Bitget Suffers $351M Loss as Transaction Spoofing Attack Exposes Exchange Security Weakness
A large-scale transaction spoofing attack on Bitget in September 2026 drained $351.6 million from its hot wallets, highlighting a vulnerability in exchange security that experts say is still prevalent two years after the industry's biggest heist.
The attack echoed the Bybit hack in February 2025, where North Korea's Lazarus Group compromised a developer machine at Safe{Wallet} and used it to inject malicious code into the signing interface. In both cases, the attackers exploited the gap between what a verification system displays and what it actually executes.
Bitget's own incident update detailed how an attacker compromised a critical backend system inside its wallet infrastructure and triggered the exchange's own authorization process into moving funds out. The attack was not a private key compromise, but rather a sophisticated spoofing of transaction data.
The stolen assets included 102.93 million XRP ($157.48 million), 31,890 ETH ($85.75 million), and other cryptocurrencies, which were quickly converted into ETH before being laundered. Bitget's wallet architecture held up where it mattered most, containing the breach to a portion of its warm and hot layers with cold wallets untouched.