BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Crypto Hack News Today: Bitget Attackers Bypassed Its Signing Controls

Crypto Hack News Today: How Did Attackers Bypass Bitget's Security? There's a lot of crypto hack news today worth breaking down in detail, and most of it centers on new forensic findings from

AnonymousCryptoCompass newsroom
September 27, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

Crypto Hack News Today: How Did Attackers Bypass Bitget's Security?

There's a lot of crypto hack news today worth breaking down in detail, and most of it centers on new forensic findings from the Bitget breach. 

Two separate security teams, GoPlus Security and AMLBot, have published detailed technical analyses this week explaining exactly how attackers pulled off the $387.5 million theft and where the stolen funds actually sit right now. 

The picture that emerges is more nuanced than a typical hack: this wasn't stolen private keys; it was a compromised trust chain.

Information by WuBlockChain on X

Source: WuBlockChain on X

How the Attack Actually Worked

According toGoPlus Security's detailed analysis, the Bitget breach did not involve a private key leak at all. 

GoPlus Security detailed analysis

Instead, attackers compromised a critical backend system within Bitget's wallet infrastructure, forged transaction data, and tricked the exchange's own authorized signing flow into generating valid signatures for transfers Bitget never intended to make. 

In GoPlus's own words, attackers "did not take the key layer. They took the risk-decision layer." 

A normal withdrawal path runs through backend risk checks before a signer approves it, but attackers bypassed those checks entirely, feeding the signer already-poisoned transaction data it had no way to independently verify.

The Timeline of the Drain

GoPlus's timeline, cross-referenced with Bitget's own security updates, lays out exactly how the attack unfolded:

Time (Sept 24)

Event

18:31 UTC

The attacker received an address funded with 0.84 ETH gas; unauthorized transfers were detected

18:58 UTC

First large withdrawal: ~$34.75M USDT

19:16 UTC

Largest single wave: ~$185M drained in about one minute

18:58–21:23 UTC

Full 2-hour 25-minute multi-chain drain window across ETH, USDT, USDC, AVAX, BNB, XAUt, XRP, and TRX

~21:30 UTC

Bitget CEO Gracy Chen posts security notice, withdrawals paused.

GoPlus flagged one particularly important detail: nearly three hours passed between detection at 18:31 and the last outgoing transfer at 21:23, with no circuit breaker halting the process. 

Had the first $34.75M transfer tripped an automatic stop, GoPlus estimates roughly 90% of the stolen funds could have stayed in place.

Where the Stolen Funds Actually Sit Right Now

This is where things get genuinely interesting for anyone following crypto hack news today. 

PerAMLBot's tracing update, roughly 88.1% of the stolen funds, about $343.2 million, is currently sitting completely dormant. 

AMLBot tracing update

AMLBot identified 13 attacker wallets that have not sent a single transaction since being funded:

  • ~68.3K ETH across 8 wallets on Ethereum Mainnet (~$184.79M)

  • ~83.0M XRP across 4 wallets (~$128.56M)

  • ~18.9K ZEC in a single wallet (~$29.88M)

The remaining roughly $46.2 million is actively moving, funneled mainly through one active XRP wallet running a "peel chain," where small amounts are repeatedly split off and laundered, with roughly 5.2 million XRP peeled off so far. 

TRON, BNB, and stablecoin proceeds are being swapped into BTC using THORChain, Bridgers, and NEAR Intents.

The Mixer Connection: Wasabi CoinJoin

Adding another layer to this story,AMLBot's separate tracing update found that stolen funds have begun entering Wasabi CoinJoin, a Bitcoin mixing service. 

AMLBot tracing update on x

Roughly 4 BTC in one CoinJoin round was traced directly back to a Bitget TRON wallet. 

The laundering path AMLBot mapped out was genuinely elaborate:

  • TRX converted to USDT

  • Bridged to Ethereum via USDT0

  • Swapped into roughly 145 ETH

  • Routed through THORChain into approximately 4.59 BTC

  • Split into smaller amounts and fed into CoinJoin rounds

AMLBot said it has blacklisted the related addresses and continues monitoring the attacker's BTC holdings for further CoinJoin activity.

Why This Matters Beyond Bitget

GoPlus drew a direct structural comparison to the 2025 Bybit hack, noting both incidents share the same underlying weakness: a single trust root feeding a single signing pipeline, whether compromised through a manipulated frontend interface (Bybit) or forged backend data (Bitget). 

GoPlus's recommendations for exchanges going forward include standing up an independent pre-sign risk engine that scores every transaction before it's signed, implementing real circuit breakers with genuine rate limits, and treating staff and vendor supply-chain security as first-class controls rather than afterthoughts.

Conclusion

This round of crypto hack news today paints a clearer, more technical picture of exactly how $387.5 million left Bitget's wallets in just over two hours and where most of it has ended up since. 

With 88% of stolen funds still sitting dormant across traced wallets, active laundering now confirmed through Wasabi CoinJoin, and structural parallels drawn to the 2025 Bybit breach: this incident is shaping up to be a genuine case study in signing-pipeline security, one that both GoPlus and AMLBot are continuing to actively monitor as the situation develops.

Disclaimer

This article is for educational and informational purposes only and should not be considered financial or investment advice. Always conduct your own research before making investment decisions.