September 25, 2026
at
8:20 am
EST
MIN READ

Update: Since this story was originally published, Bitget has confirmed that two more wallets were compromised, bringing the total stolen to $387.5 million. The attacker also compromised wallets on Zcash and TRON that were not reviously accounted for. You can read Bitget's full statement here.
On Wednesday (September 24), Bitget detected transfers from four of its storage wallets that triggered emergency protocols. Next, CEO Gracy Chen confirmed on X that approximately $351.6 million in assets had been stolen.
Arkham sleuth Emmett Gallic was one of the first to notice the hack, tweeting about it over an hour before Gracy Chen’s statement. Gallic noticed that the funds were stolen from three Bitget hot wallets and one cold wallet, across multiple chains, and had subsequently been consolidated into a single address belonging to the hacker. (A fifth XRP wallet was also compromised.)
You can interact with the Bitget Hacker’s entity page in the Arkham window below:
These are the compromised Bitget wallets:
Hot wallet 1: 0x1AB4973a48dc892Cd9971ECE8e01DcC7688f8F23
Hot wallet 2: 0x5bdf85216ec1e38D6458C870992A69e38e03F7Ef
Hot wallet 3: 0x97b9D2102A9a65A26E1EE82D59e42d1B73B68689
Cold wallet: 0xffa8DB7B38579e6A2D14f9B347a9acE4d044cD54
Having consolidated the funds into the single address, the hacker then rapidly began to launder the stolen crypto through multiple different addresses, using a peel chain tactic that is frequently used by North Korean affiliated hackers. This process is ongoing now.
The attacker also swapped 19.67 million USDT0 for 7,111 ETH in just six minutes, paying up to 5% above market rate - a sign of someone prioritizing speed over price.
In a statement, Chen explained that the attackers had compromised a third-party tool connected to Bitget's wallet infrastructure, allowing them to forge transfer data that passed through the exchange's own authorized signing process. No private keys were stolen. She also revealed that the attackers' IP addresses matched VPN patterns associated with North Korean hacking groups, suggesting the operation was likely carried out by the DPRK - and, if so, most plausibly by the Lazarus Group, the state-backed collective the FBI blamed for the $1.5 billion Bybit hack in February 2025.
Read our comprehensive guide to the Lazarus Group here.

Founded in 2018 and registered in the Seychelles, Bitget operates globally with regional hubs across Asia and Latin America, serving over 120 million users. It is one of the world's largest exchanges by trading volume. Bitget has stated that all losses are fully covered by its User Protection Fund, which holds 5,500 BTC - worth approximately $464 million.
The hacker's addresses have been collected into a single entity on Arkham: Bitget Hacker.
From the entity page, you can use Arkham's Tracer to follow the stolen funds step by step as they move between addresses and chains.

In addition to the four compromised wallets already mentioned, a fourth wallet on XRP was also compromised. Indeed, the largest share of the stolen funds - roughly 103 million XRP - was moved on the XRP Ledger, which can be tracked on a dedicated XRP explorer. Paste the hacker's XRP address into an XRP explorer to follow every outbound payment in real time: rwNhefsz1UQEusxhCvHip3RANinWi4CTck.
Additionally, the following addresses on Zcash and TRON belong to the hacker:
Zcash: t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG


.jpeg)
.jpeg)














.png)
.png)






























.jpg)
.jpg)


















.png)
.png)
.png)
.png)










.png)
.png)




.png)
.png)


.png)
.png)


.png)
.png)


.png)
.png)
.png)
.png)


















.png)
.png)


.png)
.png)
.png)
.png)


.png)
.png)








.png)
.png)





