How Backend Spoofing Took $351M From Bitget’s Liquidity Layer

In September 2026, Bitget lost $351.6 million out of its hot wallets in a transaction spoofing attack that strikingly echoed Bybit’s $1.5 billion cold wallet heist nineteen months earlier, the largest crypto heist ever recorded.

I’ve read through a lot of exchange hack post-mortems over the past two years, and most of them read the same: detection, containment, reassurance, investigation pending. What makes this one worth slowing down on isn’t just the dollar figure, it’s how closely the attacker’s method echoes the exact playbook that took down Bybit, and how differently the two exchanges’ wallet architecture handled it.

What Happened To Bitget’s Hot Wallets

At 18:31 UTC on September 24, Bitget’s security systems flagged unauthorized transfers moving out of some of its hot wallets. The exchange’s own incident update laid out the mechanics as far as the investigation has confirmed them: an attacker compromised a critical backend system inside Bitget’s wallet infrastructure, used it to spoof transaction data, and triggered the exchange’s own authorization process into moving funds out.

How Backend Spoofing Took $351M From Bitget’s Liquidity Layer

Bitget was explicit that this was not a private key compromise, a distinction the team said ruled out the more severe categories of risk.

Where The Stolen $351.6 Million Actually Went

On-chain analysts at Lookonchain tracked the stolen assets in real time, and the breakdown is worth sitting with: 102.93 million XRP ($157.48 million), 31,890 ETH ($85.75 million), 34.75 million USDT, 21.05 million USDC, 19.67 million USD₮0, 3,000 XAUt ($12.82 million), 12,719 BNB, 821,012 AVAX, and 20.59 million TRX.

How Backend Spoofing Took $351M From Bitget’s Liquidity Layer

Within hours, the attacker had already converted most of the EVM-chain holdings into 67,982 ETH, worth roughly $183 million, a laundering step that mirrors almost every major exchange hack of the last three years, where stolen assets get consolidated into ETH before moving toward mixers or cross-chain bridges.

How Bitget Says It Plans To Make Users Whole

Bitget’s response leaned heavily on its wallet architecture holding up where it mattered most. The exchange operates a three-tier system, cold, warm, and hot and said the breach was contained to a portion of the warm and hot layers, with cold wallets, which hold the majority of reserves, untouched.

Withdrawals were paused as a precaution while deposits and trading kept running, and the exchange said the full loss falls within its User Protection Fund, which it states currently holds more than $464 million, enough to cover the incident outright without touching customer balances. Whether that fund performs as described once withdrawals resume is the part that will actually validate the promise.

How Backend Spoofing Took $351M From Bitget’s Liquidity Layer

The Bybit Parallel Nobody Can Ignore

Here’s where I think the comparison gets genuinely interesting rather than just convenient. Bybit’s $1.5 billion loss in February 2025 didn’t happen because attackers stole a private key either, it happened because North Korea’s Lazarus Group compromised a developer machine at Safe{Wallet}, the multisig platform Bybit relied on, and used it to inject malicious code into the signing interface. Bybit’s own signers approved what looked like a routine cold-to-warm wallet transfer, saw the correct address on screen, and unknowingly authorized a transaction that handed over control of the entire wallet. The FBI later attributed the attack to the TraderTraitor cluster tied to Lazarus.

How Backend Spoofing Took $351M From Bitget’s Liquidity Layer

Strip away the specific tooling, and the core mechanism is the same category of attack in both cases: the exchange’s own authorization process was deceived into approving something it wasn’t actually looking at. Bybit’s signers were shown a spoofed interface. Bitget’s backend system processed spoofed transaction data. Neither incident required brute-forcing cryptography or stealing a raw private key, both exploited the gap between what a verification system displays and what it actually executes.

Where The Two Hacks Actually Diverge

The differences matter just as much, though. Bybit’s breach hit a cold wallet, the layer every exchange treats as its most defensible line, precisely because it’s offline and requires deliberate, multi-signature action to move funds. Bitget’s incident, by contrast, stayed contained to hot and warm wallets, the layers built for liquidity and speed rather than maximum security, which is a meaningfully smaller blast radius by design. Attribution is also an open question here in a way it wasn’t for Bybit. Investigator ZachXBT weighed in publicly but said he has no current plans to formally monitor the Bitget exploit.

He added that he’s stepped back from donating his time to industry players who aren’t supporters of his work, a notably different posture from the rapid, confirmed Lazarus attribution that followed Bybit within days.

One detail stood out to me more than the technical comparison, honestly: Bybit CEO Ben Zhou publicly offered to help, noting that Bitget had supported Bybit during its own hack and that Bybit’s team was updating its Lazarus Bounty tracker specifically to help trace Bitget’s stolen funds. That’s the kind of reciprocity you don’t see written into any post-mortem template.

What The Rest Of The Industry Is Taking From This

The timing also put a spotlight on how other exchanges structure their wallet security. CoinEx’s CEO, in the middle of winding the exchange down, used the moment to describe the MPC-based dual-signature system CoinEx built for its own hot wallets, splitting signing authority across two fully independent teams, business and wallet infrastructure, so that a single compromised system still can’t move funds without the other team’s independent risk review. He said the retrofit took over a year across roughly 300 supported chains, which is the kind of unglamorous engineering effort that doesn’t get attention until an incident like Bitget’s makes the alternative look expensive by comparison.

Whether Bitget adopts something structurally similar once its investigation closes is the next thing worth watching. For now, the pattern is hard to miss: nearly two years after the industry’s largest-ever hack, the weak point still isn’t the cryptography, it’s the process standing between a system and the transaction it thinks it’s approving.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services. Follow us on X @nulltxnews

Leave a Reply

Your email address will not be published. Required fields are marked *

UP NEXT

Related Tags

Loading RSS Feed

You May Like

Subscribe To Our Newsletter

Metus in ac vivamus dui id purus in risus. Nunc fringilla donec amet pulvinar vivamus suscipit. Augue porttitor eu sed proin tortor bibendum facilisis felis. Nunc egestas tellus nisl tempor aliquet malesuada ali eu sed proin tortor bibendum facilisis felis
Stay Updated by our Monthly / Weekly News Update. Zero Spamming. Terms & Condition Applied