Bitget Hacker Used Small Test Transfers to Probe Risk Controls
Bitget's CEO Gracy Chen revealed that the attacker behind the $388M theft used two small test transfers to probe the exchange's risk controls before making larger withdrawals.
The first unauthorized transfers occurred on September 24 at 6:31 p.m. UTC, involving 0.184 ETH and 193 TRX from hot wallets, which didn't trigger an alert due to being below Bitget's risk-control threshold.
About 30 minutes later, the attacker began processing much larger withdrawals, totaling around $361 million in just over an hour, across various chains including Ethereum, XRP, Zcash, BNB Chain, and others.
Bitget has since introduced stricter assessment criteria for third-party products and stronger deployment controls to prevent similar incidents, but the exact details of the attack remain unclear until the formal incident report is published.