Bitget Suffers $387.5 Million Hack Through Spoofed Transfers
A major cryptocurrency exchange, Bitget, has fallen victim to a sophisticated hack, resulting in losses of approximately $387.5 million. The attack occurred on September 24, when unauthorized transfers were detected leaving several hot and warm wallets.
The hackers exploited a critical backend system within the wallet service, spoofing transaction data to trick the exchange's own authorization-signing process into approving the transactions. This allowed the attackers to drain funds from multiple blockchain networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base.
The affected assets included ETH, XRP, BNB, AVAX, USDT, USDC, and several smaller tokens. The XRP Ledger suffered the largest single-chain loss, with around 93.7 million XRP transferred to a newly created address.
Interestingly, Bitget's cold wallets remained unaffected throughout the attack, and customer balances were not compromised. Deposits and trading continued uninterrupted during the withdrawal freeze, which lasted from September 24 until October 2.