l0grisk intelligence · english

// analysis

Bitget: $387.5 million stolen and the signing blind spot

Illustration for the analysis: Bitget: $387.5 million stolen and the signing blind spot

Private keys, the protection fund, XRP freeze limits and the withdrawal schedule: understanding Bitget’s theft and its promised safeguards.

dated revision: September 26, 2026French originalprimary sourcesno tracker

The balance on the screen can stay unchanged while withdrawals stop. That is the situation Bitget describes following its September 24, 2026 attack. The exchange now estimates that $387.5 million in assets was transferred to attacker-controlled addresses, up from its initial $351.6 million figure. It attributes the revision to Zcash and TRON transfers omitted from the first count. Both estimates concern the same attack; the eventual net loss will also depend on recoveries. Initial notice, revised estimate.

Chief executive Gracy Chen’s account raises a question that goes beyond the size of the theft. Attackers allegedly compromised a backend system, falsified transaction data and triggered Bitget’s authorization process. Chen says the private keys were not compromised. CoinDesk reports this preliminary company assessment. How can assets leave if the secret used to move them remains protected? Chen’s account, reported September 25.

On September 26, Bitget announced a phased withdrawal restart running from September 28 to October 2. Those dates are still in the future at the time of publication. Announced schedule.

The key signs the instruction it receives

A private key can produce a cryptographic signature. Among its functions, a signature allows verification of the origin and integrity of data, as the US National Institute of Standards and Technology explains. An Ethereum transaction includes a destination, a value and a signature; the network applies its validation rules. Checking whether the payment complies with a company’s business procedures requires additional controls. Ethereum documentation.

Consider a hypothetical company that keeps its key inside a dedicated signing device. Separate software prepares payments and submits them for approval. If a falsified request passes the controls and reaches the device, it can receive a valid signature while the key remains secret. The signature then protects data that was already false when it entered the process.

A false request, validly signed Hypothetical example: a falsified request passes an internal control and reaches a device whose key stays secret. The resulting signed transaction can execute if it meets network rules. Arrows trace this process; this is not a reconstruction of the Bitget attack. A false request, validly signed Hypothetical compromised workflow Falsified request Control deceived Secret key Signature Network Execution
Conceptual mechanism, without measurements or a reconstruction of the intrusion. The key stays inside the device; a failed control admits the request. Execution requires compliance with network rules. Sources: NIST, Ethereum. Accessed September 26, 2026.

This makes the information presented to approving systems and people critical. Multiple approvals can share the same blind spot if they all rely on the same falsified instruction. This is a general mechanism: public documents do not describe Bitget’s architecture in enough detail to reconstruct the intrusion.

In its September 25 update, Bitget says it has fixed the vulnerability and is working with Mandiant and SlowMist. It is withholding some details during the investigation. We found no independent technical report in the material reviewed that confirms its full account. Incident update.

A timeline that needs explaining

Public transactions add another part of the record. In its analysis updated September 26, Bitquery places the last transfer it classifies as stolen at 21:23 UTC on September 24. Bitget had reported detecting the incident at 18:31 UTC. The gap raises a question about the containment timeline. Bitquery’s records and methodology, Bitget’s stated detection time.

The timestamps have different origins. Bitquery’s endpoint relies on transactions and its address labels; the detection time comes from the company. Without internal logs, the available record cannot establish which systems had been isolated at each stage or why later transfers went through. A signature recorded on the chain also leaves open whether a copied key or an abused signing service produced it.

An account balance still depends on custody

The incident concerns Bitget’s centralized exchange. Bitget Wallet, the separate self-custody product using the same brand, operates on different infrastructure and was unaffected, according to the spokesperson who spoke to The Block. The distinction concerns two different services. Bitget’s response to The Block.

With third-party custody, the provider controls access to the keys needed to move assets. With self-custody, the user manages that access and takes responsibility for lost or stolen secrets. The SEC’s December 12, 2025 investor bulletin explains this allocation of responsibilities.

Imagine customers trading with each other on a platform that maintains an internal ledger. The operator can update their balances without sending assets to an external wallet for every trade. A customer can therefore change price exposure while remaining dependent on the custodian. Buying a stablecoin within the application leaves that dependency in place until an actual withdrawal.

Suspension may serve a legitimate security purpose: replenishing a vulnerable payment system could expose more funds. Chen told Reuters that withdrawals had stopped as a security precaution rather than because of an asset shortfall. That is Bitget’s explanation; the available sources do not establish an independent assessment of its solvency. Reuters, September 25, republished by The Star.

French residents were already subject to a separate arrangement before the attack. Bitget’s March 13, 2026 notice set out the closure of positions and transfer of remaining assets to a licensed provider, with transfers beginning April 8. The global restart schedule published after the theft should therefore not be presented as automatically applicable to those former accounts. This article does not establish their individual status. Notice for French users.

What the protection fund promises

In its September 24 notice, Bitget put its protection fund above $464 million and said it covered the loss. The fund’s public page describes a bitcoin reserve and claims assessed by the company for platform-wide incidents. It is Bitget’s own protection mechanism, whose conditions and actual deployment matter. Dated statement, fund rules.

Sufficient, available resources could replace the stolen assets without reducing customer balances. Assessing that capacity requires matching usable quantities and valuations against obligations. A bitcoin reserve’s dollar value changes, while the stolen asset mix may be different. Simply subtracting the theft from the advertised fund value would produce a misleadingly precise estimate of the remaining cushion.

Bitget also publishes proof of reserves. Its described process combines asset snapshots with a Merkle tree, a cryptographic structure that lets a customer check whether a balance is included in a declared set. Bitget’s explanation.

On March 8, 2023, the investor advocate’s office at the PCAOB, the US audit oversight body, explained the limitations of such reports. Procedures may leave liabilities, customers’ rights and the effectiveness of internal controls outside their scope. The advisory addresses this category of reports; it makes no finding about Bitget. PCAOB office advisory.

An accurate inventory can precede a theft. Assessing protection therefore means examining available assets, what the company owes its customers and how its systems authorize payments.

Freezing a token takes a specific power

Recovery involves several actors. On September 25, CoinDesk reported that Circle and Tether had blocked USDC and USDT held at an address linked to the attack. That intervention applies to their tokens. Reported interventions.

Circle expressly describes its ability to block USDC transfers to and from certain addresses in section 13 of its terms for holders outside the European Economic Area. This documents a power over the token; European holders’ rights are addressed in separate documents. Circle’s terms.

XRP illustrates the distinction. In a September 26 follow-up, CoinDesk reported further movements of stolen XRP. The protocol distinguishes tokens issued on the XRP Ledger from its native asset, XRP: the token-freezing function does not apply to XRP itself. Ripple therefore lacks that same power over XRP held directly at attacker-controlled addresses. A custodial exchange can, however, restrict an account holding funds in its custody. September 26 update, XRP Ledger documentation.

Who can freeze which asset? Circle can block USDC transfers involving an address. The cross between Ripple and XRP indicates that the native XRP asset has no such freeze function. A custodial exchange can separately restrict its own accounts. Who can freeze which asset? Control over the token Circle USDC Targeted transfers can be blocked Ripple XRP XRP has no native freeze function
Functional comparison as of September 26, 2026, without amounts. Token blocking and exchange account restrictions have different scopes. An exchange can restrict funds in its custody, including XRP. Sources: Circle, USDC Terms, §13, XRP Ledger, Freezing Tokens.

That distinction helps explain the rapid conversions observed by Elliptic: moving from certain administrable tokens into a native asset can remove the original issuer’s ability to intervene in the new asset. Investigations and seizures can still proceed through other means. Elliptic’s analysis.

Tracing funds, stopping their movement and returning them are separate stages. A freeze can preserve the possibility of recovery; an actual return still requires the relevant operations and decisions. Adding together amounts tracked, frozen and recovered could count the same money more than once. Our analysis of the USDT seizure sought by US prosecutors over alleged Iranian oil proceeds explores the relationship between technical control and judicial process.

The North Korea assessment

Elliptic considers a North Korean link highly likely. It points to connections with addresses involved in thefts previously attributed to those actors, including Bybit, and similarities in how the funds moved. Its assessment also incorporates technical indicators reported by Bitget. Assessment published September 25.

This remains the analytics firm’s attribution. Searches conducted through September 26 found no public FBI or US Justice Department attribution specific to this incident. Identifying the attackers and examining responsibility for payment controls each require their own evidence.

The next milestone is a completed withdrawal

Bitget announced the following stages, all at 08:00 UTC, or 10:00 in Paris on the dates shown. This is the schedule published September 26 and may change. The specified networks matter as much as the asset symbol. Official schedule.

Announced date Assets or services Listed networks
September 28, 2026 BTC Bitcoin
September 29, 2026 ETH Ethereum, BSC, Arbitrum, Base, Optimism
September 30, 2026 USDT Ethereum, BSC, Solana, Tron
October 2, 2026 Other tokens, fiat currencies and peer-to-peer (P2P) trading Not detailed in the announcement’s table

What comes next will be measured through completed withdrawals, deployment of the promised resources and findings from the technical investigation. Self-custody places responsibility for keys and backups on the user and calls for its own precautions. SEC custody bulletin.

The Bitget case brings the control points into focus: protect the secret, verify the instruction before signing, and make assets accessible to the customer. A key can remain locked away after the power to pay has changed hands.

Sources

Method and limitations

Research current to September 26, 2026. The $387.5 million estimate, promised coverage and reported absence of private-key compromise originate with Bitget. Bitquery’s and Elliptic’s findings are attributed to their authors; l0g has not reproduced their full tracing work. The withdrawal schedule is prospective.

The diagrams explain general mechanisms and do not describe Bitget’s architecture. l0g had no access to internal logs, performed no complete reserve audit and conducted no interviews. Chen’s statement was checked against CoinDesk’s account; her X post was not directly accessible. General fund and token rules do not determine each customer’s contractual position.

This analysis is not investment advice.

// cite this analysis

l0g, “Bitget: $387.5 million stolen and the signing blind spot”, l0g.fr, published September 26, 2026, updated September 26, 2026, https://l0g.fr/en/analysis/bitget-387-million-theft-signing-keys/


$ cd ../analysis