AdvertisementAdvertisementAdvertisementAdvertisement
Cryptocurrency

GoPlus Unveils Attack Mechanism on Bitget with $387.5 Million Loss

9/27/2026, 11:46 AM • Evgenia Sliv

(edited: 09/27/2026)

GoPlus Unveils Attack Mechanism on Bitget with $387.5 Million Loss

According to GoPlus Security, the attack on Bitget was not related to the theft of private keys but rather the compromise of a critical backend system in the wallet infrastructure. By gaining control over this component, the attackers were able to alter transaction data and feed it into the exchange's internal authorization and signing process. As a result, the system generated valid cryptographic signatures for operations that the platform itself did not intend to execute. Bitget's head, Gracie Chen, confirmed this incident scheme on September 25, although the exact method of initial penetration remained unknown at the time of GoPlus's analysis publication. Unauthorized transfers continued for about 2 hours and 25 minutes—from 21:58 to 00:23 Moscow time on September 24–25. The largest operation occurred around 22:16: approximately $185 million was withdrawn in about one minute, including 13,966 ETH, about $91.4 million in XRP, and 20.6 million TRX.

The total damage amount was later clarified by Bitget to be $387.5 million, up from the initial estimate of $351.6 million after accounting for assets in the Zcash and TRON networks. The attack affected some hot and warm wallets, while the cold storage and Bitget Wallet, intended for self-custody of assets, were not impacted. GoPlus noted similarities to the attack on Bybit; however, in the case of Bitget, the data alteration occurred directly at the server infrastructure level rather than the user interface. This distinction shows that protecting cryptographic keys alone does not prevent the compromise of subsequent transaction preparation stages. GoPlus added the addresses associated with the attack to blacklists and shared the information with ecosystem partners. Bitget stated that it had fixed the vulnerability and contained the incident, making further unauthorized transfers through the compromised mechanism impossible. To cover obligations to users, the exchange also pointed to a protection fund of over $464 million.

Following the incident, Bitget began gradually restoring withdrawals: Bitcoin is expected to return on September 28, Ethereum and several other networks on September 29, USDT operations on September 30, and other assets, fiat operations, and P2P on October 2. The attack mechanism shifts focus from the traditional task of key protection to controlling the data entering the signing system. If the component forming the transaction can be compromised, a cryptographically correct signature no longer guarantees that the operation matches the original intent of the fund owner. This principle is known beyond the cryptocurrency industry: in attacks on payment infrastructure, attackers can also influence the formation of orders without gaining direct access to signing keys. Therefore, the Bitget incident demonstrates the need to control the entire chain from transaction creation to final confirmation, including verifying the content of operations by independent system components.

Popular news