According to Bitget, an attacker wrote forged withdrawal commands into its wallet system on September 24, 2026, draining about $387.5 million from its hot and warm wallets; every stolen stablecoin was swapped into native tokens within 41 minutes, and the funds are now being consolidated into BTC, mainly through THORChain. Publicly visible freezes total about $840,000, or 0.2% of the stolen amount: Tether and Circle froze stablecoins left idle on attacker addresses, and NEAR Intents says it froze about $503,000 mid-execution. Multiple parties have linked the attack to North Korea's TraderTraitor, but on-chain overlaps point more directly to shared laundering groups than to the same attackers.
1. What Happened
At 18:31 on September 24, 2026 (UTC; all times below are UTC), Bitget's Ethereum hot wallet sent out 0.84 ETH and its TRON hot wallet sent out 93 TRX. According to Bitget in a later livestream, these were two test transfers by the attacker. The amounts were below the risk-control threshold and did not trigger an alert.
Large outflows began at 18:58. At 19:05, Bitget's reconciliation system detected a large discrepancy, and risk controls automatically blocked all user-initiated withdrawals on the platform. According to Bitget, however, the attacker was writing forged withdrawal commands directly into the wallet system, and the outflows continued. The last transfer took place at 21:23, 2 hours and 52 minutes after the test transfers, and the Bitget tracing dashboard recorded 26 successful outflows in total. At 21:44, Bitget shut down the signing machines and other wallet withdrawal services.
According to Bitget, the attacker exploited a zero-day vulnerability in a third-party security product, stole high-privilege internal network credentials, wrote forged withdrawal commands into the wallet system, bypassed risk checks, and deleted the related records after each transfer. Bitget says its private keys were not compromised and its cold wallets were unaffected. The loss was first reported at about $351.6 million and later revised to about $387.5 million after transfers on Zcash and TRON were added. Dashboard records show 13 stolen assets across 12 chains, with XRP the largest single-chain loss. Bitget says user balances are unaffected and the loss will be covered by its user protection fund.
2. The Laundering Path
Based on the attacker's behavior so far, the laundering has three main steps: swap freezable assets into native tokens, consolidate assets from different chains into Bitcoin (with Ethereum as the main transit chain), and then move BTC into mixers over time.
The first step was the fastest. The stolen assets included about $75.48 million in USDT, USDC and USDT0, plus 3,000 XAUt, a gold token issued by Tether. These assets have centralized issuers, which is likely why the attacker dealt with them first. Each was swapped into ETH or AVAX within 41 minutes of being stolen:
| Asset | Amount stolen | Stolen at | First swap | All swapped | Received |
|---|---|---|---|---|---|
| Ethereum USDT | 34,751,168 | 18:58:59 | after 10 min | after 18 min | 12,876.76 ETH |
| Ethereum USDC | 12,852,046 | 19:01:23 | after 17 min | after 18 min | 4,761.74 ETH |
| Ethereum XAUt | 3,000.32 | 19:01:23 | after 23 min | after 28 min | 4,689.14 ETH |
| Arbitrum USDT0 | 19,668,852 | 19:01:20 | after 35 min | after 41 min | 7,111.24 ETH |
| Avalanche USDC | 8,204,679 | 20:55:07 | after 31 min | after 33 min | 740,684 AVAX |
The swaps went through common channels such as UniswapX, Uniswap, 1inch and the swap feature built into the MetaMask wallet. All of them were completed before Bitget's CEO posted publicly about the incident at 21:30.
The second step began on September 24, the day of the theft, and as of September 29 had been under way for nearly five days. According to the Bitget tracing dashboard (data as of 12:30 on September 29; unless otherwise noted, all dashboard data below comes from the same snapshot), every cross-chain transfer currently in flight is headed to BTC, and about 90% of them by value were sent from Ethereum.

The main channel for this step is THORChain, a cross-chain swap protocol. Dashboard figures show that the attacker has sent a net total of about $269 million into THORChain (7,804 transactions). Among cross-chain swap services, Chainflip comes second at about $37.27 million. Note that these are pass-through amounts: the same funds may pass through several channels, so the figures for different channels should not simply be added together, and they do not represent the amount that has already been laundered.
The third step is Bitcoin CoinJoin, which mixes many users' bitcoin in a single transaction and breaks the link between inputs and outputs. As of September 29, a cumulative total of about $3.94 million had gone into CoinJoin, still small relative to the attacker's BTC holdings.
One example is a CoinJoin transaction confirmed at 11:03 on September 27. It has 356 inputs and 401 outputs. Four of the inputs (2.5 BTC each, 10 BTC in total) came from addresses that the Bitget dashboard labels as the attacker's. Many outputs share the same denomination; for example, 21 outputs are 0.02097152 BTC each, and on-chain data alone cannot tell who owns which of them.

Nearly five days after the attack began, the attacker still controls about $342 million, or 88.3% of the stolen total. Of this, BTC accounts for about 83.7% (about 3,386 BTC), ZEC about 8.5%, ETH about 7.3% (about 9,357 ETH) and stablecoins about 0.2%. The dashboard's reconciliation shows about $3.78 million lost to swaps and cross-chain transfers as of September 25. Tether and Circle have frozen about $340,000, and NEAR Intents says about $500,000 was frozen during execution on its platform.
3. Freezes
As of September 29, publicly visible freezes total about $840,000, about 0.2% of the stolen total. Stablecoin issuers Tether and Circle froze about $340,000, and the cross-chain service NEAR Intents says it froze about $500,000 during execution. The two kinds of freezes work differently.
Freezes by stablecoin issuers
For stablecoins issued by Tether and Circle, the issuer can freeze the balance held at a given address. Likely to avoid such freezes, the attacker swapped every stolen stablecoin into native tokens within 41 minutes of it being stolen (see Section 2). That does not mean stablecoins disappeared from the transfer process, and their reappearance is what made the Tether and Circle freezes possible.
As of September 29, Tether and Circle had frozen about $340,000. We traced the source of each frozen amount and found that most of it came from stablecoins the attacker used as a transit asset during cross-chain transfers.
| Address | Frozen | First stablecoin received | Frozen funds arrived | Frozen at |
|---|---|---|---|---|
| 0xe07b...7d57 (Ethereum) | 218,022.97 USDT | 9/24 20:23 | 9/24 23:36-23:47 | Tether 9/25 12:19 |
| 0xe07b...7d57 (Ethereum) | 99,989.91 USDC | 9/24 21:23 | 9/24 23:38 | Circle 9/25 05:00 |
| 0x9acc...b046 (Ethereum) | 21,090.53 USDT | 9/25 08:45 | 9/25 12:48 | Tether 9/25 14:09 |
| 2 addresses on TRON | 221.13 USDT | 9/25 11:22 | from 9/25 11:22 | Tether 9/28 13:09 |
Freeze times are from the BlockSec USDT Freeze Tracker.
The largest amount, about $318,000, sits at 0xe07b...7d57, an address the attacker used on both BSC and Ethereum. On BSC, the attacker swapped BNB into BSC-USD and other stablecoins, split them into round chunks of 200,000, 100,000 and 20,000, and sent them to Ethereum through PancakeSwap's cross-chain service (built on Across) and other channels. On the Ethereum side, the funds arrived as USDT or USDC and were swapped into ETH within minutes. BSC-USD (full name Binance-Peg BSC-USD) is issued by Binance, and its contract has no freeze function; once bridged to Ethereum, the funds became USDT and USDC that Tether and Circle could freeze. Of the 48 transfers this address sent through PancakeSwap's cross-chain service, the median arrival time was 88 seconds. Four of the stablecoin transfers, however, were delayed by 62 to 83 minutes and became the last to arrive, landing between 23:36 and 23:47, while the attacker had stopped operating this address at 23:07. About 27 hours later, the attacker returned to the address and moved out the 170.47 ETH it held, but by then the USDT and USDC had already been frozen by Circle and Tether.
The other two cases are similar. The 21,090 USDT frozen at 0x9acc...b046 was a THORChain refund. The attacker had sent bridged USDT into THORChain to swap for BTC, and part of the order was refunded. Other refunds to this address arrived within 17 minutes, but this one took 109 minutes, and by the time it arrived the attacker had left. The two amounts on TRON are leftovers after the attacker moved funds out in round numbers.
What these frozen amounts have in common is that they stayed at the address long enough. By contrast, 425,959 USDT that arrived at 07:01 on September 29 stayed for only 1 hour and 14 minutes before being swapped into ETH and sent into THORChain. That is shorter than the fastest freeze so far (about 5 hours and 24 minutes from the address first receiving stablecoins to the freeze), and it was not frozen.
A long stay, however, does not guarantee a freeze. As of September 29, the dashboard showed about $310,000 in stablecoins still freezable across 5 attacker-linked addresses. The largest is 267,364 USDC at 0xec13...691f, which arrived at 05:57 on September 29. As of 13:27 (see figure below) it had stayed for about 7.5 hours and had not been frozen. For comparison, Circle's earlier freeze of USDC at 0xe07b...7d57 took about 7.6 hours from the time that address first received USDC, so the two are roughly the same.

How cross-chain services handled the funds
The other kind of freeze happens while a cross-chain service is processing a swap request. According to a September 28 disclosure by NEAR Intents, the attacker tried to move more than $50 million through it. After its risk layer SHIELD flagged the requests, it either declined to quote or halted execution. In the end about $166,000 got through, and about $503,000 was frozen mid-execution and remains restricted. These figures are NEAR Intents' own account, and the original post says they may be off by up to 10%.
One example is an order that the Bitget dashboard labels as held by NEAR Intents. At 16:35 on September 25, an attacker address deposited 173,819 XRP (valued at about $266,000 on the dashboard) from the XRP Ledger into NEAR Intents, to be swapped into BTC. The deposit was confirmed, but the order remains stuck in "Processing," well past its 17:35 deadline, and no refund has been issued. The dashboard labels 4 such orders, totaling about $294,000.

Besides NEAR Intents, the attacker's funds passed through several other cross-chain services. Dashboard figures show that THORChain handled the largest amount, about $269 million, followed by USDT0/LayerZero at about $55.13 million, Circle's cross-chain protocol CCTP at about $49.33 million, Chainflip at about $37.27 million, Across at about $14.38 million and Stargate at about $12.82 million. These are pass-through amounts and should not be added together.
THORChain handled the largest volume and has also drawn controversy. On September 26, Bitget CEO Gracy Chen publicly asked THORChain to refuse service to the attacker's addresses, writing: "Decentralization is a design principle, not a shield for facilitating known stolen funds." Others pointed out that when THORChain lost about $10.7 million in May this year because of a vulnerability in its own signing scheme, it paused the entire network. THORChain responded that "a halt is not a selective freeze of specific funds or an individual swap," and that the protocol "doesn't censor by design." As of September 29, stolen funds were still being swapped from ETH into BTC through THORChain.
4. The "North Korean Hackers" Assessment, and Comparison with Bybit
Within hours of the incident, multiple parties pointed to North Korean hackers. Their reasoning falls into three categories.
The first is Bitget's own assessment. Bitget CEO Gracy Chen said that, based on IP behavioral patterns and on-chain signatures, the attack is "consistent with techniques used by DPRK-linked hacker groups," and that Bitget had identified IP addresses matching the VPN choices of a certain DPRK group. The technical basis has not been published.
The second is on-chain links between funds. About six hours after the incident, on-chain analyst Specter said that the XRP stolen from Bitget, after being bridged, "can be directly linked to the funds stolen in the AFX hack" in July this year, which was attributed to TraderTraitor. Some media noted that this link runs through a single Ethereum wallet holding about $4,300, so the evidence is thin.
The third is overlap in laundering networks and methods. ZachXBT published the social media accounts and related transactions of five Chinese illicit actors laundering funds on behalf of the attackers, and said that one of them had also been seen laundering funds from the $292 million Kelp DAO exploit earlier this year. He said he had observed the same pattern after multiple TraderTraitor-attributed exploits and has closely tracked these groups, and that the funds are currently being chain-hopped via bridges and deposited into mixing services such as Wasabi. Arkham also noted that the attacker used "a peel chain tactic that is frequently used by North Korean affiliated hackers."
Among these leads, the 2025 Bybit case comes up again and again. At the time, about $1.5 billion was stolen from Bybit's Ethereum cold wallet. Five days later, the FBI issued a notice attributing the theft to North Korea and referring to this activity as "TraderTraitor." A report by the security firm Sygnia notes that it is also known as the Lazarus Group.
The two cases are indeed similar. First, neither attack stole the exchange's private keys; both went through a third party. In the Bybit case, the attacker first compromised a Safe{Wallet} developer's computer and then altered the Safe web interface's scripts so that Bybit's signers approved a transaction that handed over control of the cold wallet. In this case, according to Bitget, the attacker exploited a zero-day vulnerability in a third-party security product. Second, the laundering methods are similar, with THORChain as the main channel in both: figures published by Bybit CEO Ben Zhou on March 4, 2025 showed that 72% of the stolen funds had moved through THORChain at that point. Differences in the laundering paths, such as the extra steps of swapping stablecoins and consolidating across chains in this case, depend mainly on which assets were in the stolen wallets and cannot be used to tell attackers apart.
But at a time when both attacks and laundering are highly service-based, the information above is not enough to determine the attacker's identity. According to Bitget, the entry point was a vulnerability in a third-party security product; services such as THORChain and CoinJoin are open to anyone; and the underground groups laundering funds on behalf of the attackers are not necessarily the attackers themselves. On-chain overlaps therefore point more directly to the possibility that the same laundering groups were involved in this case and earlier ones, not necessarily the same attackers. A firmer conclusion will have to wait for Bitget's full investigation report or an announcement from law enforcement.
Data notes: all times are UTC. Unless otherwise noted, dynamic data from the Bitget tracing dashboard comes from a snapshot taken at 12:30 UTC on September 29, 2026. On-chain figures come from BlockSec's review of the addresses listed on Bitget's official tracing dashboard. The account of the incident comes from Bitget's official livestream (as transcribed by Wu Blockchain) and official announcements. Freeze times come from the BlockSec USDT Freeze Tracker.
Sources:
- Bitget tracing dashboard https://trace.bgblockchain.xyz
- Gracy Chen on X, 2026-09-24 https://x.com/GracyBitget/status/2103235655879074084
- Bitget on X, 2026-09-25 https://x.com/bitget/status/2103485484165120005
- Bitget livestream as transcribed by Wu Blockchain https://mp.weixin.qq.com/s/bCYi4kV8qAJHdlkDlkng9A
- BlockSec USDT Freeze Tracker https://blocksec.ai/en/usdt-freeze/addresses
- NEAR Intents (AlexAuroraDev), 2026-09-28 https://x.com/AlexAuroraDev/status/2104554958754357482
- FBI IC3 notice, 2025-02-26 https://www.ic3.gov/PSA/2025/PSA250226
- Sygnia, 2025-03-16 https://www.sygnia.co/blog/sygnia-investigation-bybit-hack/
- Ben Zhou on X, 2025-03-04 https://x.com/benbybit/status/1896798476945744010
- Elliptic, 2026-09-25 https://www.elliptic.co/insights/bitget-attack-pushes-suspected-north-korea-crypto-heists-over-1-billion-in-2026/
- TRM Labs, 2026-09-25 https://www.trmlabs.com/resources/blog/bitget-loses-usd-3516-million-in-hot-wallet-breach-in-likely-north-korea-attack
- ZachXBT on X, 2026-09-28 https://x.com/zachxbt/status/2104528688469647700
- Gracy Chen on X, 2026-09-26 https://x.com/GracyBitget/status/2103812967066439817
- THORChain on X, 2026-09-28 https://x.com/THORChain/status/2104460133132562449
- Star Xu on X, 2026-09-27 https://x.com/star_okx/status/2104004321805480214
- mempool.space, CoinJoin transaction 2380584fe493b68403b1e1d5848118590c9b8c323efe630426e26b15523f125e https://mempool.space/tx/2380584fe493b68403b1e1d5848118590c9b8c323efe630426e26b15523f125e
- NEAR Intents explorer, order rhMr4vRDbUC5R38x3VZ9aHfuvmA4A1RjsS https://explorer.near-intents.org/transactions/rhMr4vRDbUC5R38x3VZ9aHfuvmA4A1RjsS
- CoinDesk, 2026-05-15 https://www.coindesk.com/tech/2026/05/15/thorchain-halts-trading-after-usd10-million-cross-chain-exploit-rune-token-drops-12
- AMBCrypto, 2026-06-24 https://ambcrypto.com/thorchain-resumes-trading-after-10-7m-exploit-unveils-monero-swap-roadmap/
- Gracy Chen on X, 2026-09-25 https://x.com/GracyBitget/status/2103359608484172104
- Startup Fortune (citing Cointelegraph), 2026-09-25 https://startupfortune.com/bitgets-ceo-says-north-korean-hackers-spoofed-transfers-to-steal-352-million/
- Specter on X, 2026-09-25 https://x.com/SpecterAnalyst/status/2103286738961486186
- Bitcoin.com News, 2026-09-25 https://news.bitcoin.com/exchanges/bitget-hack-xrp-157m-cannot-be-frozen/
- Arkham Research, 2026-09-25 https://info.arkm.com/research/hacker-steals-350m-from-bitget-and-begins-on-chain-laundering



