Skip to main content

Crypto: how hackers stole 387 million from Bitget without stealing a single key?


Well then, my friends, this week's heist is a bit of a special one: the pirates didn't force the safe, they didn't even steal the key to the safe, they simply slipped a fake check into the pile, and it was the bank itself that signed it. Total bill: $387.5 million.

The bank in question is Bitget, one of the big cryptocurrency exchanges, where millions of people buy and sell bitcoin or other cryptocurrencies. And the most interesting thing isn't the amount. It's how they did it.

A closed and intact safe door, and in the foreground an open and empty cash drawer

The safe held. The cash drawer, not so much

Nineteen transfers on a Thursday evening

Thursday, September 24, at 8:31 p.m. Brussels time, Bitget's security systems detected transfers that no employee had requested. Nineteen in total, to addresses belonging to the pirates. Ether, XRP, Avalanche, BNB and digital dollars (USDT and USDC, tokens supposedly always worth one dollar), scattered across five different networks.

The first figure announced by Bitget's boss, Gracy Chen, was $351.6 million. The next day, after a full recount, it rose to $387.5 million. Bitget says this wasn't a second theft: the first calculation had simply forgotten two networks. Well, a $36 million difference, we're past worrying about that, it's a disaster anyway!

Chart: $351.6 million announced, $387.5 million recounted, protection fund of more than $464 million

The emergency fund covers the shortfall. If it pays for everything, less than a quarter of it remains

It's the biggest hack of a cryptocurrency exchange in 2026. With it, September passes $684 million stolen worldwide in the crypto world, according to CryptoSlate's tally. The most expensive month of the year, and it's not even over.

Hot, warm, cold: how a platform stores your money

To understand what was affected, you need to know how a platform stores its customers' money. Imagine a supermarket.

The cash register is the “hot” wallet: it's connected to the Internet all the time, because it is used to pay out the day's withdrawals. It contains only a small part of the money, precisely because it's exposed. The little office safe is the “warm” wallet: a reserve used to refill the cash register. And the vault in the basement is the “cold” wallet: it never touches the Internet, and that's where most of the money sleeps.

Diagram of a platform's three wallets: the hot wallet, online for the day's withdrawals, and the warm wallet, the reserve, affected on September 24; the cold wallet, offline, the vault, untouched

Three floors, and the pirates stayed on the first two

At Bitget, the cash register and the little safe were partly emptied. The vault didn't move. That's exactly why things are stored this way, and that's why Bitget can say that most of its customers' assets were not affected.

No key stolen: Bitget itself signed

To get money out of a crypto wallet, you need a digital signature, made with a secret key. For years, the catastrophe scenario was the theft of that key. This time, Gracy Chen is categorical: the keys were not stolen.

What happened, according to her message of September 25, is that the pirates got into an internal computer that prepares transfers (hmmm... this still smells like a leak by a former employee, though). From there, they created fake transaction data, and they triggered Bitget's own authorization process. The signing system saw orders that looked normal, and it signed them. The withdrawal slip was fake, the stamp was real.

A gloved hand slips a fake transfer order into a pile while an employee stamps it

The stamp is authentic, it's the sheet that isn't

And this isn't new. In February 2025, the Bybit platform had 1.5 billion dollars stolen with a trick of the same kind: those in charge had approved a transaction that looked perfectly normal on their screen, while underneath it had been tampered with. Elliptic, the analysis firm, also found part of Bitget's money on addresses already linked to the Bybit theft.

The lesson is the same as in my article yesterday about Ledger keys : the weak link is no longer the key, it's the screen showing you what you're about to sign. If the screen lies, the finest signature in the world is useless. Investigators from Mandiant and SlowMist, two specialized firms, are now looking for how the hackers got in, including through a tool from an outside supplier. We're still waiting for the full report.

What if you had crypto at Bitget?

The good news is that Bitget says it will cover the entire loss with its user protection fund, a pot of more than 464 million dollars set aside for this kind of bad blow. Deposits and trading continued. Withdrawals, meanwhile, were suspended : Bitget was due to announce its recovery plan this Saturday at 6 a.m., Brussels time, and Gracy Chen assured everyone that it "shouldn't take weeks".

As for the treasure hunt, Bitget is offering 5% of whatever is recovered to anyone who helps freeze or find the funds. Circle and Tether, the issuers of the stolen digital dollars, blocked one of the hackers' addresses, meaning about 318,000 dollars frozen. Out of 387 million, that's a drop in the ocean. Some of the rest is already flowing towards Tornado Cash, a service that mixes the funds of thousands of users so that their trail can no longer be followed.

And for a Belgian reader, there's one detail that matters. Bitget does not have European MiCA approval, the licence required since July 1, 2026 by the European regulation on crypto to serve customers in the Union : its application is pending in Austria, and in the meantime the platform has closed its services in several countries, including France at the end of March. But at an approved platform, reimbursing a customer after a hack for which it is responsible is not a commercial gesture, it's an obligation written into the text (Article 75 of MiCA). At Bitget, the emergency fund is the company's promise. It's keeping it this time, which is good, but it's the company that decides. I also went into detail last month about who really protects you when a platform holds your tokens.

In practice, what I take away for myself comes down to two things. One : a platform is the store's cash register, not your vault. What you buy or sell can stay there, what you plan to keep for years has no business being there, and a wallet that you control yourself, on your phone or in a device, doesn't depend on the office next door of a company on the other side of the world. Two : before opening an account, you take two minutes to check that the platform appears in the European register of MiCA-approved providers, maintained by ESMA, the European financial markets watchdog. That won't stop it from being hacked, but it decides who pays when it happens.

Personally, what strikes me is the trajectory : we hardened the keys, put the vault offline, and the hackers came through the office next door, the one where the paperwork is prepared. Today, the 464 million pot was enough, but it must hurt, hoping that this won't have other consequences for Bitget's long-term survival (or for its employees).

Sources

Article written with the help of Claude Code, reread and corrected by me.

Join the conversation

You need an account to comment on this article. Creating one is free and takes under a minute.

  • The XMLTV file, free to download every day
  • Comment on articles and reply to other readers
  • Get an e-mail when an article you follow is updated

No comments yet.

Une erreur s'est produite. Cette application peut ne plus répondre jusqu'à ce qu'elle soit rechargée.Veuillez contacter l'auteur. Reload 🗙