home › blog › bitget-hack-387m-cross-chain
Bitget hack: how $387.5M moved through cross-chain swaps — and what it means if you swap without KYC
Key takeaways
- Attackers moved about $387.5 million out of Bitget’s hot and warm wallets on September 24, 2026, over roughly three hours and across several blockchains.
- They did not steal private keys. Bitget says they exploited an unknown flaw in a third-party security product, took internal credentials, and tricked the exchange’s own approval process into signing the transfers.
- The money was moved across chains. THORChain refused Bitget’s request to block the attacker’s addresses; NEAR Intents blocked more than $50 million in attempted transfers with its screening layer, SHIELD.
- Investigator ZachXBT named five accounts he says are laundering the funds — one of them was also tied to the $292 million Kelp DAO exploit in April.
- For anyone who swaps without KYC, the practical effect is more screening: most instant exchanges we track already risk-score incoming coins after your deposit. Below is how to stay clear of tainted coins and what to do if a swap is held.
What happened at Bitget
Bitget is a large centralized exchange that requires KYC — it is not a service we review. We cover this breach because of where the stolen funds went next: through the same cross-chain swap infrastructure our readers use every day.
| date (UTC) | event |
|---|---|
| Sept 24, 2026 | Unauthorized transfers run for about three hours; the first one at 02:31 and the last at 05:23 (UTC+8), according to SlowMist. Bitget halts withdrawals and reports $351.6 million affected. |
| Sept 25 | Bitget revises the total to about $387.5 million after counting Zcash and TRON transfers, launches a recovery bounty and a live tracking dashboard. ZachXBT says he has no plans to monitor the case. |
| Sept 26–28 | THORChain declines Bitget’s request to refuse the attacker’s addresses; NEAR Intents reports blocking over $50 million in attempted transfers. |
| Sept 28 | ZachXBT publishes five accounts he says are laundering the funds. Bitget restarts Bitcoin withdrawals. |
| Sept 30 | Bitget restores BTC, ETH and USDT withdrawals and publishes a proof of reserves showing a 131% reserve ratio across 19 assets. |
The affected assets included ETH, XRP, BNB, AVAX, USDT and USDC on Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base, CEO Gracy Chen said.
How the attackers got in
This was not a stolen-key hack. According to Bitget’s own account, relayed by Fortune and BleepingComputer:
- The attackers exploited a zero-day vulnerability in third-party security software used by the exchange.
- With it they obtained internal credentials and reached a backend system that processes wallet transactions.
- They forged transfer data so that fraudulent withdrawals looked legitimate, and Bitget’s approval process signed them.
- The transfers came only from hot and warm wallets. Bitget says its cold wallets and the separate Bitget Wallet product were not affected.
Bitget says the flaw is fixed. It is investigating with Mandiant and SlowMist.
The lesson is uncomfortable for every custodial service: an approval system is only as strong as the software it trusts. The keys were never touched — the process that decides when to use them was.
Who was behind it?
Bitget says it suspects North Korean attackers. No government has formally attributed the attack.
What has been published concerns the laundering, not the breach itself. On September 28, ZachXBT named five accounts he says are moving the stolen funds on behalf of the suspected attackers, and matched each to a transaction. He says they asked for help with stuck transactions in the public Discord and Telegram channels of services they were using. One of them — known as “lolo”, also referred to as “Alias 4” — also laundered funds from the $292 million Kelp DAO exploit in April. ZachXBT says he has seen the same pattern after several exploits attributed to the North Korea-linked group known as TraderTraitor, and plans to publish more data.
As one analysis notes, this evidence does not by itself prove who carried out the breach.
Where the money went
The stolen funds were split across chains and services. ZachXBT and others report movement through cross-chain bridges and swap protocols, including THORChain, and into the bitcoin mixer Wasabi.
Two kinds of freezes have happened so far:
- Stablecoin issuers froze about $318,000: Tether roughly 218,000 USDT and Circle about 100,000 USDC.
- NEAR Intents froze about $503,000 during execution and rejected the rest of more than $50 million it flagged.
That is less than 0.3% of the total. Gracy Chen has said she is not very optimistic about recovery: once funds have crossed chains, freezing gets hard.
NEAR Intents vs THORChain: two answers to the same question
The Bitget hack turned a long-running debate into a live test. What should a cross-chain protocol do when stolen money arrives?
| NEAR Intents | THORChain | |
|---|---|---|
| What it did | Its screening layer SHIELD flagged and rejected more than $50 million in attempted transfers; froze about $503,000 during execution; about $166,000 passed through | Declined Bitget’s request to refuse service to the attacker’s addresses |
| Stated position | Will actively fight the laundering of hacked funds; frozen funds to be returned through a legal process; waived Bitget’s 5% + 5% bounty | It is “decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain” |
| Where screening sits | On integrated quote flows, before the swap; its documentation says coverage can vary by flow | Not at protocol level; interfaces built on top may screen |
| Sources | Cointelegraph, NEAR Intents docs | Cointelegraph Magazine |
Note what happened to the money NEAR Intents rejected: it moved to other providers. Screening at one door does not stop the money; it changes which door it uses.
THORChain has been here before. It was used to swap a large share of the funds from the $1.46 billion Bybit hack in 2025. Lawyers now argue over whether “decentralized” is a defense, and over whether NEAR’s blocking shows that its system can be made to block in other situations too.
What our own data shows
We label screening for every service in our catalog: what is checked, when, and by whom, quoted from each service’s own terms or documentation. As of October 1, 2026:
- Cross-chain protocols: Relay, NEAR Intents and Garden screen addresses before the swap starts. THORChain does not screen at protocol level. At Chainflip, brokers — and whitelisted screeners acting through any broker — can reject flagged deposits.
- Instant exchanges: 12 of the 14 we track risk-score incoming coins after your deposit arrives. One checks the country you connect from. For one we could not read the terms at all.
In other words, “no KYC” rarely means “no checks”. The checks have moved: from your identity to your coins. See the catalog — each service shows its screening label, with the full quote and source on its review page.
If you swap without KYC: how to avoid tainted coins
After a hack of this size, stolen coins spread. Most of them will never touch you, but here is how to keep it that way.
Before you swap
- Know where your coins came from. If someone sends you funds with no clear history, do not swap them straight away.
- Read the screening label of the service. A service that screens before the swap rejects you early; one that screens after your deposit can hold your coins.
- Always set a refund address when the service allows it, so a rejected swap comes back to you, not into a support queue.
- Check large incoming payments against public lists. Bitget published an attacker-address dashboard and API; ZachXBT’s posts list transaction hashes.
If your swap is held
- Do not send more funds to “unlock” it.
- Ask support in writing which clause of their terms they rely on.
- Keep your order ID, deposit and payout transaction hashes, and screenshots of the quote.
- Read what the service’s own terms say about holds and refunds — we quote them, with paragraph numbers, in our frozen-funds guide.
- If you do not want to publish your evidence, you can still prove later that you had it today: submit only its sha256 hash in the comment form of the service’s review — we timestamp it in Bitcoin.
Will Bitget users get their money back?
Bitget says its user protection fund covers the loss. The fund held about $465 million when the incident was disclosed; Bitget says it will top it back above $300 million from its own capital. Withdrawals have been restored in stages, and users can check whether their balances are included in the reserves through Bitget’s Merkle-tree tool.
Recovering the stolen funds themselves is another matter. Bitget’s recovery bounty pays 5% for helping freeze funds and another 5% for recovering them. So far the frozen amounts are small.
Frequently asked questions
How much was stolen in the Bitget hack? About $387.5 million. Bitget first reported $351.6 million and raised the figure after counting Zcash and TRON transfers; it says the increase reflects fuller accounting, not a second theft.
Were Bitget users’ funds lost? Bitget says its protection fund covers the loss. The fund held about $465 million when the incident was disclosed, and withdrawals have been restored in stages since September 28.
Was North Korea behind the Bitget hack? Bitget says it suspects North Korean attackers. No government has made a formal attribution yet. ZachXBT’s published evidence concerns the people laundering the funds, not the people who carried out the breach.
Why did NEAR Intents block the funds while THORChain did not? NEAR Intents runs a screening layer called SHIELD on its quote flows and rejected more than $50 million in attempted transfers. THORChain says it is decentralized and permissionless and does not selectively refuse transactions.
Could I receive stolen Bitget coins in a no-KYC swap? It is possible if you swap with someone who received them. Most instant exchanges we track risk-score incoming coins after your deposit, so tainted funds can lead to a hold or a request for source-of-funds information.
What should I do if my swap is held after a big hack? Do not send more funds to unlock it. Ask support in writing which clause they rely on, keep your order ID and transaction hashes, and read what that service’s own terms say about holds and refunds.
Sources
- Bitget and Gracy Chen, incident updates on X and Bitget Support, September 24–30, 2026 — via PANews, Fortune, Crypto Briefing
- BleepingComputer: zero-day in third-party security products
- Cointelegraph: NEAR Intents blocked $50M · Cointelegraph Magazine on THORChain
- ZachXBT’s findings, as reported by Crypto Times and The Cryptonomist
- NEAR Intents: Risk & Compliance
- Our own screening labels: catalog · methodology
This article is updated as the investigation continues. We do not review Bitget and have no commercial relationship with it, THORChain or NEAR Intents.