 million after the attack, meaning this could have been considerably worse.
Chen's response, on record: "User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million. Every dollar and every decision will be accounted for, transparently and in full."
On attribution, Chen pointed toward North Korea's Lazarus Group, noting she'd personally dealt with the group before, an $80,000 theft from one of her own wallets outside Bitget. The stablecoin-to-ETH laundering pattern matches Lazarus's playbook from the Bybit hack in February 2025, where the group took $1.4-1.5 billion, still the largest crypto exchange hack ever. Bybit recovered within 72 hours using bridge loans and stayed a top-five exchange by volume through 2026. Bitget's loss is a quarter of that scale.
What's still unknown: the actual entry vector. Hot wallet compromise, private key theft, insider access, nothing's been disclosed yet. Bitget has promised a full incident report, including root cause, before 21:30 UTC on September 25.
This pushes September 2026's total crypto hack losses above $684 million, already surpassing April's $646.9 million, making this the costliest month for exchange hacks so far this year.
$BGB fell about 5% on the news. Withdrawals stay frozen until the security review completes. Deposits and trading remain open.






