On 24 September, Bitget detected unauthorised transfers from its hot and warm wallets. An estimated $351.6 million was taken, making it the largest crypto theft reported this year. Bitget says its cold wallets and customer balances are intact, and that its User Protection Fund, which it puts at more than $464 million, will cover the loss. Withdrawals were nonetheless suspended on 25 September.[1][2]
No forensic report has yet been published and the details may change. But the preliminary picture is already instructive: because this is the second time in under two years that a major exchange has lost hundreds of millions of dollars without anyone breaking a key.
What we know so far
Bitget's chief executive, Gracy Chen, has ruled out a private-key leak. Preliminary accounts point instead to a supply-chain compromise.[3] As currently understood, the attack path ran as follows:
- A third-party tool had approved access to Bitget's backend wallet system as part of day-to-day operations.
- The attacker compromised the tool's vendor rather than Bitget directly.
- The tool then issued forged transfer instructions, structurally identical to legitimate ones, through the same internal API.
- Bitget's backend appears to have checked the format of each instruction, but not its origin or integrity beyond confirming that it came from an approved tool.
- The signing machines then signed and executed the transfers as routine.
The tool was not a control that failed to catch the attack – it was the route in.
What we don't yet know
Bitget has not named the tool or its vendor, nor has it saidhow the vendor was compromised or how long the attacker had access. It is also unclear whether controls were in place to flag anomalous instructions from a legitimate source, such as unusual volumes, new destination patterns, or large withdrawals without second-factor confirmation – or indeed whether the controls were bypassed or entirely absent.
Attribution is also preliminary. Chen has said a link to North Korea is "very likely", citing IP addresses that match VPN services used by a DPRK-linked group and an attack pattern resembling known North Korean techniques.[3] So far, no f government agency has confirmed the attribution.
A familiar pattern
The shape of the attack will be familiar to anyone who followed the Bybit breach in February 2025, when a compromised Safe{Wallet} interface showed signers one transaction and had them approve another. Around $1.5 billion was taken, and the FBI attributed the theft to North Korea.[4]
In both cases the cryptography held. What failed was the assumption that an instruction arriving through a trusted channel can itself be trusted . The industry has invested heavily in key custody: hardware security modules, multi-party computation, multi-signature schemes and cold storage. Attackers have responded by moving upstream, to the tools, interfaces and vendors that tell the keys what to do. That pattern is consistent with wider data: Verizon's 2025 Data Breach Investigations Report found third-party involvement in breaches had doubled year on year to around 30%.[5]
Why this is not only a crypto problem
Traditional institutions may be tempted to read this as a story about crypto exchanges, but his would be a mistake. Asset managers, banks and funds with digital-asset exposure increasingly rely on custodians, sub-custodians, prime brokers and tokenisation platforms, each with its own toolchain. A supplier compromise several layers removed can freeze assets needed for settlement or collateral, even if balances are ultimately made whole.
Bitget's customers may ultimately be protected from loss, but for several days they could not withdraw. Their access, for now, is not. An accurate balance is little comfort if your assets cannot be reached when they are needed.
Four questions for boards and risk committees
- Does anything check an instruction independently of the system that sent it? Controls such as multi-party confirmation above set thresholds, address allowlists, and velocity and destination-anomaly limits should be enforced outside the originating system, so that a trusted source cannot also be the only check.
- Do we know every component with a path to our wallet or payment infrastructure? A vendor list is not a toolchain map. Third- and fourth-party components with a route to signing or payment systems need to be identified, owned and monitored.
- How much could a forged instruction move before a control intervenes? Model it, then test it. The answer is rarely what the control documentation suggests.
- What happens if a venue or custodian suspends withdrawals for a week? Run it as a tabletop exercise, covering the impact on settlement, collateral and client communications.
None of these questions is new. What Bybit and Bitget show is that threat actors learn quickly from each other's successes, and defenders need to learn from each other's incidents at least as quickly.
Could a trusted supplier move our assets without anyone stealing our keys? For most institutions using digital-asset infrastructure, directly or through custodians, the answer is not yet known.
We will update this analysis as forensic findings emerge. This is the second in our series on trust as an attack surface, following our analysis of the Revolut incident.
How Thomas Murray can help
Thomas Murray helps financial institutions understand and manage cyber risk within their organisations and across complex ecosystems. Our Cyber Resilience Ratings and Orbit Security monitoring show where third- and fourth-party dependencies sit and how exposed they are. To discuss how we can help test your own exposure, book a 30-minute call with one of our consultants.
- Digital Asset Market Information
- Beneath the Asset
- The Revolut incident: when trust becomes the attack surface
References
[1] Bitget, security notice, 24 September 2026
[2] Bitget, withdrawal update, 25 September 2026
[3] Bitget CEO, preliminary account; reporting by TechFlow, Cybersecurity News and FinanceFeeds, September 2026
[4] Federal Bureau of Investigation, public service announcement on the Bybit theft, February 2025




