Tag: Crypto exchange hack

  • Swiss Bank Shields Bitget Institutional Clients as Retail Funds Remain Frozen

    Swiss Bank Shields Bitget Institutional Clients as Retail Funds Remain Frozen

    Key Highlights

    • Bitget confirmed a Sept. 24 wallet breach that transferred approximately $387.5 million in assets to attacker-controlled addresses, affecting hot and warm wallet layers while cold wallets remained secure.
    • Sygnum Bank’s Protect service offers Bitget institutional clients an off-exchange custody route where pledged collateral—including Bitcoin, Ethereum, stablecoins, and U.S. Treasuries—is held in segregated, bankruptcy-remote Swiss accounts, reducing direct exposure to exchange wallets.
    • Withdrawals remain suspended as of Sept. 25; Bitget cites a User Protection Fund holding 5,500 BTC (valued above $464 million at the time of the breach) to cover qualifying losses, with a withdrawal-status update promised by Sept. 26 04:00 UTC.

    The Breach and Immediate Response

    Bitget detected unauthorized transfers at 18:31 UTC on Sept. 24, initially estimating the loss at roughly $351.6 million. A Sept. 25 update raised that figure to approximately $387.5 million after a fuller accounting that included Zcash and TRON transfers; the exchange emphasized the revision did not represent a fresh wave of unauthorized activity. Bitget stated the breach reached portions of its hot and warm wallet layers while cold wallets remained secure. The exchange said it identified and remediated the underlying vulnerability, contained the incident, and engaged Mandiant and SlowMist to assist the investigation.

    Withdrawals were paused immediately, with deposits and trading left operational. Bitget’s notice promised to announce a withdrawal plan or status by Sept. 26 at 04:00 UTC. For ordinary customers, a displayed balance and the ability to trade do not by themselves provide an exit while withdrawals are unavailable.

    Sygnum’s Off-Exchange Custody Alternative

    On the same day as the breach, Sygnum announced that Bitget’s institutional clients could trade against collateral held at the Swiss bank instead of placing that collateral in Bitget’s wallets. Under the Protect service, eligible clients onboard with Sygnum, sign a contractual framework, open a Protect portfolio, and pledge assets—Bitcoin, Ethereum, stablecoins, and U.S. Treasuries are listed as eligible collateral—before receiving exchange margin. Bitget mirrors the balance as trading margin.

    Sygnum describes the collateral as held in segregated accounts off the bank’s balance sheet and bankruptcy remote under Swiss banking law. The arrangement is intended to keep pledged assets outside Bitget’s estate should the exchange face financial distress, and to reduce direct custody exposure to Bitget’s own wallets. The announcement is dated Sept. 24 but does not state when client access became operational, whether the integration preceded or followed the 18:31 UTC breach, how many Bitget clients have onboarded, any Bitget-specific collateral balance, or whether Sygnum-held assets were involved in the incident. Public figures for Protect’s total assets and the trading-volume share of all integrated exchanges do not measure Bitget client uptake.

    User Protection Fund and Recovery Outlook

    For users holding ordinary balances on Bitget, the exchange pointed to its User Protection Fund. In its initial Sept. 24 notice, Bitget said the fund was worth more than $464 million and that the then-estimated $351.6 million incident fell within its coverage. The fund’s public page lists 5,500 BTC and states users may claim for qualifying losses from platform-wide events beyond their own actions or trading behavior, with Bitget reserving the right to assess and investigate claims. The dollar value of the Bitcoin-denominated fund moves with BTC’s price; Bitget’s August report put the fund’s monthly average at $382 million and its month-end value near $432 million on the same 5,500 BTC holding.

    Bitget also said it froze some affected assets through work with industry partners, but its Sept. 25 update did not quantify the frozen or recovered amount. The next measurable tests are a confirmed withdrawal timetable, a firmer loss and recovery accounting, and the terms of any fund disbursement.

    Why This Matters

    The incident highlights a structural tension in crypto custody: even when institutional collateral is segregated off-exchange with a regulated bank like Sygnum, trading still depends on the exchange’s order, margin, and settlement processes. Public materials do not establish that a Protect client can instantly reclaim pledged collateral during an exchange disruption, nor that operational problems could never delay settlement. Conversely, they do not show that any Sygnum client is blocked from its collateral in this incident. The arrangement creates an optional boundary between institutional collateral and Bitget wallet custody—Bitget’s ordinary balances faced exchange-wallet exposure, while Institutional Protect keeps pledged collateral off-exchange with Sygnum. Missing facts include Bitget-specific Protect uptake and the contract terms governing collateral release and settlement when the exchange is under strain.

    Frequently Asked Questions

    How much was stolen in the Bitget breach and which wallets were affected?

    Bitget estimates approximately $387.5 million in assets were transferred to attacker-controlled addresses. The breach reached hot and warm wallet layers; cold wallets were not compromised.

    What is Sygnum Protect and how does it differ from keeping funds on Bitget?

    Sygnum Protect lets eligible institutional clients pledge collateral—such as Bitcoin, Ethereum, stablecoins, and U.S. Treasuries—in segregated, bankruptcy-remote accounts at the Swiss bank. Bitget mirrors that collateral as trading margin, but the assets remain off Bitget’s balance sheet and outside its wallets, reducing direct custody exposure.

    When will Bitget withdrawals resume and are user funds insured?

    Withdrawals remain suspended as of Sept. 25. Bitget promised an update by Sept. 26 04:00 UTC. The exchange cites a User Protection Fund holding 5,500 BTC (valued above $464 million at the time of the breach) to cover qualifying platform-wide losses, subject to claim assessment and investigation.

  • Bitget Freezes Withdrawals After $351.6M Hack

    Bitget Freezes Withdrawals After $351.6M Hack

    Key Highlights

    • Bitget confirmed a $351.6 million exploit from its hot wallets on September 24, 2026, with on-chain data showing the first unauthorized transfer at 18:31:11 UTC and major outflows continuing for nearly three hours before the public notice.
    • The attacker rapidly converted freezable stablecoins (USDT, USDC, Tether Gold) into ether via a router contract, paying up to 5% above spot price, suggesting a deliberate race against issuer freeze functions.
    • CEO Gracy Chen stated user funds are safe and the loss is covered by Bitget’s $464 million User Protection Fund, while withdrawals remain suspended pending a full incident report due within 24 hours.

    Timeline Reveals Hours-Long Gap Between Detection and Containment

    Bitget chief executive Gracy Chen confirmed on Thursday night that attackers drained roughly $351.6 million from the exchange’s hot wallets, suspending customer withdrawals while an investigation proceeds. Chen published the notice at 21:30 UTC on September 24, 2026, stating: “At 18:31 UTC on September 24, 2026, Bitget’s security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.”

    On-chain data corroborates the 18:31 detection timestamp but paints a more granular picture of the subsequent three hours. At 18:31:11 UTC, a wallet labeled “Bitget 6” on Etherscan, Arbiscan, and BscScan sent 0.84 ether to a newly created address — a test transaction that typically precedes large transfers and marks the first movement of the breach. The outflows accelerated rapidly: by 18:58:59, the same wallet moved 34,751,168 USDT; at 19:01:20 on Arbitrum, 19,668,851 USDT0; at 19:01:23, 12,852,046 USDC; and at 19:01:35, 7,130.86 ether. A second wallet, “Bitget 35,” added 15,362 ether across three transfers, followed by another 223.2 ether at 21:23:11 — two hours and 52 minutes after detection and just seven minutes before Chen’s public notice.

    Across Ethereum and Arbitrum alone, $133.4 million exited Bitget-labeled wallets, plus 3,000 Tether Gold tokens worth approximately $12.8 million from a third address. The remainder of the $351.6 million moved on other chains. Chen emphasized that cold storage was never touched and described a three-tier wallet architecture in which “the breach contained only a portion of the hot wallet and warm wallet layers.” However, the extended window between detection and containment allowed substantial value to leave the exchange’s control.

    Attacker Strategy Signals Intent to Outrun Freeze Functions

    The composition of stolen assets and the speed of conversion provide the clearest signal of the attacker’s intent. Tether can freeze USDT, Circle can freeze USDC, and Tether can freeze its gold token — but ether cannot be frozen by any central party. Within six minutes of receiving the stablecoins, the attacker pushed all three asset types into router contract 0x7c96279E, which fanned them across Uniswap V3 pools and the Uniswap V4 PoolManager, converting everything into ether.

    Pseudonymous analyst DCF GOD, who identified the Arbitrum leg before Bitget’s public statement, noted the buyer was “paying up to +5% over spot” and drove one pool to $2,870 against a spot price near $2,688. “which makes no sense if someone was just trying to buy eth,” he wrote. The premium paid aligns with a seller racing issuer freeze functions rather than a typical market participant. The resulting ether — approximately 24,590 ETH — now sits in three previously inactive wallets: 10,000 ETH at 20:13, another 10,000 at 20:19, and 4,590 more at 21:41:11. That final transfer occurred ten minutes after Chen’s notice and one minute after Bitget’s official account stated it had “identified and flagged the relevant transfer addresses.”

    Exchange Response and Industry Context

    “User funds are safe,” Chen wrote. “The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million.” She added that deposits and trading continue normally and promised a full incident report within 24 hours: “We will not speculate on the attack vector until the investigation is complete.”

    That restraint reflects a pattern security experts recognize across recent major exchange breaches. Ido Sofer, founder and CEO of key management firm Sodot, described the dynamic on the On The Margin podcast: “Those are off-chain hacks that led to on-chain loss of funds. Developer credentials, deployment keys, API keys that are being stolen. And that provided access to moving funds on chain.” His blunter assessment: “There will be hacks. The question is, is it gonna be in your company or not?”

    Bitget’s $464 million protection fund against a $351.6 million loss provides a thin but real cushion. The exchange has published proof-of-reserves attestations for 45 consecutive months, most recently reporting a 122% reserve ratio for August. The immediate test is whether withdrawals reopen without disruption.

    Why This Matters

    This incident represents the largest exchange loss since the Bybit breach and follows a series of high-profile security failures including the $130 million Coldcard theft and a $137 million November exploit that reshaped DeFi’s yield infrastructure. The attack underscores a persistent industry vulnerability: custodial exchanges remain prime targets where compromised off-chain credentials — developer keys, API access, deployment infrastructure — translate directly into on-chain asset drainage. The attacker’s sophisticated conversion strategy, deliberately overpaying to swap freezable assets for censorship-resistant ether before issuers could intervene, demonstrates an evolving playbook that prioritizes speed and asset selection over stealth. For the broader market, the episode tests whether exchange-backed protection funds can credibly absorb nine-figure losses without contagion, and whether proof-of-reserves attestations translate into operational resilience when withdrawals are suspended. The 24,590 ether now parked in three fresh wallets remains a live threat vector; any movement will signal the next phase of laundering or liquidation.

    Frequently Asked Questions

    What assets were stolen and how much is the total loss?
    Approximately $351.6 million was drained from Bitget’s hot wallets across multiple chains. On Ethereum and Arbitrum alone, $133.4 million in USDT, USDC, USDT0, and ether left labeled wallets, plus 3,000 Tether Gold tokens worth ~$12.8 million. The remainder moved on other networks. The attacker converted all freezable stablecoins and gold tokens into ether within minutes.
    Are user funds affected and will withdrawals resume?
    CEO Gracy Chen stated “User funds are safe” and confirmed the loss falls within Bitget’s User Protection Fund, which holds over $464 million. Cold storage was not touched. Deposits and trading continue normally, but withdrawals remain suspended pending investigation. A full incident report is promised within 24 hours from the September 24 notice.
    How did the attacker move the funds and can they be recovered?
    The attacker used a router contract (0x7c96279E) to swap USDT, USDC, and Tether Gold for ether via Uniswap V3 and V4 pools, paying up to 5% above spot price to execute quickly before issuers could freeze the stablecoins. The resulting ~24,590 ether now sits in three previously unused wallets. Ether cannot be frozen by any central party. Tether and Circle have freeze capabilities for USDT and USDC respectively, but those assets were already converted. Recovery depends on law enforcement action, exchange cooperation, and whether the attacker makes operational security mistakes when moving the ether.