Key Highlights
- On-chain data indicates a potential exploit at cryptocurrency exchange Bitget, with over $170 million in assets moved from three hot wallets and one cold wallet across multiple networks, primarily converted to Ethereum ($ETH).
- An attacker address on Arbitrum acquired 7,111 $ETH in six minutes using approximately 19.67 million USDT0 via UniswapX and 1inch Fusion, executing some trades at a 5% premium to spot prices.
- Bitget has begun moving remaining funds—approximately $530 million—from the affected wallets to secure addresses in what appears to be an emergency containment effort, while the root cause and potential North Korea links remain unconfirmed.
Massive On-Chain Outflows Trigger Hack Suspicions at Bitget
Unusual on-chain activity detected in wallets allegedly controlled by the centralized exchange Bitget has sparked widespread suspicion of a significant security breach. Blockchain analytics reveal that high-value assets have been systematically drained from the exchange’s hot and cold wallet infrastructure, with the bulk of the stolen funds rapidly converted into Ethereum ($ETH). The incident appears to span multiple blockchain networks, suggesting a broad compromise rather than an isolated vulnerability on a single chain.
Arbitrum Transactions Reveal Speed and Scale of Attack
Initial alarm was raised by a flurry of transactions on the Arbitrum network. A newly created address purchased 7,111 $ETH in a mere six minutes, spending approximately 19.67 million USDT0 sourced directly from a Bitget hot wallet. The trades were routed through UniswapX and 1inch Fusion, with several executions occurring at prices roughly 5% above the prevailing spot rate. This aggressive buying pressure momentarily pushed the WETH/USDC pool price to $2,870, illustrating the urgency and volume of the asset conversion.
Compromise Extends Across Multiple Wallets and Asset Classes
Subsequent blockchain analysis indicates the breach is not confined to a single wallet or network. Data shared by on-chain investigators suggests three hot wallets and one cold wallet associated with Bitget have been impacted. A diverse range of assets—including $ETH, AVAX, BNB, $USDC, $USDT, USDT0, and XAUT—have been moved from these addresses. The addresses attributed to the attacker continue to swap remaining stablecoin balances ($USDC and $USDT) for $ETH, driving the total tracked on-chain loss above $170 million. Early social media speculation had placed the figure at over $100 million, but cross-network transaction tracing has since revised the estimate upward.
Exchange Initiates Emergency Containment Measures
In a significant development approximately five minutes prior to this report, Bitget-owned addresses began actively transferring assets remaining in the compromised wallets to new destinations. Roughly $530 million in assets are still held within the affected wallet cluster. This movement is being interpreted by analysts as an emergency fund transfer and a security measure to isolate wallets not yet believed to be compromised. The exchange has not yet issued a formal public statement detailing the root cause, leaving critical questions unanswered regarding whether private keys were exposed or if a deeper infrastructure vulnerability was exploited.
Why This Matters
The suspected breach at Bitget represents one of the largest exchange-related security incidents in recent months, underscoring the persistent systemic risk posed by centralized custody of digital assets. The sophistication of the attack—leveraging advanced DEX aggregators like UniswapX and 1inch Fusion for rapid, high-slippage conversion to Ether—suggests a highly capable actor. Unverified claims attributing the hack to North Korea-linked groups, such as the Lazarus Group, align with historical patterns of state-sponsored cybercrime targeting crypto exchanges to fund sanctioned regimes. If confirmed, this would mark another major success for such actors. For the broader market, the incident tests the resilience of exchange solvency proofs and the effectiveness of real-time on-chain monitoring in mitigating losses. The next 24 to 48 hours are critical: the industry will be watching for Bitget’s official incident report, proof-of-reserves updates, and whether the remaining $530 million in identified wallets can be fully secured.
Frequently Asked Questions
How much money was stolen in the Bitget hack?
On-chain analysis currently estimates the total value of assets moved by the attacker exceeds $170 million. Approximately $530 million remains in the affected wallets, which Bitget is actively moving to secure addresses.
Which networks and tokens were affected?
The exploit spanned multiple networks, with initial major activity on Arbitrum. Assets moved include Ethereum ($ETH), AVAX, BNB, $USDC, $USDT, USDT0, and XAUT. The attacker is converting stablecoins into $ETH.
Has Bitget confirmed the hack and are user funds safe?
As of this report, Bitget has not released an official statement confirming the hack or detailing the cause. However, on-chain data shows the exchange has begun transferring remaining funds from the compromised wallets, suggesting an active emergency response. Users should monitor official Bitget channels for updates.



