Bitget's Containment Controls Failed in $290M Hack
Bitget detected unauthorized wallet transfers about 30 minutes before attackers began draining hundreds of millions of dollars from the crypto exchange. The exchange said its systems flagged the suspicious activity at 18:31 UTC on September 24, and its security team immediately activated emergency protocols.
However, blockchain security firm Hypernative's reconstruction of the attack shows that most losses came later: $87.6 million left hot wallets at 19:01, and another $202.8 million left warm wallets at 19:16. Those two bursts, completed in a combined 24 seconds, accounted for about three-quarters of the $387.5 million Bitget ultimately said was moved to attacker-controlled addresses.
The sequence suggests Bitget had roughly half an hour after its initial alert to prevent the first major wave and about 45 minutes before the largest transfer burst. Hypernative said the attacker initially tested the compromised route at 18:31 with transfers of 0.84 ETH and 93 TRX to new addresses.
Bitget's containment controls failed to stop the signing process, which allowed the attacker to trick the exchange's authorization process into approving the transfers. The company said private keys were not compromised.