Bitget's 30-Minute Window to Contain Hack Proves Crucial in $387.5 Million Loss
Bitget detected suspicious activity on its exchange at 18:31 UTC on September 24, giving it 30 minutes to contain a major hack before attackers began draining hundreds of millions of dollars. However, blockchain security firm Hypernative's reconstruction of the attack shows that most losses came later.
The largest transfer wave occurred about an hour after Bitget's initial alert, with $87.6 million leaving hot wallets at 19:01 and another $202.8 million leaving warm wallets at 19:16. These two bursts accounted for roughly three-quarters of the $387.5 million that ultimately left the exchange.
Bitget said its systems flagged unauthorized transfers, and its security team activated emergency protocols immediately after detection. However, Hypernative found unusual transaction parameters in the attacker's requests, including gas limits that differed from Bitget's normal withdrawal pipeline. This could have been used to flag the 18:31 test transaction before larger withdrawals began.
The unresolved issue is why Bitget's compromised signing route stayed active long enough for the breach to escalate after detection. Bitget has since said it remediated the vulnerability and that no further unauthorized transfers occurred after containment.