In September 2026, Bitget was the victim of an attack targeting its backend infrastructure to spoof on-chain transactions. In total, an estimated $387.5 million was stolen, making it the biggest hack of 2026 to date and among the ten largest of all time.
Inside the Attack
The Bitget hack was detected based on anomalous transfers from some of the exchange’s hot and warm wallets (the exchange runs a hot/warm/cold wallet infrastructure). Normally, this would mean that compromised private keys were the most likely culprit. However, this wasn’t the case for the Bitget incident.
Instead, the attacker targeted the exchange’s backend wallet infrastructure and used it to generate spoofed transactions. This involved exploiting a vulnerability in a third-party security product used by Bitget. This granted the attackers high-level credentials for the internal network, which were used to forge transactions.
These fake transactions were then routed through the legitimate transaction approval process. Since they looked legitimate, they were automatically approved without raising alerts. Via this process, the attacker was able to drain hot and warm wallets, but cold ones were unaffected.
After the attack, about $100 million of the stolen tokens were converted to ETH, largely to protect USDT, USDC, and similar assets from being frozen/blocklisted, and an additional $85 million was already ETH. About $157.5 million in XRP and $7 million in TRX remained unconverted.
The pattern of converting assets, including rapid conversions of some assets, IP addresses used, and transfers to wallets linked to past hacks, resulted in this incident being attributed to North Korea’s Lazarus Group. The entire sum will be covered by the $464 million Bitget User Protection Fund, and the exchange has offered a 5% bounty for freezing attacker funds and a 5% one for recovery.
Lessons Learned from the Attack
The Bitget hack is an example of a Web3 hack that targeted off-chain infrastructure to perform an on-chain exploit. Instead of trying to steal the private keys used to digitally sign blockchain transactions, the Lazarus Group exploited the wallet infrastructure that managed unsigned transactions. A supply chain attack exploiting a third-party solution provided the credentials needed to forge transactions and steal funds without access to the private keys.
This incident demonstrates the importance of securing every element of a Web3 organization’s infrastructure. Transactions are only immutable and authenticated after they’re digitally signed, so spoofing or modifying transactions before signatures are applied gives attackers the opportunity to steal funds without keys.
Halborn offers Custody and Key Management Assessments to help organizations identify potential risks and security gaps in these key security and transaction signing workflows. To learn more about protecting your organization against these threats, get in touch with Halborn.
