Crypto Hack News Today: How Did Attackers Bypass Bitget's Security? There's a lot of crypto hack news today worth breaking down in detail, and most of it centers on new forensic findings from
Crypto Hack News Today: How Did Attackers Bypass Bitget's Security?
There's a lot of crypto hack news today worth breaking down in detail, and most of it centers on new forensic findings from the Bitget breach.
Two separate security teams, GoPlus Security and AMLBot, have published detailed technical analyses this week explaining exactly how attackers pulled off the $387.5 million theft and where the stolen funds actually sit right now.
The picture that emerges is more nuanced than a typical hack: this wasn't stolen private keys; it was a compromised trust chain.

Source: WuBlockChain on X
How the Attack Actually Worked
According toGoPlus Security's detailed analysis, the Bitget breach did not involve a private key leak at all.

Instead, attackers compromised a critical backend system within Bitget's wallet infrastructure, forged transaction data, and tricked the exchange's own authorized signing flow into generating valid signatures for transfers Bitget never intended to make.
In GoPlus's own words, attackers "did not take the key layer. They took the risk-decision layer."
A normal withdrawal path runs through backend risk checks before a signer approves it, but attackers bypassed those checks entirely, feeding the signer already-poisoned transaction data it had no way to independently verify.
The Timeline of the Drain
GoPlus's timeline, cross-referenced with Bitget's own security updates, lays out exactly how the attack unfolded:
Time (Sept 24)
Event
18:31 UTC
The attacker received an address funded with 0.84 ETH gas; unauthorized transfers were detected
18:58 UTC
First large withdrawal: ~$34.75M USDT
19:16 UTC
Largest single wave: ~$185M drained in about one minute
18:58–21:23 UTC
Full 2-hour 25-minute multi-chain drain window across ETH, USDT, USDC, AVAX, BNB, XAUt, XRP, and TRX
~21:30 UTC
Bitget CEO Gracy Chen posts security notice, withdrawals paused.
GoPlus flagged one particularly important detail: nearly three hours passed between detection at 18:31 and the last outgoing transfer at 21:23, with no circuit breaker halting the process.
Had the first $34.75M transfer tripped an automatic stop, GoPlus estimates roughly 90% of the stolen funds could have stayed in place.
Where the Stolen Funds Actually Sit Right Now
This is where things get genuinely interesting for anyone following crypto hack news today.
PerAMLBot's tracing update, roughly 88.1% of the stolen funds, about $343.2 million, is currently sitting completely dormant.

AMLBot identified 13 attacker wallets that have not sent a single transaction since being funded:
~68.3K ETH across 8 wallets on Ethereum Mainnet (~$184.79M)
~83.0M XRP across 4 wallets (~$128.56M)
~18.9K ZEC in a single wallet (~$29.88M)
The remaining roughly $46.2 million is actively moving, funneled mainly through one active XRP wallet running a "peel chain," where small amounts are repeatedly split off and laundered, with roughly 5.2 million XRP peeled off so far.
TRON, BNB, and stablecoin proceeds are being swapped into BTC using THORChain, Bridgers, and NEAR Intents.
The Mixer Connection: Wasabi CoinJoin
Adding another layer to this story,AMLBot's separate tracing update found that stolen funds have begun entering Wasabi CoinJoin, a Bitcoin mixing service.

Roughly 4 BTC in one CoinJoin round was traced directly back to a Bitget TRON wallet.
The laundering path AMLBot mapped out was genuinely elaborate:
TRX converted to USDT
Bridged to Ethereum via USDT0
Swapped into roughly 145 ETH
Routed through THORChain into approximately 4.59 BTC
Split into smaller amounts and fed into CoinJoin rounds
AMLBot said it has blacklisted the related addresses and continues monitoring the attacker's BTC holdings for further CoinJoin activity.
Why This Matters Beyond Bitget
GoPlus drew a direct structural comparison to the 2025 Bybit hack, noting both incidents share the same underlying weakness: a single trust root feeding a single signing pipeline, whether compromised through a manipulated frontend interface (Bybit) or forged backend data (Bitget).
GoPlus's recommendations for exchanges going forward include standing up an independent pre-sign risk engine that scores every transaction before it's signed, implementing real circuit breakers with genuine rate limits, and treating staff and vendor supply-chain security as first-class controls rather than afterthoughts.
Conclusion
This round of crypto hack news today paints a clearer, more technical picture of exactly how $387.5 million left Bitget's wallets in just over two hours and where most of it has ended up since.
With 88% of stolen funds still sitting dormant across traced wallets, active laundering now confirmed through Wasabi CoinJoin, and structural parallels drawn to the 2025 Bybit breach: this incident is shaping up to be a genuine case study in signing-pipeline security, one that both GoPlus and AMLBot are continuing to actively monitor as the situation develops.
Disclaimer
This article is for educational and informational purposes only and should not be considered financial or investment advice. Always conduct your own research before making investment decisions.