Primary path starts at Bitget’s own Security Notice: detection at 18:31 UTC Sep 24, emergency response within minutes, abnormal transfer addresses flagged, withdrawals paused, deposits and trading left up. The exchange said the loss sits inside its User Protection Fund (over $464 million) and that customer account balances remain accurate. Cold wallets were not in the breached tier.
Bitget’s Sep 25 update is the number that matters for the desk: on-chain tracing plus fuller chain coverage pushed the confirmed attacker-controlled transfer total to approximately $387.5 million. The revision adds affected assets on Zcash and TRON that were missing from the first print; Bitget says it does not reflect further unauthorized transfers after containment. Assets named include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, and TRX across Ethereum / EVM networks, XRP Ledger, Zcash, and TRON.
Operational status per Bitget: the underlying vulnerability has been identified and remediated; Mandiant and SlowMist are on the investigation; a Recovery Bounty Program (5% of frozen / 5% of recovered eligible voluntary freezes) is live, including via Bybit’s LazarusBounty channel; withdrawal timing is due to be announced by September 26, 4:00 AM UTC.
Attribution note (secondary, CEO livestream / CNBC / Cointelegraph Sep 25): Chen said investigators saw IP addresses matching VPN choices associated with a DPRK group and that the pattern resembled prior North Korean ops. She also said private-key compromise of cold / hot / warm wallets had been ruled out and that attackers breached a backend wallet path rather than forging user withdrawal requests. Treat nation-state attribution as preliminary / suspected until Bitget or a named intel firm publishes a finished RCA. TechCrunch frames the incident as the largest known digital-currency heist of 2026 so far.
Update Sep 30 (Mandiant + SlowMist interim): Per Bitget’s sharing of Mandiant’s note and SlowMist’s English summary (as of Sep 29, posted Sep 30) via BleepingComputer: on Sep 24 a threat actor gained unauthorized privileged access to third-party security appliances “A” and “B,” deployed a web shell on appliance B, established C2, then moved laterally to Bitget’s production wallet job server and deployed malicious packages. SlowMist dates the earliest available-log activity to Aug 31 on Product A (hidden script under a service process; env/db password read attempts). Investigators recovered a custom withdrawal tool that forged risk-control parameters so Bitget’s own withdrawal path accepted the transfers — on-chain outflow ~2h52m from 18:31–21:23 UTC Sep 24. Mandiant: no evidence private keys leaked; cold wallets not affected. Neither firm named the appliance vendors (Undisclosed). Fuller RCA still pending; treat today’s notes as interim.
